Splunk Search

Splunk Search
Community Activity
mikeyty07
I have this multivalue fields where i am tring to rex and get particular field value like "value":"ESC1000",  but ins...
by mikeyty07 Communicator in Splunk Search 10-16-2023
0 6
0
6
atebysandwich
I have two fields: DNS and DNS_Matched. The latter is a multi-value field. How can I see if a field value in DNS is i...
by atebysandwich Path Finder in Splunk Search 10-16-2023
0 10
0
10
johnnymc
hello, i would like to find days in which a particular sourcetype is missing. With this, i'll drive an alert. for no...
by johnnymc Path Finder in Splunk Search 10-16-2023
1 12
1
12
MM0071
Let's say im running a search where I want to look at domains traveled to.index=web_traffic sourcetype=domains domain...
by MM0071 Path Finder in Splunk Search 10-16-2023
0 9
0
9
karimoss
Hello,I want to detect workstations authenticated to the active directory that are not compliant with our naming conv...
by karimoss Loves-to-Learn in Splunk Search 10-16-2023
0 4
0
4
Yusuf
I am trying to use my windows event data to update users ID on panorama, however, running the below query in my es en...
by Yusuf Observer in Splunk Search 10-16-2023
0 0
0
0
AL3Z
Hi,Need an spl  from src_ip to dest_ip  would like to know the dest_url, logs and outbound traffic size. 
by AL3Z Builder in Splunk Search 10-16-2023
0 3
0
3
nivi
While doing a splunk search using a splunk query and retrieving logs in an automated matter, the job extraction only ...
by nivi New Member in Splunk Search 10-16-2023
0 2
0
2
claudiaG
Hi I have the use case that i need to find some direct links between different events of the same index and sourcetyp...
by claudiaG Engager in Splunk Search 10-15-2023
0 2
0
2
splunk_novice99
Hello, Im trying to use the data from one search in another search.  This is what I'm trying to do:-index=index_examp...
by splunk_novice99 Explorer in Splunk Search 10-14-2023
0 2
0
2
pgates
I'm having trouble getting a duration between two timestamps from some extracted fields.My search looks like this: My...
by pgates Explorer in Splunk Search 10-14-2023
0 4
0
4
parthiban
Hi @All , I want to extract the correlation_id for the below payload, can anyone help me to write rex command.{"messa...
by parthiban Path Finder in Splunk Search 10-14-2023
0 4
0
4
atebysandwich
I have a field called DNS whos field values contain the hostname in the lookup. There is also another field called Id...
by atebysandwich Path Finder in Splunk Search 10-14-2023
0 2
0
2
kc_prane
Hello,  I am searching to get results for each hour  top 1 max URL hits.  Iam using the below search but not getting ...
by kc_prane Communicator in Splunk Search 10-14-2023
0 3
0
3
av_
I want to extract Sample ID field value"Sample ID":"020ab888-a7ce-4e25-z8h8-a658bf21ech9"
by av_ Path Finder in Splunk Search 10-14-2023
0 2
0
2
mohammadsharukh
My data is coming for 0365 as JSON, I am using SPath to get the required fields after that i want to compare the data...
by mohammadsharukh Path Finder in Splunk Search 10-13-2023
0 3
0
3
tkerr1357
Hello all,  I could use some help here with creating a search. Ultimately I would like to know if a user is added to ...
by tkerr1357 Path Finder in Splunk Search 10-13-2023
0 3
0
3
anissabnk
Hello, I would like to calculate a weighted average on an average call time.The logs I have available are of this typ...
by anissabnk Path Finder in Splunk Search 10-13-2023
0 1
0
1
eranhauser
How to assign the value of param name original to the source in the | collect statementindex=123 | eval original=abcd...
by eranhauser Path Finder in Splunk Search 10-13-2023
0 5
0
5
lladi
I am creating a continuous error alert in Splunk. I have been working on constructing a search query to group differe...
by lladi Loves-to-Learn Lots in Splunk Search 10-13-2023
0 8
0
8
emcglade
Afternoon,We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered...
by emcglade Engager in Splunk Search 10-13-2023
0 0
0
0
mahesh27
Dashboard xml:I am using this dashboard  to Schedule PDF report, and all panels are showing data for 7 days.I need to...
by mahesh27 Communicator in Splunk Search 10-13-2023
0 5
0
5
atebysandwich
I need to search a field called DNS_Matched, that has multi-value fields, for events that have one or more values tha...
by atebysandwich Path Finder in Splunk Search 10-12-2023
0 2
0
2
Anthony3rd
Can someone help me with the Splunk code that would be necessary to search for the Idemia Machines?Thank youAnthony
by Anthony3rd Explorer in Splunk Search 10-12-2023
0 1
0
1
Deepika_R
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors