Splunk Search

Splunk Search
Community Activity
splunkreal
Hello, is it possible to set 'smart mode' search for all users in a search head cluster, if yes, how? Thanks.
by splunkreal Influencer in Splunk Search 08-07-2017
0 1
0
1
jaango123
Hi, I am new to Splunk and I managed to construct the below query to generate statistics with the help of the answer...
by jaango123 Engager in Splunk Search 08-07-2017
0 10
0
10
Rocky31
I am typing all command like splunk start, splunk help, nothing is working, i don't know what to do, every time comma...
by Rocky31 Path Finder in Splunk Search 08-06-2017
0 9
0
9
wifemin
tl;dr how does renaming a field to "search" help? how to make a map visualization with the lookup table/codes shown...
by wifemin Engager in Splunk Search 08-06-2017
0 4
0
4
splunkerkanaka
Is there a specific command that we use to take away a field from the results displayed?
by splunkerkanaka New Member in Splunk Search 08-06-2017
0 2
0
2
chinchin96
When you run a standard search query (say, in verbose mode), it auto-extracts fields and displays them on the left. W...
by chinchin96 New Member in Splunk Search 08-06-2017
0 2
0
2
matansocher
Hi, I have created a chart to show the accumulated number of open and closed ticket: My code: sourcetype=snow:in...
by matansocher Contributor in Splunk Search 08-06-2017
0 1
0
1
colinmchugo
Hi all, I am trying to discover the standard deviation from one set of data to another in a percentage to see if the...
by colinmchugo Explorer in Splunk Search 08-04-2017
0 6
0
6
rwardwell
Hello, We currently have a use case to examine the permissions/access associated with a users Office365 or SharePoint...
by rwardwell Explorer in Splunk Search 08-04-2017
0 1
0
1
kteng2024
When I give admin_all_objects to a role, that role can also edit the permissions of the dashboards, but when I remove...
by kteng2024 Path Finder in Splunk Search 08-04-2017
0 2
0
2
raghu0463
Hi, Here I want to assign Initial_L1_Decision_Date dates to Queue_to_Initial_L1_Days. There are some dates for Initi...
by raghu0463 Explorer in Splunk Search 08-04-2017
0 4
0
4
deadbits
I am looking to create a way to track multiple types of events across different sources. For example, where 'web' is ...
by deadbits Explorer in Splunk Search 08-04-2017
1 4
1
4
iaintealecapite
I have a string of status codes per component, something, like this: 0113000000000000000 To determine what this mean...
by iaintealecapite Explorer in Splunk Search 08-04-2017
0 1
0
1
griffinpair
I have extracted a field from log files that is called file_Date and it is in the format "8/1/2017". How do get the d...
by griffinpair Path Finder in Splunk Search 08-04-2017
0 4
0
4
vshakur
I have a query that ends with: | eval error_message=mvindex(splited,0) | stats count as error_count by error_message...
by vshakur Path Finder in Splunk Search 08-04-2017
0 6
0
6
jcorkey
Below is my search string: | multisearch [search index="*" host="*" sourcetype="*" user="*" useradd "type=ADD_GROUP...
by jcorkey Explorer in Splunk Search 08-04-2017
0 1
0
1
rkaakaty
Hello, For some reason my SEVERITY, and CATEGORY field aren't showing any value.. Can anyone see why? index=nessu...
by rkaakaty Path Finder in Splunk Search 08-04-2017
0 11
0
11
sfrazer
This may have been asked before, but I'm having trouble finding it. I have weblogs that I've sliced into transaction...
by sfrazer Explorer in Splunk Search 08-04-2017
0 3
0
3
HeinzWaescher
Hi, I'm wondering why (and when) there is a different handling when a lot of searches are running at the same time ...
by HeinzWaescher Motivator in Splunk Search 08-04-2017
1 10
1
10
timm747747
Hey guys, I have a search that gives me a login from a country along with the user and the user's "work country". Un...
by timm747747 Path Finder in Splunk Search 08-04-2017
0 3
0
3
kulo
I found that the _time field in my event was a bit unusual 19756;10;7;mik;security;2017-08-04 10:57:33;test(20170731...
by kulo Engager in Splunk Search 08-04-2017
0 2
0
2
gadepoonam
I am trying to implement security use case to detect Multiple login from same Source IP. Source IP is dynamic, every ...
by gadepoonam Explorer in Splunk Search 08-03-2017
0 4
0
4
vishmehra
Can we add the values to the bar chart items that have been plotted?
by vishmehra New Member in Splunk Search 08-03-2017
0 7
0
7
honobe
For each subject in the search sentence, the count number is displayed. In addition to the information currently bein...
by honobe Explorer in Splunk Search 08-03-2017
0 2
0
2
honobe
For each subject in the search sentence, the count number is displayed. In addition to the information currently bein...
by honobe Explorer in Splunk Search 08-03-2017
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...