Splunk Search

Splunk Search
Community Activity
siddharthmis
Hi, I have events like following (in the sequence of occurrence)- {"TransactionId":"570978b406264e398d888cd8b49f867...
by siddharthmis Explorer in Splunk Search 02-14-2018
0 10
0
10
surekhasplunk
I have a drop-down to choose values of quarter. <label>Choose Quarter</label> <choice value="Q">Quarter</choic...
by surekhasplunk Communicator in Splunk Search 02-14-2018
0 10
0
10
madakkas
Hi All, I have a question that I am trying to solve … I have two files which I can upload to be used as inputlooku...
by madakkas Explorer in Splunk Search 02-14-2018
0 6
0
6
jackreeves
Hi, I am trying to use an eval if function with a stats command. I am having an issue creating an IF command where o...
by jackreeves Explorer in Splunk Search 02-14-2018
0 11
0
11
leirga11
i have events that has columns like this: date1 date2 01/01/2018 01/01/2018 01/02/2018 01/26/2...
by leirga11 New Member in Splunk Search 02-14-2018
0 3
0
3
nrnirmal
Hi, I have a requirement to be developed in Splunk. Please provide your inputs. I need to provide an option to load...
by nrnirmal New Member in Splunk Search 02-13-2018
0 4
0
4
vader_akbarhan
I am trying to copy the search history (not the saved searches) from my old computer to the new one. I found CSV f...
by vader_akbarhan New Member in Splunk Search 02-13-2018
0 3
0
3
sarwshai
I have created more than 10 alerts for different trigger conditions which send a unique CSV through mail, For e.g. th...
by sarwshai Communicator in Splunk Search 02-13-2018
0 1
0
1
tksre
I have a list of about 200 userids for which I want to fetch the client ip address (from which they logged on )- is t...
by tksre New Member in Splunk Search 02-13-2018
0 1
0
1
leonrtx
Hello Has anybody seen any indexer/search performance degradation after installing the Meltdown patches on Linux? An...
by leonrtx Explorer in Splunk Search 02-13-2018
1 4
1
4
claudiocruz
Forgive me if this question has been asked before but I couldn't find the answer and I'm a little confused. I have ...
by claudiocruz Engager in Splunk Search 02-13-2018
0 3
0
3
amar85
I am writing a Splunk query where I need to send an alert if the count of both queries are not same. I am trying some...
by amar85 New Member in Splunk Search 02-13-2018
0 6
0
6
casswell
I have a fairly simple search that returns a table of values - the number of processors used vs the number of jobs wi...
by casswell Explorer in Splunk Search 02-13-2018
0 1
0
1
LoganRhamy
earliest=-100d index=nessus OR index=nessus_workstation severity_id!=0 severity_id!=1 | dedup signature_id sortby _t...
by LoganRhamy New Member in Splunk Search 02-13-2018
0 4
0
4
jcolin101
Hi, I wondering Why Splunk Enterprise shows at Data Summary the earliest event from 48 years ago. Can it be erased o...
by jcolin101 New Member in Splunk Search 02-13-2018
0 2
0
2
vkumar6
Hi How can I create a PIE chart using multiple subsearches? notable | search source="ENV: Windows Privilege Escala...
by vkumar6 Explorer in Splunk Search 02-13-2018
0 1
0
1
tschn00
I have written a python script whose purpose is to add a line to a file every time the specified command is called in...
by tschn00 Explorer in Splunk Search 02-13-2018
1 4
1
4
cxfuent29
I am using a lookup csv file. events have userid and CSV file has userid. Some of the event file userid's are not o...
by cxfuent29 New Member in Splunk Search 02-13-2018
0 1
0
1
alanhowlett
We are trying to carry out a field extraction in a log that contains xml output. We have worked out the regex to get...
by alanhowlett New Member in Splunk Search 02-13-2018
0 2
0
2
ksbuchanan
Here is my search: source="WinEventLog:Security" EventCode="4723" OR EventCode="529" | eval UserName=coalesce(User_N...
by ksbuchanan Explorer in Splunk Search 02-13-2018
0 11
0
11
tamduong16
I have the following search: index="monthlycdr" | eval "transporttype"=replace('Transport Type',"\"","") | eval "t...
by tamduong16 Contributor in Splunk Search 02-13-2018
0 5
0
5
Sukisen1981
Hi, I have a CSV with something like the one shown. first field is order id and second field is product code. ordr ...
by Sukisen1981 Champion in Splunk Search 02-13-2018
0 2
0
2
bcarr12
Hello everyone, I am sure this is a relatively easy regex to build but I was hoping for some assistance, my regex ex...
by bcarr12 Path Finder in Splunk Search 02-13-2018
0 9
0
9
Naren26
I have to forecast data for next 15 days, based on the last 30 days data. I have used the following query: sourcetyp...
by Naren26 Path Finder in Splunk Search 02-13-2018
0 3
0
3
paulalbert
I am trying to join the results of two searches so it looks like this: CWID, authorization_pk,weillCornellEduPrimary...
by paulalbert Engager in Splunk Search 02-13-2018
0 9
0
9
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors