Splunk Search

Splunk Search
Community Activity
Makinde
Hello, I have this search string to identify hosts that have stopped sending logs to Splunk, however the search stri...
by Makinde New Member in Splunk Search 07-13-2016
0 5
0
5
Makinde
I have vulnerability detection in Splunk where there is the possibility of duplicate QID, IP and PORT, so I run a sea...
by Makinde New Member in Splunk Search 07-13-2016
0 3
0
3
michael_sleep
Hey there, I've been learning how to use the search features in Splunk and trying to find a way to get some user-age...
by michael_sleep Communicator in Splunk Search 07-13-2016
0 7
0
7
akashjohn
Hi Team, I am looking for a Splunk search to get a statistics table output I am looking for is the SSH user account...
by akashjohn Explorer in Splunk Search 07-13-2016
0 4
0
4
Shark2112
Hey guys. I have events like this "ip delay|" every second: 10.161.30.19 0.290|10.2.10.151 0.793|10.2.10.152 0.596|1...
by Shark2112 Communicator in Splunk Search 07-13-2016
0 11
0
11
splunkids75
Hi everybody! My database has to many properties, but important properties to set in my Dashboard starting with "U" ...
by splunkids75 New Member in Splunk Search 07-13-2016
0 4
0
4
sim_tcr
Hello, We have two fields: elapsedMs and backendServiceMillis. Both have only numeric values. How can we display a n...
by sim_tcr Communicator in Splunk Search 07-13-2016
0 1
0
1
daniel333
All, We are currently getting a log like this from our F5. xff="1.2.3.4, 4.3.2.1, 4.2.2.2, 9.8.7.1" I'd like ...
by daniel333 Builder in Splunk Search 07-12-2016
0 2
0
2
rashid47010
I have one CSV file containing important user names. I want to create an alert/correlation rule whenever the user fro...
by rashid47010 Communicator in Splunk Search 07-12-2016
0 2
0
2
brianlee12
I have a column chart with 4 bars, with the values 2, 10, 46, and 50. The spacing between these 4 bars are the same a...
by brianlee12 Engager in Splunk Search 07-12-2016
0 17
0
17
arulbalans
Query1-Results: ProxiesProcessed,Status Query2-Results: ProxiesProcessed,Audio_Tracks,year_mm_dd Join Query: ind...
by arulbalans Engager in Splunk Search 07-12-2016
0 5
0
5
wzgoda
For my data set, I am looking to see the sum of the number of events per distinct count of servers. Reasoning, I am l...
by wzgoda Explorer in Splunk Search 07-12-2016
0 5
0
5
rashid47010
how can I get/increase my reputation points to post the question
by rashid47010 Communicator in Splunk Search 07-12-2016
1 4
1
4
agemkowacc
Is the openssl vulnerability exploitable on all versions or certain older versions?
by agemkowacc New Member in Splunk Search 07-12-2016
0 1
0
1
mcgi906
Currently, I have a form with a search that populates a two column table, and am using one of the columns as a key to...
by mcgi906 Explorer in Splunk Search 07-12-2016
0 1
0
1
Jhand2016
I have a situation where we break out user classes by adding numeric characters at the end of their username. As an e...
by Jhand2016 Explorer in Splunk Search 07-12-2016
0 5
0
5
wrangler2x
I was under the impression that if I did index=_internal source="/opt/splunk/var/log/splunk/splunkd.log" realtime tha...
by wrangler2x Motivator in Splunk Search 07-12-2016
0 3
0
3
splunker9999
Hi, Need help on a Splunk subsearch. Below is our Splunk basic search which gives us few fields if it satisfies the...
by splunker9999 Path Finder in Splunk Search 07-12-2016
0 4
0
4
mmather67
In props.conf, I would like to create a field abc by saying: abc = "xyz". Is there any way to say this so that Splu...
by mmather67 Path Finder in Splunk Search 07-12-2016
2 12
2
12
sbattista09
I want to see the duration that a user has been logged in to the PC for. Would the transaction command work the best ...
by sbattista09 Contributor in Splunk Search 07-12-2016
0 2
0
2
sureshchinta
My app writes two log statements, audit and activity statement, for each invocation as below: audit: type:audit | ti...
by sureshchinta Explorer in Splunk Search 07-12-2016
0 5
0
5
kmccowen
query: index=ctap source="/charter/apps/gwtrbl/logs/troubleshooting*.log" host=sc58laopp0* End of Branch Execution : ...
by kmccowen Path Finder in Splunk Search 07-12-2016
0 2
0
2
warrenpage
I have a main centralized splunk index server with logs for 50+ hosts. I have a secondary Splunk instance for a smal...
by warrenpage Explorer in Splunk Search 07-12-2016
1 5
1
5
iisaphd
I am writing a search that will track when the firewall sees outbound traffic over non-standard ports. I have a requ...
by iisaphd Engager in Splunk Search 07-12-2016
0 2
0
2
kaskirana01
Hi, I have a list of executables uploaded as a lookup in Splunk and have proxy logs to compare against it. I need to...
by kaskirana01 New Member in Splunk Search 07-12-2016
0 5
0
5
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...