Splunk Search

Splunk Search
Community Activity
abazgwa21cz
I have an issues with lookup, i create a table  I want to exclude path in lookup table from my search, so i try this...
by abazgwa21cz Explorer in Splunk Search 10-23-2023
0 7
0
7
LearningGuy
How to create total average/median/max of field in a separate table?Thank you in advance| index=testindex| table comp...
by LearningGuy Motivator in Splunk Search 10-23-2023
0 6
0
6
HattrickNZ
I have the following graph: On the y-axis, 0 is on and 10 is off. Can I label it accordingly, but still present it...
by HattrickNZ Motivator in Splunk Search 10-23-2023
0 4
0
4
sekhar463
Hi All,i am using below search to monitor a status of process based on PID and usage we have tried by stopping the se...
by sekhar463 Path Finder in Splunk Search 10-23-2023
0 5
0
5
licroBI_0x1
Hi all,I been working on new rule and I just can't get it work fully. I know that there are many similar questions/an...
by licroBI_0x1 Explorer in Splunk Search 10-23-2023
0 2
0
2
abazgwa21cz
Hi guys , I just install misp42 app in my splunk , and add misp instance to splunk , it work   But i want compare fro...
by abazgwa21cz Explorer in Splunk Search 10-23-2023
0 0
0
0
Satyapv
Hello,I have 2 distinct indexes with distinct values.Want to create one final stats query from select fields of both ...
by Satyapv Engager in Splunk Search 10-22-2023
0 3
0
3
NitishUa
Hi Team,I'm currently receiving AWS CloudWatch logs in Splunk using the add-on. I'm developing a use case and need to...
by NitishUa Loves-to-Learn Lots in Splunk Search 10-22-2023
0 2
0
2
Mien
Hi, May I know, why is daily EPS on specific date get less than usually? Is there any factor or cause to the less EPS...
by Mien New Member in Splunk Search 10-22-2023
0 3
0
3
LearningGuy
How to count total row number of non-zero field?Thank you in advanceBelow is the data set:ipVulnerabilityScoreip1Vuln...
by LearningGuy Motivator in Splunk Search 10-22-2023
0 2
0
2
Naji
I am new to Splunk and I have the following message which I would like to parse into a table of columns:  {dt.trace_i...
by Naji Explorer in Splunk Search 10-22-2023
0 4
0
4
herrypeterlee
I have a data like:{"adult": false,  "genre_ids": [16, 10751], "id": 1135710, "original_language": "sv", "original_ti...
by herrypeterlee New Member in Splunk Search 10-22-2023
0 2
0
2
oneemailall
Cheers,I am hoping to get some help on a splunk search to generate a badging report.I'll explain further.There are tw...
by oneemailall Engager in Splunk Search 10-22-2023
0 6
0
6
Taruchit
Hello All,I have a lookup file which stores a set of SPLs and it periodically gets refreshed.How to build a search qu...
by Taruchit Contributor in Splunk Search 10-22-2023
0 3
0
3
Muthu_Vinith
Hi allI have a combined lookup data with a fields containing various values like aaa acc aan, and more. I'm looking t...
by Muthu_Vinith Path Finder in Splunk Search 10-22-2023
0 1
0
1
ttovarzoll
I am trying to write a Report which queries our Windows Security Event logs for event # 4738, "user account was chang...
by ttovarzoll Path Finder in Splunk Search 10-21-2023
0 8
0
8
tamduong16
Hi I'm new to Splunk and currently trying to understand how the search function work. How could I get Splunk to displ...
by tamduong16 Contributor in Splunk Search 10-20-2023
0 9
0
9
ritzz
for my mail logs in JSON format, with my splunk query I created below tablemail frommail submail toABCaccount created...
by ritzz Loves-to-Learn Lots in Splunk Search 10-20-2023
0 2
0
2
waJesu
How do I use a lookup table to filter events based on a list of known malicious IP addresses (in CIDR format), or to ...
by waJesu Path Finder in Splunk Search 10-20-2023
0 3
0
3
ktaeil
_Raw json format is below{<!-- -->"test-03": {<!-- -->"field1": 97869,"field2": 179771,"field3": "test-03","traffics": 1070140210},"t...
by ktaeil Engager in Splunk Search 10-20-2023
0 1
0
1
yaswanth1992
Below is our RequirementLookup file has just one column DatabaseName, this is the left datasetDatabaseNameABC My Sear...
by yaswanth1992 New Member in Splunk Search 10-19-2023
0 4
0
4
POR160893
Hi, I have created a dashboard to filter firewall statuses. One of the inputs I need is a checkbox to eliminate dupli...
by POR160893 Builder in Splunk Search 10-19-2023
0 10
0
10
yuanliu
When I use timechart, if some trailing buckets have zero count, they are displayed as zero on the time axis that exte...
by SplunkTrust SplunkTrust in Splunk Search 10-19-2023
0 2
0
2
ktaeil
when i made a log for HEC with json array, im not sure what is more better way to use spl.can someone advise me pleas...
by ktaeil Engager in Splunk Search 10-19-2023
0 1
0
1
bmanikya
 Above is the event, not sure why this is showing up as two different events. Anyways, I have written a splunk query ...
by bmanikya Loves-to-Learn Everything in Splunk Search 10-19-2023
0 9
0
9
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors