Splunk Search

Splunk Search
Community Activity
LCM_BRogerson
I'm running Splunk Enterprise v 6.6.1 on Windows 2008 R2 (not by choice). Without making any configuration changes (...
by LCM_BRogerson Path Finder in Splunk Search 11-09-2017
1 10
1
10
98123722
A user is only allowed to log in from one of their AllowedPlatform: userAllowedPlatform.csv | User | Allowed...
by 98123722 Explorer in Splunk Search 11-09-2017
0 2
0
2
rbochen
"call" OR "exception1" OR "exception2" OR "exception3" | eval calls = if(like(message, "%call%"), 1, 0) | eva...
by rbochen New Member in Splunk Search 11-09-2017
0 2
0
2
thenhaque
I am writing a saved search to trigger and alert when a difference between values is higher than a threshold. A simp...
by thenhaque Explorer in Splunk Search 11-09-2017
0 5
0
5
vinisha29
eg: source = shuttle(Oct1-3).zip:./shuttle/5720/LOG/shuttle_log.20171002 ,shuttle_3.zip:./shuttle_3/5720/LOG/shuttle_...
by vinisha29 New Member in Splunk Search 11-09-2017
0 1
0
1
pfabrizi
I run this search: index=_audit action=fired_alert I get back this which looks like properties of the alert. Audit...
by pfabrizi Path Finder in Splunk Search 11-09-2017
0 2
0
2
robertlynch2020
I have a lookup that end users can update. However they might make a mistake and put in the same data twice. The issu...
by robertlynch2020 Influencer in Splunk Search 11-09-2017
0 2
0
2
christoffertoft
Hello. I have a dataset with a regular expression where i extract the hostname of the computer to a hostname variabl...
by christoffertoft Communicator in Splunk Search 11-08-2017
0 4
0
4
kiril123
I am trying to list the events from the subsearch which are not found in the main search. For example the subsearch ...
by kiril123 Path Finder in Splunk Search 11-08-2017
0 5
0
5
rajgowd1
Hi, can someone help me to exact "536 MiliSeconds" from below is log 6>2017-11-02T05:55:12Z d065d14b-3bcd-481c-512a-...
by rajgowd1 Communicator in Splunk Search 11-08-2017
0 3
0
3
kenliu
I'm trying to compare multi-value fields from multiple events and display the diff between the two sets. For example...
by kenliu Explorer in Splunk Search 11-08-2017
0 2
0
2
anil_ec21
Dear All, We have a scenario, where For each Application_ID, Application_Name is having multi-value and delimited. ...
by anil_ec21 Explorer in Splunk Search 11-08-2017
1 4
1
4
cinchnetops
I'm basically trying to identify whether some of my hosts are not doing something successfully as it should be in a d...
by cinchnetops Explorer in Splunk Search 11-08-2017
0 3
0
3
tamduong16
I have been searching about this for the last couple of days. I don't think Splunk have this feature but I just want ...
by tamduong16 Contributor in Splunk Search 11-08-2017
1 4
1
4
rookie507SL
Hi mates, I'm figuring out the reason, why I'm looking LAN addresses as source IP if my search is clearly filtering ...
by rookie507SL New Member in Splunk Search 11-08-2017
0 3
0
3
k_harini
I have below text and i need to extract "Successfully Sent" FTP Ipaddress and store number. I could extract first po...
by k_harini Communicator in Splunk Search 11-08-2017
0 2
0
2
skiourus
Hello after a search like this: index=myindex|lookup mycsv.csv host_ip I have the following output: I would lik...
by skiourus New Member in Splunk Search 11-08-2017
0 4
0
4
robertlynch2020
Hi I have an issues where I am joining a Data-model with a lookup table and its working very well. We are looking to...
by robertlynch2020 Influencer in Splunk Search 11-08-2017
0 2
0
2
surekhasplunk
I have two lookup csv files. file1.csv and file2.csv 1st query results me with field1 which has a pattern match in ...
by surekhasplunk Communicator in Splunk Search 11-08-2017
0 2
0
2
smurfy_91
Let's say I had used a search like: index=mail RecipientUserDomain=user@domain.com | stats count by Subject | sort-c...
by smurfy_91 New Member in Splunk Search 11-08-2017
0 2
0
2
mbond81
I'm trying to calculate man hours, but my field format is "12 Mins" not simply "12". How can I either calculate this ...
by mbond81 Engager in Splunk Search 11-08-2017
0 4
0
4
pari04home
For the same sourcetype, I have a lot many different patterns from which I want to extract one specific field. Is the...
by pari04home New Member in Splunk Search 11-07-2017
0 3
0
3
tragiccode
We have 2 sourcetypes that we would like to somehow do a join based on if sourcetype2 has a ArrivalDateTime that fall...
by tragiccode New Member in Splunk Search 11-07-2017
0 8
0
8
Aftab_alam
I have custom log file in which we all logging various activities in a transaction context (correlation ID). In this ...
by Aftab_alam Explorer in Splunk Search 11-07-2017
1 4
1
4
jw44250
How to capture only word that has white the start and end : - 1) ERROR 2) url :/test.com/error.html 3) this is my e...
by jw44250 New Member in Splunk Search 11-07-2017
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors