Splunk Search

Splunk Search
Community Activity
Hema_Nithya
index=os source="/var/log/bitbucket" host=servera* Failedand evaluate them as failed packages  to install. Failed:pyt...
by Hema_Nithya Explorer in Splunk Search 11-02-2023
0 1
0
1
Jouman
Hi All,I am working on analyzing processing time among 10 devices and categorize all the evnets into 3 categories, in...
by Jouman Path Finder in Splunk Search 11-02-2023
0 11
0
11
LearningGuy
Hello,How to calculate distinct count with condition?How to calculate unique vuln that has score >0, group by ip?Befo...
by LearningGuy Motivator in Splunk Search 11-02-2023
0 5
0
5
LearningGuy
How to hide a field of a table but keep it for separate search?   Thank you for your helpFor example:  field "id" exi...
by LearningGuy Motivator in Splunk Search 11-02-2023
0 6
0
6
BoscoBaracus
Good mornign All,I have several logs with fields which have sibfield. I would like to be able to extract the subfield...
by BoscoBaracus Engager in Splunk Search 11-01-2023
0 2
0
2
smith_
Hi,I  need an spl to find the threshold for the respective domains.index=ss group="Threat Intelligence"| stats values...
by smith_ Builder in Splunk Search 11-01-2023
0 10
0
10
ojensen
Say I have events of the form:{<!-- --> something: "cool", subfield: {<!-- --> this: "may contain", arbitrary: ["...
by ojensen Explorer in Splunk Search 11-01-2023
0 1
0
1
hmi79
Is there a built-in solution in splunk that does the frequency analysis (for ex. on domain names) ?There is a solutio...
by hmi79 Loves-to-Learn in Splunk Search 11-01-2023
0 1
0
1
ravir_jbp
I am trying to remove T and Z from the output timestamp results. Can you please help me with the query to remove  and...
by ravir_jbp Explorer in Splunk Search 11-01-2023
0 4
0
4
smahoney
Haven't been able to find this, but I want to basically calculate up time percentage for a host based on 2 unique eve...
by smahoney Path Finder in Splunk Search 11-01-2023
0 7
0
7
Roy_9
Hello,I have a lookup where all the hostnames are available under the field called "title" with respect to teams.I wo...
by Roy_9 Motivator in Splunk Search 11-01-2023
0 9
0
9
duesser
Basically I have a search with a lot of fields, similar to this example:  | makeresults | eval aa1&#61;1, aa2&#61;2, aa1x&#61;3, ...
by duesser Path Finder in Splunk Search 11-01-2023
0 3
0
3
jip31
hello   I have a admin role when I create a field alias, I can see it in the props.conf file but when I run the searc...
by jip31 Motivator in Splunk Search 11-01-2023
0 2
0
2
sigma
Hi all,I have a forwarder in my cluster and it sends events to the indexers. The events are json formatted and I want...
by sigma Path Finder in Splunk Search 11-01-2023
0 1
0
1
Komal0113
From splunk user we are receiving logs but when it comes to Splunk search head its splitting into different events Ex...
by Komal0113 Loves-to-Learn in Splunk Search 11-01-2023
0 3
0
3
leenaut
Hello,    I have a table with a column recording the ID, I want to make each ID in the table a Hyperlink and click on...
by leenaut Loves-to-Learn in Splunk Search 10-31-2023
0 0
0
0
VatsalJagani
Hello Splunkers,I’m looking for the best algorithm to search for events. with the below criteria.I have a lookup with...
by SplunkTrust SplunkTrust in Splunk Search 10-31-2023
0 2
0
2
sathiyasun
below is the sample json log content the main filelds are default extracts but the nested aren't. Please help to extr...
by sathiyasun Explorer in Splunk Search 10-31-2023
0 2
0
2
karu0711
my DN field value "cn&#61;jsuwus, jkhzdhkjc,ou&#61;sdsfefv accounts,ou&#61;ffdsrew users,dc&#61;hgsywy,dc&#61;tre,dc&#61;hyt,dc&#61;kuhytr"I need...
by karu0711 Communicator in Splunk Search 10-31-2023
0 2
0
2
DanSec
I have a current search used in dashboards and alerts. It extracts fields from an existing field. I'm trying to edit ...
by DanSec Engager in Splunk Search 10-31-2023
0 2
0
2
riposans
I'm confused how to truncate from this log. how do I do it from props.conf or from the SPL command? Can anyone provid...
by riposans Explorer in Splunk Search 10-31-2023
0 2
0
2
jbanAtSplunk
Hi,How to create automatic tag if:eventtypes.conf[duo_authentication]search &#61; sourcetype&#61;json:duo type&#61;authentication...
by jbanAtSplunk Communicator in Splunk Search 10-31-2023
0 1
0
1
av_
Is there any prebuilt search (like rest command) to find the number of triggered alerts for a particular dashboard? i...
by av_ Path Finder in Splunk Search 10-31-2023
0 1
0
1
Dustem
Hi guys, I want to detect a service ticket (TGS) request (Windows event code 4769) that is not preceded by one of the...
by Dustem Explorer in Splunk Search 10-30-2023
0 11
0
11
GaryZ
I am looking to create an acronym from a dynamic string, by capturing the first letter of each broken substringHow do...
by GaryZ Path Finder in Splunk Search 10-30-2023
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors