Splunk Search

Splunk Search
Community Activity
ananthan123
Hello, All of the sudden we have some uncertain usage and trying to under the usage, here are the same lines .... ...
by ananthan123 Explorer in Splunk Search 08-02-2017
0 1
0
1
smuderasi
host=dummy | eval Pattern='arb_usg_mps%06' | where like (source,'%Pattern%') doesnot work . can you help what's wro...
by smuderasi Explorer in Splunk Search 08-02-2017
0 2
0
2
jcorkey
I am receiving the audit.log data from a universal forwarder running on a Linux box Hello below is my search string ...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
jcorkey
trying to search for when sudo user1 adds user2 to a group and I want to extract the name of the user2 that was added...
by jcorkey Explorer in Splunk Search 08-02-2017
0 1
0
1
lim2
Want to label sc_status <= 304 as Ok and sc_status >= 400 as Error and get the Ok and Error counts and table the clie...
by lim2 Communicator in Splunk Search 08-02-2017
0 1
0
1
ringbbg
I have a simple search query to look for vpn alerts index=nm host = inyod1-jvpn1a-dmz8-lo0 syslog_message="*karachi*...
by ringbbg Engager in Splunk Search 08-02-2017
0 3
0
3
jerin1982
I am very new to regex and I need to extract anything that comes between "device_" and "_1_vol" as volume name. "de...
by jerin1982 New Member in Splunk Search 08-02-2017
0 4
0
4
sarahw3
I want to create a timechart based on 5 tags. I have tried | timechart count by tag |regex tag="Working|No_Images|Oth...
by sarahw3 Explorer in Splunk Search 08-02-2017
0 3
0
3
t_splunk_d
I trying figure out what is the best search query for reporting on the count of different unique status. Following i...
by t_splunk_d Path Finder in Splunk Search 08-02-2017
0 3
0
3
Aufex
Hi there, i try to buildup a firewall report: "sourcetype="firewall" action=blocked | table host src dest src_port ...
by Aufex Explorer in Splunk Search 08-01-2017
0 3
0
3
nkannan1984
I am using the following splunk query to combine the events in to one transaction based on the referenceid. It work...
by nkannan1984 Engager in Splunk Search 08-01-2017
0 3
0
3
tamakg
Hi, I'm trying to replace the host value using a field in the data. I tried to find any previous similar solution bu...
by tamakg Path Finder in Splunk Search 08-01-2017
0 4
0
4
rijinc
THis is my query i want to display a time chart where it should display the last 4week ( week by week) in a time char...
by rijinc Explorer in Splunk Search 08-01-2017
0 12
0
12
jcorkey
Below is my search string: index=* host=* sourcetype="*" "usermod" "add" "to shadow group" | rex "^(?:[^'\n]*'){3}(?...
by jcorkey Explorer in Splunk Search 08-01-2017
0 2
0
2
ankithreddy777
What is the difference between with or without using OUTPUT parameter in lookup command.
by ankithreddy777 Contributor in Splunk Search 08-01-2017
0 2
0
2
wormfishin
I'm running a query for a 1 hour window. I need to group events by a unique ID and categorize them based on another ...
by wormfishin Engager in Splunk Search 08-01-2017
1 4
1
4
karthi2809
I need only amber and severe but i am not getting any result base search|eval responseTime=TransactionEndtime-Trans...
by karthi2809 Builder in Splunk Search 08-01-2017
0 2
0
2
mintucs
| inputlookup kv_adani | where (tag="CHP.Device1.C1 BELT VW" ) | eval _time=tagtime |dedup _time| stats max(_time) a...
by mintucs New Member in Splunk Search 08-01-2017
0 3
0
3
jl19
I'm trying to sum a count from one event and group all of these summations by another events unique ID. The two event...
by jl19 Explorer in Splunk Search 08-01-2017
0 4
0
4
griffinpair
My current search (below) returns 3 results that has a field called "import_File" that contains either the text "Acco...
by griffinpair Path Finder in Splunk Search 08-01-2017
0 5
0
5
mumblingsages
I have a collection of log data in an index and for the purposes of this discussion _time has the value I want. When ...
by mumblingsages Path Finder in Splunk Search 08-01-2017
0 8
0
8
superhm
I want to get IP addresses that is not duplicated There is two example search that A and B. A search is index=AV ...
by superhm Explorer in Splunk Search 08-01-2017
0 4
0
4
hemendralodhi
Hello, For same base query I am getting different distinct count result in timechart and stats for same time range (...
by hemendralodhi Contributor in Splunk Search 07-31-2017
0 5
0
5
kteng2024
Hi There, Can i please know the ports to be opened for heavy forwarder , indexer , universal forwarder ?
by kteng2024 Path Finder in Splunk Search 07-31-2017
0 3
0
3
sylbaea
Hello, Does anybody see something wrong with this regex ? \w{3}S*ALTSIP*\d{1,2} When testing against my host lis...
by sylbaea Communicator in Splunk Search 07-31-2017
0 2
0
2
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...