Splunk Search

Splunk Search
Community Activity
atebysandwich
I have two fields: DNS and DNS_Matched. The latter is a multi-value field. How can I see if a field value in DNS is i...
by atebysandwich Path Finder in Splunk Search 10-16-2023
0 10
0
10
johnnymc
hello, i would like to find days in which a particular sourcetype is missing. With this, i'll drive an alert. for no...
by johnnymc Path Finder in Splunk Search 10-16-2023
1 12
1
12
MM0071
Let's say im running a search where I want to look at domains traveled to.index=web_traffic sourcetype=domains domain...
by MM0071 Path Finder in Splunk Search 10-16-2023
0 9
0
9
karimoss
Hello,I want to detect workstations authenticated to the active directory that are not compliant with our naming conv...
by karimoss Loves-to-Learn in Splunk Search 10-16-2023
0 4
0
4
Yusuf
I am trying to use my windows event data to update users ID on panorama, however, running the below query in my es en...
by Yusuf Observer in Splunk Search 10-16-2023
0 0
0
0
smith_
Hi,Need an spl  from src_ip to dest_ip  would like to know the dest_url, logs and outbound traffic size. 
by smith_ Builder in Splunk Search 10-16-2023
0 3
0
3
nivi
While doing a splunk search using a splunk query and retrieving logs in an automated matter, the job extraction only ...
by nivi New Member in Splunk Search 10-16-2023
0 2
0
2
claudiaG
Hi I have the use case that i need to find some direct links between different events of the same index and sourcetyp...
by claudiaG Engager in Splunk Search 10-15-2023
0 2
0
2
splunk_novice99
Hello, Im trying to use the data from one search in another search.  This is what I'm trying to do:-index=index_examp...
by splunk_novice99 Explorer in Splunk Search 10-14-2023
0 2
0
2
pgates
I'm having trouble getting a duration between two timestamps from some extracted fields.My search looks like this: My...
by pgates Explorer in Splunk Search 10-14-2023
0 4
0
4
parthiban
Hi @All , I want to extract the correlation_id for the below payload, can anyone help me to write rex command.{"messa...
by parthiban Path Finder in Splunk Search 10-14-2023
0 4
0
4
atebysandwich
I have a field called DNS whos field values contain the hostname in the lookup. There is also another field called Id...
by atebysandwich Path Finder in Splunk Search 10-14-2023
0 2
0
2
kc_prane
Hello,  I am searching to get results for each hour  top 1 max URL hits.  Iam using the below search but not getting ...
by kc_prane Communicator in Splunk Search 10-14-2023
0 3
0
3
av_
I want to extract Sample ID field value"Sample ID":"020ab888-a7ce-4e25-z8h8-a658bf21ech9"
by av_ Path Finder in Splunk Search 10-14-2023
0 2
0
2
mohammadsharukh
My data is coming for 0365 as JSON, I am using SPath to get the required fields after that i want to compare the data...
by mohammadsharukh Path Finder in Splunk Search 10-13-2023
0 3
0
3
tkerr1357
Hello all,  I could use some help here with creating a search. Ultimately I would like to know if a user is added to ...
by tkerr1357 Path Finder in Splunk Search 10-13-2023
0 3
0
3
anissabnk
Hello, I would like to calculate a weighted average on an average call time.The logs I have available are of this typ...
by anissabnk Path Finder in Splunk Search 10-13-2023
0 1
0
1
eranhauser
How to assign the value of param name original to the source in the | collect statementindex=123 | eval original=abcd...
by eranhauser Path Finder in Splunk Search 10-13-2023
0 5
0
5
lladi
I am creating a continuous error alert in Splunk. I have been working on constructing a search query to group differe...
by lladi Loves-to-Learn Lots in Splunk Search 10-13-2023
0 8
0
8
emcglade
Afternoon,We are currently having issues with duplicate JSON entries on our search heads which operate in a clustered...
by emcglade Engager in Splunk Search 10-13-2023
0 0
0
0
mahesh27
Dashboard xml:I am using this dashboard  to Schedule PDF report, and all panels are showing data for 7 days.I need to...
by mahesh27 Communicator in Splunk Search 10-13-2023
0 5
0
5
atebysandwich
I need to search a field called DNS_Matched, that has multi-value fields, for events that have one or more values tha...
by atebysandwich Path Finder in Splunk Search 10-12-2023
0 2
0
2
Anthony3rd
Can someone help me with the Splunk code that would be necessary to search for the Idemia Machines?Thank youAnthony
by Anthony3rd Explorer in Splunk Search 10-12-2023
0 1
0
1
Deepika_R
0
2
shai
my question is very simple. This returns nothing: sourcetype=my_sourcetype This returns X amount of events (same amou...
by shai Explorer in Splunk Search 10-12-2023
0 7
0
7
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...