Thread Info | |||||
---|---|---|---|---|---|
From IPS Event How can I extract only CVE value
XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low)
I am wr...
by
rashid47010
Communicator
in
Splunk Search
03-16-2017
|
0
|
3
| |||
I have data in the following format:
GenericHostName1=vm1,vm2,vm3,vm4;
GenericHostName2=vm5,vm6,vm7;
When I se...
by
morenodelgad1
Explorer
in
Splunk Search
10-25-2017
|
0
|
7
| |||
Hi All,
I am recently new to SPLUNK and trying to identify a way of doing some time differences. I have done an e...
by
willadams
Contributor
in
Splunk Search
10-26-2017
|
0
|
1
| |||
I tried various combinations but failed
index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | ...
by
erickyi
Path Finder
in
Splunk Search
10-25-2017
|
0
|
6
| |||
| inputlookup clusName.csv | fields cluster ----works in a dropdown and has around 10 entries
Now, I need to use ...
by
archananaveen
Explorer
in
Splunk Search
10-25-2017
|
0
|
5
| |||
Completely New to regex, I have a log as below and wanted to extract the percentage i.e. "28" and then check it with ...
by
Vicky84
Explorer
in
Splunk Search
10-25-2017
|
0
|
2
| |||
I'm currently working on 3 separate data sourcetypes that have similar information
Sourcetype 1 - Fields X,Y,Z Sou...
by
chrisw3
Explorer
in
Splunk Search
12-09-2016
|
0
|
4
| |||
Our top user ended up with the following query -
| inputlookup WHERE [ | makeresults count=8 | streamstats count ...
by
ddrillic
Ultra Champion
in
Splunk Search
10-25-2017
|
0
|
6
| |||
I've got a regex that's working in Regex101's editor, but when I paste it into Splunk I get garbage or no results: Re...
by
JacobCarrell
Explorer
in
Splunk Search
10-24-2017
|
0
|
3
| |||
When using the HTTP Event Collector, is automatic sourcetype detection possible?
Every event at the moment appears...
by
fiveturns
Engager
in
Splunk Search
05-04-2017
|
1
|
3
| |||
Hello All !
I ask myself what is the best approach to extract all fields of logs with regex in general. I speak he...
by
jeanyvesnolen
Path Finder
in
Splunk Search
03-28-2017
|
0
|
5
| |||
Hi Peeps,
source="Log.txt" resp_status=503 | chart count by req_url
If I execute the above query I will get the...
by
mcvr
New Member
in
Splunk Search
10-25-2017
|
0
|
1
| |||
I created a list of known malicious domain names and put that information into a CSV. I named the field "dest_hostnam...
by
jon3484
New Member
in
Splunk Search
10-24-2017
|
0
|
2
| |||
Hi All:
I am unable to get the metadata host field in Splunk for the value of the database field called "HOSTNAME"...
by
mmohiuddin1512
Explorer
in
Splunk Search
10-23-2017
|
0
|
4
| |||
I have the following search
index=firewall policy_name="/Common/default" request_status=blocked (violations="Acces...
by
j_partsch
Explorer
in
Splunk Search
10-24-2017
|
0
|
2
| |||
My timechart is working perfectly for last 10 days but it is not working for time range above 15 days.Any idea to res...
by
nivethainspire_
Explorer
in
Splunk Search
10-25-2017
|
0
|
3
| |||
Hi, I am trying to give cell value using drilldown as parameter to another dashboard. Below is how I have defined it:...
by
SirHill17
Communicator
in
Splunk Search
10-25-2017
|
0
|
7
| |||
I have the following search:
..index bla bla... | eval eD_A=strptime(D_A, "%Y-%m-%d %H:%M:%S.%N") , eD_AV=strptime...
by
Mike6960
Path Finder
in
Splunk Search
10-24-2017
|
0
|
6
| |||
Hi,
I've got these strange XML logs, where each log has (among other things) a username and an arbitrary number of...
by
hettervik
Builder
in
Splunk Search
10-17-2017
|
0
|
6
| |||
I am trying search events where the destination IP is in a lookup table consisting of a list of CIDR ranges (and thre...
by
jwalzerpitt
Influencer
in
Splunk Search
08-30-2017
|
0
|
5
| |||
So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup ...
by
katzr
Path Finder
in
Splunk Search
10-24-2017
|
0
|
1
| |||
$execution$ $host$ $user$ |eval moresearch=if(execution=index=index1,"",($authentication$) OR ($configuration$) OR ($...
by
deastman
Path Finder
in
Splunk Search
10-24-2017
|
0
|
11
| |||
I am having issues with displaying data based off the results from the lookup table. I am using this search below, w...
by
AbubakarShahid
New Member
in
Splunk Search
10-24-2017
|
0
|
3
| |||
I have a query as below
| metadata type=hosts | search [| inputlookup hosts_test.csv | eval host=lower(my_hostnam...
by
pavanae
Builder
in
Splunk Search
10-24-2017
|
0
|
2
| |||
I'm looking for a way to traffic the average ssh traffic between two IP addresses (source IP and destination IP) and ...
by
serwin
Explorer
in
Splunk Search
10-24-2017
|
0
|
1
|