Thread Info | |||||
---|---|---|---|---|---|
I have a field that looks like this:
UserName=domain\joe_user
I want it to look like this:
UserName=joe_use...
by
pil321
Communicator
in
Splunk Search
09-16-2015
|
0
|
3
| |||
I'm reviewing Microsoft Event Code 4656 (Failed Object Access) but when I try to audit Accesses or Access Reasons, Sp...
by
jbala1
Engager
in
Splunk Search
10-26-2017
|
0
|
2
| |||
Hi,
in my scenario i have a lot of users for example: user1, user2, user3... and i want to count their logins to a...
by
reschal
Explorer
in
Splunk Search
10-27-2017
|
0
|
3
| |||
Hi Ninjas
I struggle with query including several "challenges".
I got proxy events like:
time="10-27-17 10:0...
by
claudio_manig
Communicator
in
Splunk Search
10-27-2017
|
0
|
5
| |||
Event separation is not working properly ?
Merged log:
[10/27/17 0:58:53:702 EDT] 0000013b TimerLog 1 com.ibm.m...
by
karthi2809
Builder
in
Splunk Search
10-26-2017
|
0
|
1
| |||
HI ,
I have a html dashboard which update a d3 graph on text input change , This text input is added to my search ...
by
jsharma123
Explorer
in
Splunk Search
10-26-2017
|
0
|
4
| |||
Hi Splunkers,
We do have a correlation rule for distinct malware infected on a system ( two ore more different mal...
by
renjujacob88
Path Finder
in
Splunk Search
10-26-2017
|
0
|
2
| |||
There are many options for capturing data (text files, tcp/udp, etc) however, what are the possibilities for getting ...
by
logmar5
Explorer
in
Splunk Search
01-15-2015
|
1
|
3
| |||
Hello i need filter fields but only on certain events.
Sample events:
1508735029.189 d = a enm_val = 25440 eve...
by
bagaeva
Engager
in
Splunk Search
10-26-2017
|
0
|
2
| |||
I am trying to use return command to output a multivalued field from subsearch to main search. My search looks like b...
by
kabiraj
Path Finder
in
Splunk Search
10-25-2017
|
0
|
6
| |||
So, I regex time from my splunk logs in form of (HH:MM:SS), and I am trying to build the report like
index: somet...
by
limalbert
Path Finder
in
Splunk Search
10-26-2017
|
0
|
4
| |||
I want a regular expression to pull a file name out of a path that is the process field. The path could be any direct...
by
jared_anderson
Path Finder
in
Splunk Search
10-25-2017
|
0
|
4
| |||
Hi, I'm trying to create an external lookup but I'm getting very confused. What are the external sources that I can...
by
jvmerilla
Path Finder
in
Splunk Search
10-26-2017
|
0
|
1
| |||
From IPS Event How can I extract only CVE value
XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low)
I am wr...
by
rashid47010
Communicator
in
Splunk Search
03-16-2017
|
0
|
3
| |||
I have data in the following format:
GenericHostName1=vm1,vm2,vm3,vm4;
GenericHostName2=vm5,vm6,vm7;
When I se...
by
morenodelgad1
Explorer
in
Splunk Search
10-25-2017
|
0
|
7
| |||
Hi All,
I am recently new to SPLUNK and trying to identify a way of doing some time differences. I have done an e...
by
willadams
Contributor
in
Splunk Search
10-26-2017
|
0
|
1
| |||
I tried various combinations but failed
index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | ...
by
erickyi
Path Finder
in
Splunk Search
10-25-2017
|
0
|
6
| |||
| inputlookup clusName.csv | fields cluster ----works in a dropdown and has around 10 entries
Now, I need to use ...
by
archananaveen
Explorer
in
Splunk Search
10-25-2017
|
0
|
5
| |||
Completely New to regex, I have a log as below and wanted to extract the percentage i.e. "28" and then check it with ...
by
Vicky84
Explorer
in
Splunk Search
10-25-2017
|
0
|
2
| |||
I'm currently working on 3 separate data sourcetypes that have similar information
Sourcetype 1 - Fields X,Y,Z Sou...
by
chrisw3
Explorer
in
Splunk Search
12-09-2016
|
0
|
4
| |||
Our top user ended up with the following query -
| inputlookup WHERE [ | makeresults count=8 | streamstats count ...
by
ddrillic
Ultra Champion
in
Splunk Search
10-25-2017
|
0
|
6
| |||
I've got a regex that's working in Regex101's editor, but when I paste it into Splunk I get garbage or no results: Re...
by
JacobCarrell
Explorer
in
Splunk Search
10-24-2017
|
0
|
3
| |||
When using the HTTP Event Collector, is automatic sourcetype detection possible?
Every event at the moment appears...
by
fiveturns
Engager
in
Splunk Search
05-04-2017
|
1
|
3
| |||
Hello All !
I ask myself what is the best approach to extract all fields of logs with regex in general. I speak he...
by
jeanyvesnolen
Path Finder
in
Splunk Search
03-28-2017
|
0
|
5
| |||
Hi Peeps,
source="Log.txt" resp_status=503 | chart count by req_url
If I execute the above query I will get the...
by
mcvr
New Member
in
Splunk Search
10-25-2017
|
0
|
1
|