Splunk Search

Splunk Search
Community Activity
EricMonkeyKing
Hi all,For this sort of json string, how can I extract KeyA, KeyB, KeyC? { "KeyA": [ { "path": "/attibuteA", "op": "r...
by EricMonkeyKing Explorer in Splunk Search 12-14-2023
0 5
0
5
duesser
 I have a multivalue field, which I would like to expand to individual fields, like so:| makeresults count=1 | eval a...
by duesser Path Finder in Splunk Search 12-14-2023
0 4
0
4
KingUs80
I'm currently working on crafting a Splunk Query to identify systems that have been inactive for a specified duration...
by KingUs80 Loves-to-Learn Lots in Splunk Search 12-13-2023
0 2
0
2
varsh_6_8_6
HiI am trying to see for a ticket that is not assigned to an analyst for the last 15 mins from the time of arrival. I...
by varsh_6_8_6 Explorer in Splunk Search 12-13-2023
0 1
0
1
nkavouris
Hello Splunkers,I am New to Splunk and am trying to figure out how to parse nested JSON data spit out by an end-of-li...
by nkavouris Path Finder in Splunk Search 12-13-2023
0 5
0
5
MirrorCraze
I have a data like this.{<!-- -->    env: prod   host: prod01   name: appName   info: {      data: [ ...     ]     indicators...
by MirrorCraze Explorer in Splunk Search 12-13-2023
0 1
0
1
Lennard
Hi guys, I started today with Splunk and have one question. I want to use an or function that if the second "or" the ...
by Lennard Engager in Splunk Search 12-13-2023
0 2
0
2
Jagat
I want to extract only the process name value from the logs and store in a table:Input Log:-------------&lt;30&gt;1 2023-12...
by Jagat Engager in Splunk Search 12-13-2023
0 4
0
4
nithys
Hi All,I need some help in searching, I have 1 index but it has multiple sources,Index &#61; Index1Source &#61; source 1Sourc...
by nithys Communicator in Splunk Search 12-12-2023
0 2
0
2
CoryC
How do I grab all of the versions of Splunk EXCEPT the top 1, basically the opposite ofindex&#61;winconfig sourcetype&#61;"WM...
by CoryC Engager in Splunk Search 12-12-2023
0 1
0
1
nehamvinchankar
Hi experts,I want to extract below fields in separate separate event to further work on it .INFO 2023-12-11 17:06:01,...
by nehamvinchankar Path Finder in Splunk Search 12-12-2023
0 4
0
4
KundanNagare23
We got output in table but all values are in one column  for each fields of output table. We want to split values in ...
by KundanNagare23 Loves-to-Learn Lots in Splunk Search 12-12-2023
0 4
0
4
ea-2023
Hello, I am working on a search to find domains queried via a particular host, and list out a count of hits per uniqu...
by ea-2023 Path Finder in Splunk Search 12-12-2023
0 5
0
5
kowsi_ksk
HI ,Need some help on removing the duplicates from table.  Am querying the accounts which uses the plain port connect...
by kowsi_ksk New Member in Splunk Search 12-12-2023
0 1
0
1
yuvaraj_m91
I have two different logs where the error is capturing in different fields in each log message...(error_message and e...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 12-12-2023
0 1
0
1
nehamvinchankar
How to get difference of  lastest value with now i have multiple values in latest column and only one value in now co...
by nehamvinchankar Path Finder in Splunk Search 12-12-2023
0 1
0
1
att35
Hi.I have a data model that consists of two root event datasets. Both accelerated using simple SPL.First dataset I ca...
by att35 Builder in Splunk Search 12-12-2023
1 1
1
1
GaryZ
Is there a way of creating a search where we can have both LIKE and NOT LIKE, based on user selected option? ie. if $...
by GaryZ Path Finder in Splunk Search 12-11-2023
0 1
0
1
akr
I am new to Splunk. I am trying to overwrite the values of a field (eventLevel) that is in Japanese. I created a look...
by akr Loves-to-Learn Lots in Splunk Search 12-11-2023
0 1
0
1
mojoes
Hi, I am new at Splunk and I'm following the lab in Enriching Data with Lookups, where I'm requested to exclude a val...
by mojoes Engager in Splunk Search 12-11-2023
0 1
0
1
Abhirup_10
I have a csv file with the user list and I want to create an alert to monitor the user login failure alert from the u...
by Abhirup_10 New Member in Splunk Search 12-10-2023
0 1
0
1
splunkernator
Do you need to return output from one section of a chain search to another, like when writing a function in a program...
by splunkernator Path Finder in Splunk Search 12-09-2023
0 17
0
17
Rhidian
Hi, I'm trying to calculate the number of events per day so I can then divide by 86400 to get the daily EPS. I know I...
by Rhidian Path Finder in Splunk Search 12-09-2023
0 12
0
12
Muthu_Vinith
Hi, I have two datasets for example –1.Index&#61;abc host&#61;def_inven, consider as Dataset A (inventory with 100 servers) a...
by Muthu_Vinith Path Finder in Splunk Search 12-09-2023
0 7
0
7
AK89
Looking for help with this rex command. I want to capture the continuous string after "invalid user" whether it has s...
by AK89 Explorer in Splunk Search 12-08-2023
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors