Splunk Search

Splunk Search
Community Activity
jhooper33
Hi Team/Community,I'm having an issue with a lookup file. I have a csv with two columns, 1st is named ioc and second ...
by jhooper33 Explorer in Splunk Search 12-31-2023
0 14
0
14
AC1
Hi all,I am trying to put together a search and stats table for users in our environment who have uploaded data to a ...
by AC1 Engager in Splunk Search 12-29-2023
0 4
0
4
bcanfield83
Hi All,This may be a bit of a peculiar question, but I'm trying to figure out if there's a way to use a certain expre...
by bcanfield83 Engager in Splunk Search 12-29-2023
0 2
0
2
xxxxxxxxxxxxxx
I am trying to generate a list of the percentages of response codes by resultCode by app.  A simplified version of ev...
by xxxxxxxxxxxxxx Explorer in Splunk Search 12-29-2023
0 8
0
8
beepbop
hi, how can I change the scheduled index time of a data source?
by beepbop Explorer in Splunk Search 12-28-2023
0 1
0
1
SplunkDash
Hello, Line breaker in my props configuration for the json formatted file is not working, it's not breaking the json ...
by SplunkDash Motivator in Splunk Search 12-28-2023
0 2
0
2
HPACHPANDE
Lookup 1  : Contains fields such as  AssetName  FQDN and IP AddressLookup 2 :  Contains fields such as Host Index and...
by HPACHPANDE Explorer in Splunk Search 12-28-2023
0 1
0
1
akselsoeb
Hello guysI need some help with making a table/dashboard that shows me changes to incidents in our Defender platform....
by akselsoeb Engager in Splunk Search 12-28-2023
0 2
0
2
Pat
I have tried to use the following eval to pretty up the return of a field but the result is always test.  I have trie...
by Pat Path Finder in Splunk Search 12-27-2023
0 11
0
11
Dipti
Hi,I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 ...
by Dipti Explorer in Splunk Search 12-27-2023
0 4
0
4
jason_hotchkiss
I have the follow time:EPOCH HUMAN READABLE170363091912/26/2023 19:48:39I would like to convert the EPOCH to CST time...
by jason_hotchkiss Communicator in Splunk Search 12-27-2023
0 3
0
3
Nagalakshmi
Hi Team,Need your assistant for below  We have created new csv lookup and we are using the below query but we are get...
by Nagalakshmi Path Finder in Splunk Search 12-27-2023
0 2
0
2
quangnm21
Hello everyone, I'm a beginner in using Splunk. I'm facing an issue in finding a search solution for the following id...
by quangnm21 Explorer in Splunk Search 12-27-2023
0 4
0
4
Assaf_Katz
Hi, I have the following transforms.conf: [REPLACEMENT_COST] CLEAN_KEYS = 0 FORMAT = $1"REPLACEMENT_COST2":"$2$s"$3 R...
by Assaf_Katz Loves-to-Learn in Splunk Search 12-27-2023
0 2
0
2
of
Hi,I need help generating search queries using SPL, especially in my new role as a SOC Analyst. I would like to know ...
by of New Member in Splunk Search 12-27-2023
0 1
0
1
yolk
Hi,I have data like these entrieslink          id                     parent     name----          ---               ...
by yolk Observer in Splunk Search 12-26-2023
0 3
0
3
HPACHPANDE
(index=123) sourcetype=XYZ AND type IN ("SERVICE_STOP") )  | _time host type _raw  is the main query where we are sea...
by HPACHPANDE Explorer in Splunk Search 12-25-2023
0 2
0
2
krutika_ag
Hi,There are a lot of clients in my architecture and every other splunk instance is deployed in either /opt/bank/splu...
by krutika_ag Path Finder in Splunk Search 12-24-2023
0 4
0
4
Jason
What is the difference between the NOT operator and the != operator? I have always used NOT up to this point, but am...
by Jason Motivator in Splunk Search 12-22-2023
3 5
3
5
t_splunk_d
I want to get the result of the next line of the log message when I encounter  a key word.Example log:----error in ch...
by t_splunk_d Path Finder in Splunk Search 12-22-2023
0 4
0
4
MGlass
I am running the current search using the network toolkit but will not show the hostname field from the csv, do I nee...
by MGlass Explorer in Splunk Search 12-22-2023
0 2
0
2
GIA
hello I am pretty new using Splunk and I am being tasked to generate multiple of these kinds of reports in Splunk (or...
by GIA Path Finder in Splunk Search 12-21-2023
0 5
0
5
yuvaraj_m91
index="********"message_type =ERROR correlation_id="*"| eval err_field1 = spath(_raw,"response_details.body")| eval e...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 12-21-2023
0 2
0
2
quangnm21
This was my initial search. I cannot compare the two fields "srcdomain = destdomain" because when I intend to use eva...
by quangnm21 Explorer in Splunk Search 12-21-2023
0 3
0
3
Mr_Adate
Hello Friends, I need your help to find out matching fields values and their total count by comparing from two differ...
by Mr_Adate Explorer in Splunk Search 12-20-2023
0 9
0
9
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors