Splunk Search

Splunk Search
Community Activity
mcbradfordwcb
I want to create an alert when the cpu is at 50% or higher for greater than 5 mins. I thought this would work, but i...
by mcbradfordwcb Engager in Splunk Search 03-15-2018
0 1
0
1
trc29
Hello all, I have the following search: index="vpn_gateway" eventtype="vpn-authall" | stats dc(vpnuid) by vpnc...
by trc29 Engager in Splunk Search 03-15-2018
0 1
0
1
mathiask
At search-time, several fields get extracted more than once, even if they only exist once in the event. I know I can ...
by mathiask Communicator in Splunk Search 03-15-2018
0 6
0
6
bkirk
BASE_SEARCH | rex field=dest_host "^(?<hostname>([a-z0-9\.\-]*\.)?(?<Domain>[a-z0-9\-]{2,}(?=\.[a-z\.]{3,})\.(?<tld>...
by bkirk Path Finder in Splunk Search 03-15-2018
0 3
0
3
burwell
I want to show the number of bad errors each minute over an hour time period to show as an embedded report. I am usi...
by SplunkTrust SplunkTrust in Splunk Search 03-15-2018
1 13
1
13
rakeshyv0807
Hi, I am quite new to splunk platform. Can you please help me out here with my requirement: I have to write a logic...
by rakeshyv0807 Explorer in Splunk Search 03-15-2018
0 5
0
5
linwqg
Need help. Appreciate in advance. I have 2 lookup csv. I need to match each value under "numberX" field against the ...
by linwqg New Member in Splunk Search 03-15-2018
0 12
0
12
jgbricker
Looking for how to query for users that are logging in via Remote Desktop which are not in a certain OU in Active Dir...
by jgbricker Contributor in Splunk Search 03-15-2018
0 4
0
4
rakeshyv0807
Hi, I have three fields which outputs Ip addresses. is there a way to display all these three field IP addresses on ...
by rakeshyv0807 Explorer in Splunk Search 03-15-2018
0 3
0
3
logloganathan
i have raw data with time stamp..ID..target page. i want this to be visualized. how can i do?
by logloganathan Motivator in Splunk Search 03-15-2018
0 1
0
1
timm747747
Hi, I am trying to compare the number of events from last month to the prior month. So January and February and disp...
by timm747747 Path Finder in Splunk Search 03-15-2018
1 2
1
2
pavanae
I have a lookup file which contains a list of hostnames under the field Host like below Host abd addf fdfs Now how...
by pavanae Builder in Splunk Search 03-15-2018
1 3
1
3
AKG1_old1
Hello, I am trying to Join/map Search query result with lookup table. I am close to perfect query, Just not be able...
by AKG1_old1 Builder in Splunk Search 03-15-2018
1 8
1
8
maheshsat
Hi , I tried understanding diff command from spunk.doc unable to understand,could you please let me know use of diff ...
by maheshsat Explorer in Splunk Search 03-15-2018
1 2
1
2
_smp_
I am attempting to determine the earliest event in a particular index by executing the following search over All Time...
by _smp_ Builder in Splunk Search 03-15-2018
0 4
0
4
cc3658
I am using the following search: index=nessus sourcetype="nessus:plugin" OR sourcetype="nessus:scan" each time I pi...
by cc3658 Explorer in Splunk Search 03-15-2018
0 5
0
5
Ponczi1
Hello I have a serach that gives me back two types of events. event A with field r_code and some other fields while e...
by Ponczi1 Explorer in Splunk Search 03-15-2018
0 3
0
3
brober27
I have a log, and in theis log I have a field that I have called Informative. This Informative can assume the followi...
by brober27 New Member in Splunk Search 03-15-2018
0 3
0
3
geantver0000
Hi, I would like to Know if it is possible ! I want to send an email on the adress mail content on my log . For exa...
by geantver0000 Engager in Splunk Search 03-15-2018
0 1
0
1
rsathish47
Hi , I have to sort 2 multivalue fields and need to compare. Please provide me some example. Thanks Sathish R
by rsathish47 Contributor in Splunk Search 03-15-2018
0 2
0
2
splunkdivya
Hi, I have a multivalue field with the name of user and the monthly expenses and another column of time. e.g: column...
by splunkdivya Explorer in Splunk Search 03-15-2018
0 3
0
3
karthi2809
How to Black out my splunk alert for particular period? There are two different scenarios firest alert: 1)16:30 ET ...
by karthi2809 Builder in Splunk Search 03-15-2018
0 5
0
5
krusovice
Hello all, How can I get the average of the output as below? Calculation is 40 + 20 + 50 / 3 = 36.6 REQUEST ...
by krusovice Path Finder in Splunk Search 03-15-2018
0 5
0
5
tkadale
I have "Other" as a drop-down option in my Time Range Picker. I have separate times.conf file for my application in ...
by tkadale Path Finder in Splunk Search 03-15-2018
2 5
2
5
joachimroshan
I have fields ComponentName, CNC in lookup A and fields ComponentName, ENDPOINT in lookup B. The output should have f...
by joachimroshan New Member in Splunk Search 03-14-2018
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors