Splunk Search

Splunk Search
Community Activity
bugnet
Hey all, I'm trying to create table for SOC members that shows number of attacks from each security device + summary...
by bugnet Path Finder in Splunk Search 04-19-2017
0 8
0
8
bugnet
Hi, I'm trying to to add a new field with constant value to my table. The new field is "Action" when "B" is constant...
by bugnet Path Finder in Splunk Search 04-19-2017
0 8
0
8
eepperman
I'd like to be able to include the search run time in the search results. If we have two different searches and we a...
by eepperman Engager in Splunk Search 04-19-2017
3 3
3
3
arrowecssupport
Hi, I have two different field extractions that i need to use. The 1st one is used all the time for my system and I'...
by arrowecssupport Communicator in Splunk Search 04-19-2017
0 6
0
6
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to run a search, compare it against fields in a lookup...
by IRHM73 Motivator in Splunk Search 04-19-2017
0 5
0
5
bugnet
Hi all, There is a way to create if statment whose result will create a new field with a constant value? For exemp...
by bugnet Path Finder in Splunk Search 04-18-2017
1 2
1
2
danielgp89
Hello, I need your help!!! I want to make an alert if a search doesn't accomplish a certain result! Example: index...
by danielgp89 Path Finder in Splunk Search 04-18-2017
0 2
0
2
x05311
Splunk code to find Error description : index="inputfile" | rex "^(?P<reasoncode>[^\t]*)" | rex max_match=0 "<me...
by x05311 Explorer in Splunk Search 04-18-2017
0 1
0
1
gingerpower121
I understand you have to modify the indexes.conf, props.conf, and transforms.conf inside of the $SPLUNK/etc/system/lo...
by gingerpower121 Explorer in Splunk Search 04-18-2017
0 4
0
4
guru865
Hi all, I am working on a search which triggers when the total failures by users is greater than 10 in last 30min. ...
by guru865 Path Finder in Splunk Search 04-18-2017
0 3
0
3
nagarjuna280
I have an event which contains user id, and two more events which contains user id (same), transaction id (different...
by nagarjuna280 Communicator in Splunk Search 04-18-2017
0 3
0
3
TXITGUYII
Brand new to Splunk...... I have about enough experience with it to spell it. I have been tasked with a set of IP add...
by TXITGUYII New Member in Splunk Search 04-18-2017
0 2
0
2
lem
Hi, I need to graph data per Area split by WeekNumber: | chart Values by Area WeekNumber Both - Values and WeekNube...
by lem New Member in Splunk Search 04-18-2017
0 4
0
4
like2splunk
Hello, I'm running a streamstats command that prints out a series of previously-searched events. There are often more...
by like2splunk Explorer in Splunk Search 04-18-2017
0 6
0
6
mhassan24
Hi, I am trying to create a report that looks at two fields: mem and cpu It should display the count of mem and cpu ...
by mhassan24 Explorer in Splunk Search 04-18-2017
0 10
0
10
like2splunk
I want to REX an entire line if it contains a particular keyword. The event looks like this: 2017-03-08 10:34:34,067...
by like2splunk Explorer in Splunk Search 04-18-2017
0 2
0
2
splunkrocks2014
I wonder if Splunk is able to display a table statistic with the following layout. Does anyone know? Thanks Catego...
by splunkrocks2014 Communicator in Splunk Search 04-18-2017
0 2
0
2
theironcook
I have a DataModel named "AccessLogs" and it has a DataSet hierarchy that looks like this RootSearchDS // sourcetyp...
by theironcook Explorer in Splunk Search 04-18-2017
1 2
1
2
xsstest
I extracted a field named "apche_zhuji_sip", but the content is not accurate, some are not IP, how do I use regular e...
by xsstest Communicator in Splunk Search 04-18-2017
0 1
0
1
dhsetty
Hi Splunk Users, Observing an Issue while I try to Query the Splunk for Search Query returns only 50000 Events/Res...
by dhsetty Explorer in Splunk Search 04-18-2017
0 7
0
7
mstark31
I have a search that needs to either snap to 7am ( -7h@d+7h) or 7pm ( -7h@d+19h) depending on whether the time of sea...
by mstark31 Path Finder in Splunk Search 04-18-2017
0 5
0
5
Abarny
Hi guys, Can you tell me if is it possible to add a values on fields to the end of a table to an other fields Exem...
by Abarny Path Finder in Splunk Search 04-18-2017
0 2
0
2
craigwilkinson
Hi All, I've recently created a single value dashboard panel with % trend, and sparkline underneath showing the curr...
by craigwilkinson Path Finder in Splunk Search 04-18-2017
1 2
1
2
lloydknight
Hello Splunkers, My problem is nearly similar to this one, only not spaces. https://answers.splunk.com/answers/36982...
by lloydknight Builder in Splunk Search 04-17-2017
0 3
0
3
madstylex
Hi, I have a search string that shows the top 20 security related events by country on my Cisco ASA. eventtype=cisc...
by madstylex New Member in Splunk Search 04-17-2017
0 4
0
4
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...