Splunk Search

Splunk Search
Community Activity
SteveHaleyClark
I'm trying to determine how I can export a full list of usernames and email addresses - can anyone advise?
by SteveHaleyClark New Member in Splunk Search 04-19-2017
0 1
0
1
davesplunk01
search error from the search.log (job inspect - search.log). DispatchThread - Error reading runtime settings: File /...
by davesplunk01 Path Finder in Splunk Search 04-19-2017
0 4
0
4
smaran06
Hi All, This give me value by subtracting 7 days from now |stats count | eval next_time=relative_time(now(),"-7d@d"...
by smaran06 Path Finder in Splunk Search 04-19-2017
1 9
1
9
greco7760
Short story, alert results to populate proxy query of dependent time ranges. Longer story- So essentially lets say I...
by greco7760 New Member in Splunk Search 04-19-2017
0 12
0
12
pradjswl
By default regex uses _raw field in the field extractor. I dont want to use regex as part of the query but I want a f...
by pradjswl Explorer in Splunk Search 04-19-2017
0 15
0
15
snix
I am trying to get a count of successful logins into our web site. The issue is depending on if the user has register...
by snix Communicator in Splunk Search 04-19-2017
0 9
0
9
mlevsh
Can someone advice on the Splunk search to generate the list of users and associated Active Directory (AD) groups? We...
by mlevsh Builder in Splunk Search 04-19-2017
0 6
0
6
raindrop18
I have this search and I keep getting "Error in 'geostats' command: The argument 'over' is invalid". How I can replac...
by raindrop18 Communicator in Splunk Search 04-19-2017
0 4
0
4
Chinmai
Hello Guys, I have a pie chart in my dashboard, so whenever the search returns nothing, the pie chart should conver...
by Chinmai Explorer in Splunk Search 04-19-2017
0 6
0
6
leomedina
Hello all, I am attempting to extract a Transaction ID and display this as _time, trans, status index=datapower env...
by leomedina Explorer in Splunk Search 04-19-2017
0 8
0
8
biec1
index=index_name earliest=-30m@m latest=now | stats latest(_time) as _time avg(cpu_usage) as cpu_usage by host | eva...
by biec1 Explorer in Splunk Search 04-19-2017
0 3
0
3
tyarrish
Hello, I'm trying to build a search against our DNS records, and I have a CSV file that contains a whitelist of domai...
by tyarrish New Member in Splunk Search 04-19-2017
0 9
0
9
bugnet
Hey all, I'm trying to create table for SOC members that shows number of attacks from each security device + summary...
by bugnet Path Finder in Splunk Search 04-19-2017
0 8
0
8
bugnet
Hi, I'm trying to to add a new field with constant value to my table. The new field is "Action" when "B" is constant...
by bugnet Path Finder in Splunk Search 04-19-2017
0 8
0
8
eepperman
I'd like to be able to include the search run time in the search results. If we have two different searches and we a...
by eepperman Engager in Splunk Search 04-19-2017
3 3
3
3
arrowecssupport
Hi, I have two different field extractions that i need to use. The 1st one is used all the time for my system and I'...
by arrowecssupport Communicator in Splunk Search 04-19-2017
0 6
0
6
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to run a search, compare it against fields in a lookup...
by IRHM73 Motivator in Splunk Search 04-19-2017
0 5
0
5
bugnet
Hi all, There is a way to create if statment whose result will create a new field with a constant value? For exemp...
by bugnet Path Finder in Splunk Search 04-18-2017
1 2
1
2
danielgp89
Hello, I need your help!!! I want to make an alert if a search doesn't accomplish a certain result! Example: index...
by danielgp89 Path Finder in Splunk Search 04-18-2017
0 2
0
2
x05311
Splunk code to find Error description : index="inputfile" | rex "^(?P<reasoncode>[^\t]*)" | rex max_match=0 "<me...
by x05311 Explorer in Splunk Search 04-18-2017
0 1
0
1
gingerpower121
I understand you have to modify the indexes.conf, props.conf, and transforms.conf inside of the $SPLUNK/etc/system/lo...
by gingerpower121 Explorer in Splunk Search 04-18-2017
0 4
0
4
guru865
Hi all, I am working on a search which triggers when the total failures by users is greater than 10 in last 30min. ...
by guru865 Path Finder in Splunk Search 04-18-2017
0 3
0
3
nagarjuna280
I have an event which contains user id, and two more events which contains user id (same), transaction id (different...
by nagarjuna280 Communicator in Splunk Search 04-18-2017
0 3
0
3
TXITGUYII
Brand new to Splunk...... I have about enough experience with it to spell it. I have been tasked with a set of IP add...
by TXITGUYII New Member in Splunk Search 04-18-2017
0 2
0
2
lem
Hi, I need to graph data per Area split by WeekNumber: | chart Values by Area WeekNumber Both - Values and WeekNube...
by lem New Member in Splunk Search 04-18-2017
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...
Top Solution Authors