Splunk Search

Splunk Search
Community Activity
claudio_manig
Hi Ninjas I struggle with query including several "challenges". I got proxy events like: time="10-27-17 10:00:00" ...
by claudio_manig Communicator in Splunk Search 10-27-2017
0 5
0
5
karthi2809
Event separation is not working properly ? Merged log: [10/27/17 0:58:53:702 EDT] 0000013b TimerLog 1 com.ibm....
by karthi2809 Builder in Splunk Search 10-27-2017
0 1
0
1
jsharma123
HI , I have a html dashboard which update a d3 graph on text input change , This text input is added to my search qu...
by jsharma123 Explorer in Splunk Search 10-27-2017
0 4
0
4
renjujacob88
Hi Splunkers, We do have a correlation rule for distinct malware infected on a system ( two ore more different malw...
by renjujacob88 Path Finder in Splunk Search 10-26-2017
0 2
0
2
logmar5
There are many options for capturing data (text files, tcp/udp, etc) however, what are the possibilities for getting ...
by logmar5 Explorer in Splunk Search 10-26-2017
1 3
1
3
bagaeva
Hello i need filter fields but only on certain events. Sample events: 1508735029.189 d = a enm_val = 25440 event =...
by bagaeva Engager in Splunk Search 10-26-2017
0 2
0
2
kabiraj
I am trying to use return command to output a multivalued field from subsearch to main search. My search looks like b...
by kabiraj Path Finder in Splunk Search 10-26-2017
0 6
0
6
limalbert
So, I regex time from my splunk logs in form of (HH:MM:SS), and I am trying to build the report like index: somethi...
by limalbert Path Finder in Splunk Search 10-26-2017
0 4
0
4
jared_anderson
I want a regular expression to pull a file name out of a path that is the process field. The path could be any direct...
by jared_anderson Path Finder in Splunk Search 10-26-2017
0 4
0
4
jvmerilla
Hi, I'm trying to create an external lookup but I'm getting very confused. What are the external sources that I can...
by jvmerilla Path Finder in Splunk Search 10-26-2017
0 1
0
1
rashid47010
From IPS Event How can I extract only CVE value XXXXDxxxre xxxrability (CVE-201x-00xx) (severity = Low) I am writin...
by rashid47010 Communicator in Splunk Search 10-26-2017
0 3
0
3
morenodelgad1
I have data in the following format: GenericHostName1=vm1,vm2,vm3,vm4; GenericHostName2=vm5,vm6,vm7; When I search...
by morenodelgad1 Explorer in Splunk Search 10-26-2017
0 7
0
7
willadams
Hi All, I am recently new to SPLUNK and trying to identify a way of doing some time differences. I have done an ex...
by willadams Contributor in Splunk Search 10-26-2017
0 1
0
1
erickyi
I tried various combinations but failed index="flowintegrator" src_port=21 |eval thisUser=src_ip + "="+ dest_ip | ti...
by erickyi Path Finder in Splunk Search 10-25-2017
0 6
0
6
archananaveen
| inputlookup clusName.csv | fields cluster ----works in a dropdown and has around 10 entries Now, I need to use ...
by archananaveen Explorer in Splunk Search 10-25-2017
0 5
0
5
Vicky84
Completely New to regex, I have a log as below and wanted to extract the percentage i.e. "28" and then check it with ...
by Vicky84 Explorer in Splunk Search 10-25-2017
0 2
0
2
chrisw3
I'm currently working on 3 separate data sourcetypes that have similar information Sourcetype 1 - Fields X,Y,Z Sourc...
by chrisw3 Explorer in Splunk Search 10-25-2017
0 4
0
4
ddrillic
Our top user ended up with the following query - | inputlookup WHERE [ | makeresults count=8 | streamstats cou...
by ddrillic Ultra Champion in Splunk Search 10-25-2017
0 6
0
6
JacobCarrell
I've got a regex that's working in Regex101's editor, but when I paste it into Splunk I get garbage or no results: Re...
by JacobCarrell Explorer in Splunk Search 10-25-2017
0 3
0
3
fiveturns
When using the HTTP Event Collector, is automatic sourcetype detection possible? Every event at the moment appears t...
by fiveturns Engager in Splunk Search 10-25-2017
1 3
1
3
jeanyvesnolen
Hello All ! I ask myself what is the best approach to extract all fields of logs with regex in general. I speak here...
by jeanyvesnolen Path Finder in Splunk Search 10-25-2017
0 5
0
5
mcvr
Hi Peeps, source="Log.txt" resp_status=503 | chart count by req_url If I execute the above query I will get the fol...
by mcvr New Member in Splunk Search 10-25-2017
0 1
0
1
jon3484
I created a list of known malicious domain names and put that information into a CSV. I named the field "dest_hostna...
by jon3484 New Member in Splunk Search 10-25-2017
0 2
0
2
mmohiuddin1512
Hi All: I am unable to get the metadata host field in Splunk for the value of the database field called "HOSTNAME". ...
by mmohiuddin1512 Explorer in Splunk Search 10-25-2017
0 4
0
4
j_partsch
I have the following search index=firewall policy_name="/Common/default" request_status=blocked (violations="Access...
by j_partsch Explorer in Splunk Search 10-25-2017
0 2
0
2
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors