Splunk Search

Splunk Search
Community Activity
OldManEd
I have a search that starts out like this; index=my_index field1=abc field2=def ( field3=aaa OR field...
by OldManEd Builder in Splunk Search 03-21-2018
0 5
0
5
davidcraven02
I have two regexes below which are pulling the domain name of the email sender (from). i.e linkedin.com, amazones.com...
by davidcraven02 Communicator in Splunk Search 03-21-2018
0 5
0
5
smdasim
Hi , I am not able to parse the below log format using timeformat -props.conf It is giving me a warning unable to pa...
by smdasim Explorer in Splunk Search 03-21-2018
0 3
0
3
myobmatt
I have extracted fields from a json log using spath, I want to add double quotes to the tabled results using ... | e...
by myobmatt New Member in Splunk Search 03-21-2018
0 5
0
5
macadminrohit
Hi, I am running this query: index=servers sourcetype=json Name=* Version=* Id=* | dedup _raw |fillnull bdy.ex.Msg ...
by macadminrohit Contributor in Splunk Search 03-21-2018
0 2
0
2
gabarrygowin
Hi all, Well a long night and day of reading about every post on forms and manual input to no avail. I'm looking f...
by gabarrygowin Path Finder in Splunk Search 03-21-2018
0 4
0
4
eddieparra
I have multiple alert actions in Python. I am trying to have the modalert helper for each action to load a common li...
by eddieparra New Member in Splunk Search 03-21-2018
0 11
0
11
donrtowery
I have a query that is returning similar, but not exact results. In the example results below, I want to get rid of '...
by donrtowery New Member in Splunk Search 03-21-2018
0 3
0
3
jeurich
I need help figuring out the best way to get the information I want in one query. I have indexA with sourcetypeA, so...
by jeurich New Member in Splunk Search 03-21-2018
0 2
0
2
jrballesteros05
Hello Everyone, I've just done a Splunk query that it required a lot of conditionals and I just wanted to use boolean...
by jrballesteros05 Communicator in Splunk Search 03-21-2018
0 8
0
8
eranday
Is it possible to do a conditional count using tstats? I want to count specific event_type: (count if(event_type = 'x...
by eranday New Member in Splunk Search 03-21-2018
0 5
0
5
cramasta
Is it possible to do a conditional count using tstats? I'm trying use the following which is the syntax that I would ...
by cramasta Builder in Splunk Search 03-21-2018
2 4
2
4
MikeBertelsen
Based on what I've found I configured the following inputs.conf in a test tier as follows: [WinEventLog://AD FS/Admin...
by MikeBertelsen Communicator in Splunk Search 03-21-2018
0 5
0
5
davidcraven02
I'm trying to build a pass/fail check to see if a machine already exists in a csv, as I have a dashboard with a text ...
by davidcraven02 Communicator in Splunk Search 03-21-2018
0 4
0
4
isamrat
I want to filter my search results based on lookup table. But the road block here is that I want not only to match fe...
by isamrat Explorer in Splunk Search 03-21-2018
0 1
0
1
sergevic
I have a problem with a query, that I'm trying to use on a dashboard. It works weird: sometimes it returns expected r...
by sergevic Explorer in Splunk Search 03-21-2018
1 16
1
16
lisa_1
I am working with a search like this: dovecot [ search DHCPACK [ search host="airport*" "Associated with sta...
by lisa_1 Explorer in Splunk Search 03-21-2018
4 4
4
4
GDude
My results are in the following table: happening time_duration Aufnahme zaehler_anzahl 1 ...
by GDude New Member in Splunk Search 03-21-2018
0 0
0
0
Dinesh_Raja
Hello, I need to create a dashboard which shows error messages & its count over the time. i have a logfile like belo...
by Dinesh_Raja Path Finder in Splunk Search 03-21-2018
0 8
0
8
Dinesh_Raja
Hello All, I have to create a real time dashboard which give insight on the different type of errors and how many su...
by Dinesh_Raja Path Finder in Splunk Search 03-21-2018
0 2
0
2
VI371887
I want to write a query or rex under field extraction, to extract each value following a string and stopping at coma,...
by VI371887 Path Finder in Splunk Search 03-20-2018
0 4
0
4
BearMormont
I have some data that looks similar to the following: { Name: Record1 Tags: [ { Key: Tag1 Value:...
by BearMormont Path Finder in Splunk Search 03-20-2018
0 1
0
1
suryaavinash
I have a requirement where i got to see if the results of a Search1 with Index1 are available in search2 with Index2....
by suryaavinash Explorer in Splunk Search 03-20-2018
0 2
0
2
MonkeyK
I am trying to use a wildcard based lookup table as part of a query that will get all non-wildcard based values so th...
by MonkeyK Builder in Splunk Search 03-20-2018
0 0
0
0
arjitgoswami
Hi All, My requirement was we needed to analyse issues with vendors who are failing to perform and for this, I need...
by arjitgoswami Explorer in Splunk Search 03-20-2018
0 4
0
4
Get Updates on the Splunk Community!

Simplifying the Analyst Experience with Finding-based Detections

    Splunk invites you to an engaging Tech Talk focused on streamlining security operations with ...

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...