Splunk Search

Splunk Search
Community Activity
hartfoml
I would like to create a look-up tool for my incident responders. they often only have an IP and I would like to be ...
by hartfoml Motivator in Splunk Search 09-12-2017
0 5
0
5
edwardrose
Hello All, I really need to get good at regex and learn to do this myself but alas there are so many other things th...
by edwardrose Contributor in Splunk Search 09-12-2017
0 5
0
5
kdimaria
So, I have a graph that shows the total user logins per day for an application and I thought it would be cool to show...
by kdimaria Communicator in Splunk Search 09-12-2017
0 4
0
4
faustf
Hi guys, I would like to convert the following event into a table: { Id: 1505207351 Start: 1505207651 ...
by faustf Communicator in Splunk Search 09-12-2017
0 5
0
5
sepkarimpour
I want to compare two identical searches but one looking for just count and the other using count | where the average...
by sepkarimpour Path Finder in Splunk Search 09-12-2017
0 6
0
6
davidlajda
Hello all. I'm totally new to splunk. And I'm totally desperate now. I have .log file in which i have to search for s...
by davidlajda Engager in Splunk Search 09-12-2017
0 8
0
8
takaakinakajima
I create a simple dashboard and put a text field (token: field1) and a panel with shows result search query. <form> ...
by takaakinakajima Path Finder in Splunk Search 09-12-2017
1 8
1
8
sepkarimpour
I've tried to set up an alert to go off whenever the number of hosts from one search is not the same for another sear...
by sepkarimpour Path Finder in Splunk Search 09-12-2017
0 3
0
3
iamjosh007
i have a user login info log file like below for eg, when i prepare a time chart for last 2 days, i need the unique u...
by iamjosh007 New Member in Splunk Search 09-12-2017
0 1
0
1
charleswheelus
I have log entries from multiple hosts which contain cumulative counters. One log entry per host about every 5 minut...
by charleswheelus Path Finder in Splunk Search 09-11-2017
3 4
3
4
himynamesdave
All - I need someone to bring me sanity with a regex I am trying to write. Essentially I want to capture everything ...
by himynamesdave Contributor in Splunk Search 09-11-2017
0 2
0
2
patilsh
Hello All, Suppose I want a search results for past 60minutes, how spunk works now is if there is any event in past ...
by patilsh Explorer in Splunk Search 09-11-2017
0 7
0
7
gowthambr
index = elm-retail-rws source="/opt/app/jboss/current/standalone/log/PosMultipaymentProfile.log"
by gowthambr New Member in Splunk Search 09-11-2017
0 7
0
7
splunk_newb
I'm trying to filter down a list of internal email addresses at search time in a field called "email." They are all t...
by splunk_newb Explorer in Splunk Search 09-11-2017
0 17
0
17
packet_hunter
This query works great index=fireeye sourcetype=hx_json [search index=fireeye sourcetype=hx_cef_syslog act="Detect...
by packet_hunter Contributor in Splunk Search 09-11-2017
0 14
0
14
luanvn
Hello everyone, Now, I encountered hard problem that I can't solve for long times. I was also google on many hours b...
by luanvn Explorer in Splunk Search 09-11-2017
1 7
1
7
ilomax
Hello, I'm new to Splunk in general, and I was wondering is there was a way to highlight inconsistencies in the IDs ...
by ilomax New Member in Splunk Search 09-11-2017
0 1
0
1
apgersplunk1
I am trying to use an external script (python) to retrieve data from a database (sqlite3) which is to be summarized w...
by apgersplunk1 Explorer in Splunk Search 09-11-2017
2 3
2
3
jeremy_fade
I use the following search to show a pie chart of the top 5 IPs connecting to the network: sourcetype="conn_log" | c...
by jeremy_fade New Member in Splunk Search 09-11-2017
0 2
0
2
gfriedmann
I am trying to settle on a method for grouping hosts into hostgroups for easy searching and reporting. I have heard e...
by gfriedmann Communicator in Splunk Search 09-11-2017
3 3
3
3
packet_hunter
This search gives me a value that I can feed into the next search and I get results without an error index=fireeye s...
by packet_hunter Contributor in Splunk Search 09-11-2017
0 2
0
2
SystemsEnginee1
Need to find the solution for a Splunk search that finds when Event_ID=24 and Event_ID=40 but not Event_ID=23 within ...
by SystemsEnginee1 New Member in Splunk Search 09-11-2017
0 11
0
11
leonheart78
I'm trying to extract the Account Name for this particular Windows Event, which is passed by a Syslog forwarder, inst...
by leonheart78 Explorer in Splunk Search 09-11-2017
0 2
0
2
andrewhlui
I have data that has multiple (and variable) ip addresses associated with each event. For example: ABCD September 1...
by andrewhlui Explorer in Splunk Search 09-11-2017
0 1
0
1
kulo
I have a search statement as follows index=test1 sourcetype=test1 |join type=left filed [search index=test2] | table...
by kulo Engager in Splunk Search 09-11-2017
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...