Splunk Search

Splunk Search
Community Activity
MM0071
Let's say im running a search where I want to look at domains traveled to.index=web_traffic sourcetype=domains domain...
by MM0071 Path Finder in Splunk Search 10-16-2023
0 9
0
9
karimoss
Hello,I want to detect workstations authenticated to the active directory that are not compliant with our naming conv...
by karimoss Loves-to-Learn in Splunk Search 10-16-2023
0 4
0
4
Yusuf
I am trying to use my windows event data to update users ID on panorama, however, running the below query in my es en...
by Yusuf Observer in Splunk Search 10-16-2023
0 0
0
0
AL3Z
Hi,Need an spl  from src_ip to dest_ip  would like to know the dest_url, logs and outbound traffic size. 
by AL3Z Builder in Splunk Search 10-16-2023
0 3
0
3
nivi
While doing a splunk search using a splunk query and retrieving logs in an automated matter, the job extraction only ...
by nivi New Member in Splunk Search 10-16-2023
0 2
0
2
claudiaG
Hi I have the use case that i need to find some direct links between different events of the same index and sourcetyp...
by claudiaG Engager in Splunk Search 10-15-2023
0 2
0
2
splunk_novice99
Hello, Im trying to use the data from one search in another search.  This is what I'm trying to do:-index=index_examp...
by splunk_novice99 Explorer in Splunk Search 10-14-2023
0 2
0
2
pgates
I'm having trouble getting a duration between two timestamps from some extracted fields.My search looks like this: My...
by pgates Explorer in Splunk Search 10-14-2023
0 4
0
4
parthiban
Hi @All , I want to extract the correlation_id for the below payload, can anyone help me to write rex command.{"messa...
by parthiban Path Finder in Splunk Search 10-14-2023
0 4
0
4
atebysandwich
I have a field called DNS whos field values contain the hostname in the lookup. There is also another field called Id...
by atebysandwich Path Finder in Splunk Search 10-14-2023
0 2
0
2
kc_prane
Hello,  I am searching to get results for each hour  top 1 max URL hits.  Iam using the below search but not getting ...
by kc_prane Communicator in Splunk Search 10-14-2023
0 3
0
3
av_
I want to extract Sample ID field value"Sample ID":"020ab888-a7ce-4e25-z8h8-a658bf21ech9"
by av_ Path Finder in Splunk Search 10-14-2023
0 2
0
2
mohammadsharukh
My data is coming for 0365 as JSON, I am using SPath to get the required fields after that i want to compare the data...
by mohammadsharukh Path Finder in Splunk Search 10-13-2023
0 3
0
3
tkerr1357
Hello all,  I could use some help here with creating a search. Ultimately I would like to know if a user is added to ...
by tkerr1357 Path Finder in Splunk Search 10-13-2023
0 3
0
3
anissabnk
Hello, I would like to calculate a weighted average on an average call time.The logs I have available are of this typ...
by anissabnk Path Finder in Splunk Search 10-13-2023
0 1
0
1
eranhauser
How to assign the value of param name original to the source in the | collect statementindex=123 | eval original=abcd...
by eranhauser Path Finder in Splunk Search 10-13-2023
0 5
0
5
lladi
I am creating a continuous error alert in Splunk. I have been working on constructing a search query to group differe...
by lladi Loves-to-Learn Lots in Splunk Search 10-13-2023
0 8
0
8
emcglade
Afternoon,We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered...
by emcglade Engager in Splunk Search 10-13-2023
0 0
0
0
mahesh27
Dashboard xml:I am using this dashboard  to Schedule PDF report, and all panels are showing data for 7 days.I need to...
by mahesh27 Communicator in Splunk Search 10-13-2023
0 5
0
5
atebysandwich
I need to search a field called DNS_Matched, that has multi-value fields, for events that have one or more values tha...
by atebysandwich Path Finder in Splunk Search 10-12-2023
0 2
0
2
Anthony3rd
Can someone help me with the Splunk code that would be necessary to search for the Idemia Machines?Thank youAnthony
by Anthony3rd Explorer in Splunk Search 10-12-2023
0 1
0
1
Deepika_R
0
2
shai
my question is very simple. This returns nothing: sourcetype=my_sourcetype This returns X amount of events (same amou...
by shai Explorer in Splunk Search 10-12-2023
0 7
0
7
rrovers
I have a search to get an overview of all users with their authorizations: roles, capabilities, indexes (search found...
by rrovers Contributor in Splunk Search 10-12-2023
0 5
0
5
Bleepie
Hi,How do I limit the results per host? I have any (random) search query. I have 10 hosts. For each hosts, hundreds o...
by Bleepie Communicator in Splunk Search 10-12-2023
0 1
0
1
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...
Top Solution Authors