| Hi, I wonder whether someone could help me please. I'm trying to extract a particular value from a field which is "f... by IRHM73 Motivator in Splunk Search 10-27-2017 0 5 | 0 | 5 | ||
| I have a field that looks like this: UserName=domain\joe_user I want it to look like this: UserName=joe_user Ho... by pil321 Communicator in Splunk Search 10-27-2017 0 3 | 0 | 3 | ||
| I'm reviewing Microsoft Event Code 4656 (Failed Object Access) but when I try to audit Accesses or Access Reasons, Sp... by jbala1 Engager in Splunk Search 10-27-2017 0 2 | 0 | 2 | ||
| Hi, in my scenario i have a lot of users for example: user1, user2, user3... and i want to count their logins to a s... by reschal Explorer in Splunk Search 10-27-2017 0 3 | 0 | 3 | ||
| Hi Ninjas I struggle with query including several "challenges". I got proxy events like: time="10-27-17 10:00:00" ... by claudio_manig Communicator in Splunk Search 10-27-2017 0 5 | 0 | 5 | ||
| Event separation is not working properly ? Merged log: [10/27/17 0:58:53:702 EDT] 0000013b TimerLog 1 com.ibm.... by karthi2809 Builder in Splunk Search 10-27-2017 0 1 | 0 | 1 | ||
| HI , I have a html dashboard which update a d3 graph on text input change , This text input is added to my search qu... by jsharma123 Explorer in Splunk Search 10-27-2017 0 4 | 0 | 4 | ||
| Hi Splunkers, We do have a correlation rule for distinct malware infected on a system ( two ore more different malw... by renjujacob88 Path Finder in Splunk Search 10-26-2017 0 2 | 0 | 2 | ||
| There are many options for capturing data (text files, tcp/udp, etc) however, what are the possibilities for getting ... by logmar5 Explorer in Splunk Search 10-26-2017 1 3 | 1 | 3 | ||
| Hello i need filter fields but only on certain events. Sample events: 1508735029.189 d = a enm_val = 25440 event =... by bagaeva Engager in Splunk Search 10-26-2017 0 2 | 0 | 2 | ||
| I am trying to use return command to output a multivalued field from subsearch to main search. My search looks like b... by kabiraj Path Finder in Splunk Search 10-26-2017 0 6 | 0 | 6 | ||
| So, I regex time from my splunk logs in form of (HH:MM:SS), and I am trying to build the report like index: somethi... by limalbert Path Finder in Splunk Search 10-26-2017 0 4 | 0 | 4 | ||
| I want a regular expression to pull a file name out of a path that is the process field. The path could be any direct... by jared_anderson Path Finder in Splunk Search 10-26-2017 0 4 | 0 | 4 | ||
| Hi, I'm trying to create an external lookup but I'm getting very confused. What are the external sources that I can... by jvmerilla Path Finder in Splunk Search 10-26-2017 0 1 | 0 | 1 | ||
| From IPS Event How can I extract only CVE value XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low) I am writin... by rashid47010 Communicator in Splunk Search 10-26-2017 0 3 | 0 | 3 | ||
| I have data in the following format: GenericHostName1=vm1,vm2,vm3,vm4; GenericHostName2=vm5,vm6,vm7; When I search... by morenodelgad1 Explorer in Splunk Search 10-26-2017 0 7 | 0 | 7 | ||
| Hi All, I am recently new to SPLUNK and trying to identify a way of doing some time differences. I have done an ex... by willadams Contributor in Splunk Search 10-26-2017 0 1 | 0 | 1 | ||
| I tried various combinations but failed index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | ti... by erickyi Path Finder in Splunk Search 10-25-2017 0 6 | 0 | 6 | ||
| | inputlookup clusName.csv | fields cluster ----works in a dropdown and has around 10 entries Now, I need to use ... by archananaveen Explorer in Splunk Search 10-25-2017 0 5 | 0 | 5 | ||
| Completely New to regex, I have a log as below and wanted to extract the percentage i.e. "28" and then check it with ... by Vicky84 Explorer in Splunk Search 10-25-2017 0 2 | 0 | 2 | ||
| I'm currently working on 3 separate data sourcetypes that have similar information Sourcetype 1 - Fields X,Y,Z Sourc... by chrisw3 Explorer in Splunk Search 10-25-2017 0 4 | 0 | 4 | ||
| Our top user ended up with the following query - | inputlookup WHERE [ | makeresults count=8 | streamstats cou... by ddrillic Ultra Champion in Splunk Search 10-25-2017 0 6 | 0 | 6 | ||
| I've got a regex that's working in Regex101's editor, but when I paste it into Splunk I get garbage or no results: Re... by JacobCarrell Explorer in Splunk Search 10-25-2017 0 3 | 0 | 3 | ||
| When using the HTTP Event Collector, is automatic sourcetype detection possible? Every event at the moment appears t... by fiveturns Engager in Splunk Search 10-25-2017 1 3 | 1 | 3 | ||
| Hello All ! I ask myself what is the best approach to extract all fields of logs with regex in general. I speak here... by jeanyvesnolen Path Finder in Splunk Search 10-25-2017 0 5 | 0 | 5 |