Splunk Search

Splunk Search
Community Activity
jonathangrant74
Good day. I am trying to use a subsearch to extract SSL certificate Subject Alternative Names (SAN) from Nessus scan...
by jonathangrant74 Explorer in Splunk Search 11-19-2017
0 6
0
6
smehmood
Here is part of two raw log messages "memberOf=CN=AU-SG NAT_ClientReadyApp,OU=UniversalGroups,OU=Groups,DC=au,DC=two...
by smehmood New Member in Splunk Search 11-18-2017
0 1
0
1
coloradoark
Palo Alto has a field called “flags”. It can have several hex type entries, but what I’m interested in is whether or...
by coloradoark New Member in Splunk Search 11-17-2017
0 3
0
3
mkrauss1
Assume the following records: Nov 17 19:24:51 x.x.x.x Nov 17 19:24:51 myserver (appx): 1510943091.801 520 192.168.0....
by mkrauss1 Explorer in Splunk Search 11-17-2017
0 5
0
5
obiwan1129
I have a query I'm working on where not all the values I feed it are in the index I am querying against. For examp...
by obiwan1129 New Member in Splunk Search 11-17-2017
0 1
0
1
johnansett
Hey guys, Looking for some help with a search. When a user starts first logs into an application to on board themse...
by johnansett Communicator in Splunk Search 11-17-2017
0 5
0
5
agdavidson
Hi there. I am new to SPL and wondering how to make a particular query more efficient. In particular, I want to creat...
by agdavidson New Member in Splunk Search 11-17-2017
0 1
0
1
ddrillic
We have a couple of automatic lookups and I don't see them in the SH under /opt/splunk/etc/apps/<app_name>/lookups W...
by ddrillic Ultra Champion in Splunk Search 11-17-2017
1 3
1
3
varunghai
Hi, i want to combine the results from my search query with a lookup table that i have uploaded. They both have 1 co...
by varunghai Engager in Splunk Search 11-17-2017
0 5
0
5
surekhasplunk
Hi, I have a calculated field call Percentage which is required for other calculations but i dont want that value...
by surekhasplunk Communicator in Splunk Search 11-17-2017
0 5
0
5
maniishpawar
Hi I have this query and trying to do a eval case on the rex field value returned base | rex "#TAGRESPONSE.*RESPONSE...
by maniishpawar Path Finder in Splunk Search 11-17-2017
1 7
1
7
guilmxm
Hi, I have a strong request from my client that wants to be to be able to view events resulting from a SPL search in...
by guilmxm Influencer in Splunk Search 11-17-2017
0 2
0
2
surekhasplunk
I have a dashboard table with fields like below. Area field2 filed3 UK 100 200 US 300 400 In the dri...
by surekhasplunk Communicator in Splunk Search 11-17-2017
0 14
0
14
koshyk
Hi We have a regex/requirement to extract col1,col2,col3,col4 everytime. But the data may not contain col3 onwards ev...
by koshyk Super Champion in Splunk Search 11-17-2017
0 2
0
2
jrfrost
I have a field extraction that gets the message number from the raw message string .{22}\s0-9 The message string is...
by jrfrost Explorer in Splunk Search 11-17-2017
1 3
1
3
krishnakanthgup
In general after we make changes in .conf files splunk instance should restart. If we deploy splunk in production en...
by krishnakanthgup New Member in Splunk Search 11-17-2017
0 3
0
3
5plunked
hi, I have searched high and low for the instructions but cant seem to find the settings for enabling the search he...
by 5plunked Explorer in Splunk Search 11-16-2017
0 2
0
2
super_virus
Hi , Very new to splunk. I need to search a index with two strings example: "ABC1" "XVZ2" And create a line graphs...
by super_virus New Member in Splunk Search 11-16-2017
0 2
0
2
stakor
So, I am going through windows logs, and have output that works for me with something like: index=windows sourcetype...
by stakor Path Finder in Splunk Search 11-16-2017
0 1
0
1
JoshuaJohn
I am not sure why I am not getting results with this query, any suggestions? index= ______ | stats max(_time) as las...
by JoshuaJohn Contributor in Splunk Search 11-16-2017
1 1
1
1
eransh10
Hi splunk guru's. I'm trying to find a way (using SPL only - i am not an admin) to do the following: My vulnerability...
by eransh10 New Member in Splunk Search 11-16-2017
0 2
0
2
abdulvehhaba
Hi I want to calculate/simulate a data to analysis price difference, my data set in picture, left is my data set, r...
by abdulvehhaba Path Finder in Splunk Search 11-16-2017
0 6
0
6
abdulvehhaba
Hi I have data like this I am joined uuid over market data together like that But there is 4 times date column...
by abdulvehhaba Path Finder in Splunk Search 11-16-2017
0 5
0
5
splunkreal
Hello guys, I'd like to check changes on the Checkpoint firewall logs but I haven't any result : index=xxx host=yyy...
by splunkreal Motivator in Splunk Search 11-16-2017
0 1
0
1
oneillryan93
I'm attempting to use a subsearch to extract a number of integers in order to transpose those integers as columns. He...
by oneillryan93 New Member in Splunk Search 11-16-2017
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...