Splunk Search

Splunk Search
Community Activity
mdavis43
I have a search that currently has 3 search terms... host="s2a*" "Command Aborted" OR "Internal queue full" OR "Abor...
by mdavis43 Path Finder in Splunk Search 10-27-2017
0 4
0
4
rookie507SL
Hi mates, I'm figuring out how I can show a table with matching IP addresses from 2 different vendor firewalls. So ...
by rookie507SL New Member in Splunk Search 10-27-2017
0 6
0
6
tonahoyos
Hello All, I am having an issue using the stats sum command. This is currently my search: source="Jan_Sept_FinanceS...
by tonahoyos Explorer in Splunk Search 10-27-2017
0 6
0
6
Rialf1959
Hello, I need to: Count all values from mv field: blkio_stats.io_serviced_recursive{}.value where blkio_stats.io_ser...
by Rialf1959 Explorer in Splunk Search 10-27-2017
0 1
0
1
suruthyshree
How i can get the string between two given strings. Log has entires like 22:09: DT : 2178we352njsdfh48734 : EF and...
by suruthyshree New Member in Splunk Search 10-27-2017
0 2
0
2
templier
Hello all, I have a next case. In one of my index i have a data on Russian language, and if i want start search some...
by templier Communicator in Splunk Search 10-27-2017
0 5
0
5
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to extract a particular value from a field which is "f...
by IRHM73 Motivator in Splunk Search 10-27-2017
0 5
0
5
pil321
I have a field that looks like this: UserName=domain\joe_user I want it to look like this: UserName=joe_user Ho...
by pil321 Communicator in Splunk Search 10-27-2017
0 3
0
3
jbala1
I'm reviewing Microsoft Event Code 4656 (Failed Object Access) but when I try to audit Accesses or Access Reasons, Sp...
by jbala1 Engager in Splunk Search 10-27-2017
0 2
0
2
reschal
Hi, in my scenario i have a lot of users for example: user1, user2, user3... and i want to count their logins to a s...
by reschal Explorer in Splunk Search 10-27-2017
0 3
0
3
claudio_manig
Hi Ninjas I struggle with query including several "challenges". I got proxy events like: time="10-27-17 10:00:00" ...
by claudio_manig Communicator in Splunk Search 10-27-2017
0 5
0
5
karthi2809
Event separation is not working properly ? Merged log: [10/27/17 0:58:53:702 EDT] 0000013b TimerLog 1 com.ibm....
by karthi2809 Builder in Splunk Search 10-27-2017
0 1
0
1
jsharma123
HI , I have a html dashboard which update a d3 graph on text input change , This text input is added to my search qu...
by jsharma123 Explorer in Splunk Search 10-27-2017
0 4
0
4
renjujacob88
Hi Splunkers, We do have a correlation rule for distinct malware infected on a system ( two ore more different malw...
by renjujacob88 Path Finder in Splunk Search 10-26-2017
0 2
0
2
logmar5
There are many options for capturing data (text files, tcp/udp, etc) however, what are the possibilities for getting ...
by logmar5 Explorer in Splunk Search 10-26-2017
1 3
1
3
bagaeva
Hello i need filter fields but only on certain events. Sample events: 1508735029.189 d = a enm_val = 25440 event =...
by bagaeva Engager in Splunk Search 10-26-2017
0 2
0
2
kabiraj
I am trying to use return command to output a multivalued field from subsearch to main search. My search looks like b...
by kabiraj Path Finder in Splunk Search 10-26-2017
0 6
0
6
limalbert
So, I regex time from my splunk logs in form of (HH:MM:SS), and I am trying to build the report like index: somethi...
by limalbert Path Finder in Splunk Search 10-26-2017
0 4
0
4
jared_anderson
I want a regular expression to pull a file name out of a path that is the process field. The path could be any direct...
by jared_anderson Path Finder in Splunk Search 10-26-2017
0 4
0
4
jvmerilla
Hi, I'm trying to create an external lookup but I'm getting very confused. What are the external sources that I can...
by jvmerilla Path Finder in Splunk Search 10-26-2017
0 1
0
1
rashid47010
From IPS Event How can I extract only CVE value XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low) I am writin...
by rashid47010 Communicator in Splunk Search 10-26-2017
0 3
0
3
morenodelgad1
I have data in the following format: GenericHostName1=vm1,vm2,vm3,vm4; GenericHostName2=vm5,vm6,vm7; When I search...
by morenodelgad1 Explorer in Splunk Search 10-26-2017
0 7
0
7
willadams
Hi All, I am recently new to SPLUNK and trying to identify a way of doing some time differences. I have done an ex...
by willadams Contributor in Splunk Search 10-26-2017
0 1
0
1
erickyi
I tried various combinations but failed index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | ti...
by erickyi Path Finder in Splunk Search 10-25-2017
0 6
0
6
archananaveen
| inputlookup clusName.csv | fields cluster ----works in a dropdown and has around 10 entries Now, I need to use ...
by archananaveen Explorer in Splunk Search 10-25-2017
0 5
0
5
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors