Splunk Search

Splunk Search
Community Activity
j_partsch
I have the following search index=firewall policy_name="/Common/default" request_status=blocked (violations="Access...
by j_partsch Explorer in Splunk Search 10-25-2017
0 2
0
2
nivethainspire_
My timechart is working perfectly for last 10 days but it is not working for time range above 15 days.Any idea to res...
by nivethainspire_ Explorer in Splunk Search 10-25-2017
0 3
0
3
SirHill17
Hi, I am trying to give cell value using drilldown as parameter to another dashboard. Below is how I have defined it:...
by SirHill17 Communicator in Splunk Search 10-25-2017
0 7
0
7
Mike6960
I have the following search: ..index bla bla... | eval eD_A=strptime(D_A, "%Y-%m-%d %H:%M:%S.%N") , eD_AV=strptime(D...
by Mike6960 Path Finder in Splunk Search 10-25-2017
0 6
0
6
hettervik
Hi, I've got these strange XML logs, where each log has (among other things) a username and an arbitrary number of h...
by hettervik Builder in Splunk Search 10-24-2017
0 6
0
6
jwalzerpitt
I am trying search events where the destination IP is in a lookup table consisting of a list of CIDR ranges (and thre...
by jwalzerpitt Influencer in Splunk Search 10-24-2017
0 5
0
5
katzr
So I have a lookup with a date field, identified field, and a description field. There are duplicates in this lookup ...
by katzr Path Finder in Splunk Search 10-24-2017
0 1
0
1
deastman
$execution$ $host$ $user$ |eval moresearch=if(execution=index=index1,"",($authentication$) OR ($configuration$) OR ($...
by deastman Path Finder in Splunk Search 10-24-2017
0 11
0
11
AbubakarShahid
I am having issues with displaying data based off the results from the lookup table. I am using this search below, w...
by AbubakarShahid New Member in Splunk Search 10-24-2017
0 3
0
3
pavanae
I have a query as below | metadata type=hosts | search [| inputlookup hosts_test.csv | eval host=lower(my_hostname...
by pavanae Builder in Splunk Search 10-24-2017
0 2
0
2
serwin
I'm looking for a way to traffic the average ssh traffic between two IP addresses (source IP and destination IP) and ...
by serwin Explorer in Splunk Search 10-24-2017
0 1
0
1
splunkrocks2014
I have a data feed with CEF format. Splunk picks up the key value pairs except the value with the whitespaces, for i...
by splunkrocks2014 Communicator in Splunk Search 10-24-2017
0 5
0
5
siddharthmis
Hi, How do I get "7515-36283" between "Result:" and "/ Value" from following text: Result: 75153-6283 / Value "Res...
by siddharthmis Explorer in Splunk Search 10-24-2017
0 2
0
2
jared_anderson
I have a field with event IDs. Some of the IDs indicate an issue, while some of them indicate the opposite. eventid=...
by jared_anderson Path Finder in Splunk Search 10-24-2017
0 5
0
5
N92
I want to ignore below user name. So I written following manner is it correct? ......| where NOT (user="*$" OR user=...
by N92 Path Finder in Splunk Search 10-24-2017
0 1
0
1
florencegoh
I have list of lookup list yyyy which I want to shown the latest login based on max login time and also user that did...
by florencegoh New Member in Splunk Search 10-24-2017
0 7
0
7
nieivan
Hi I'm trying to combine fields in multiple search result in one output table as overall result, for example: Sear...
by nieivan New Member in Splunk Search 10-24-2017
0 2
0
2
splunk_worker
Hi I want identify the long running searches who are running more than 5 min and stop them. I'm able to find the l...
by splunk_worker Path Finder in Splunk Search 10-23-2017
1 4
1
4
vik123ash
Error: Update failed. First exception on row 0 with id abcd; first error: INVALID_EMAIL_ADDRESS, Email: invalid ema...
by vik123ash Explorer in Splunk Search 10-23-2017
0 3
0
3
rsokolova
Thanks in advance, Having a hard time trying to put 3 searches together to sum both search counts by PO. Please see ...
by rsokolova Path Finder in Splunk Search 10-23-2017
0 3
0
3
pavanae
I have a query as follows to display the list of hosts which are seen in last 24 hours and hosts which are not seen i...
by pavanae Builder in Splunk Search 10-23-2017
0 14
0
14
jared_anderson
I want to create charts based on number of results. I have tried "172.20.3.6 (199.0.8.62 OR 199.0.8.57) StoresOutBo...
by jared_anderson Path Finder in Splunk Search 10-23-2017
0 2
0
2
pavanae
I have a lookup search as follows |inputlookup hostnames.csv Which displays the results as follows my_hostname...
by pavanae Builder in Splunk Search 10-23-2017
0 5
0
5
ejespiritu
Hi All, Is there an easier way in designing the charts? What i've found is using css but building one from scratch...
by ejespiritu Explorer in Splunk Search 10-23-2017
0 8
0
8
AKG1_old1
Hello, In my data, there could be multiple values(duration) for Scriptname. I am using Time Chart to display data an...
by AKG1_old1 Builder in Splunk Search 10-23-2017
2 4
2
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors