Splunk Search

Splunk Search
Community Activity
mohammadsharukh
I am working to create a use case to detect account created and deleted within short period of timeCould you please g...
by mohammadsharukh Path Finder in Splunk Search 09-19-2023
0 1
0
1
CocoaCollette
How do I rename/conjoin/remove the space between the field "ThreeDSecureResult" and "description"? The value is comin...
by CocoaCollette New Member in Splunk Search 09-19-2023
0 1
0
1
srajabi
Hey I have the following query: ```| makeresults | eval prediction_str_body="[{'stringOutput':'Alpha','doubleOutput':...
by srajabi Engager in Splunk Search 09-19-2023
0 2
0
2
LearningGuy
Hello,How to pre-calculate and search historical data from correlation between index and CSV/DB lookup?For example:Fr...
by LearningGuy Motivator in Splunk Search 09-19-2023
0 2
0
2
BK_MSP
I had data like this in Splunk.DT=2023-09-13T23:59:56.029-0500|LogId=WFTxLog|AppId=SWBS|AppInst=server1:/apps/comp/sw...
by BK_MSP New Member in Splunk Search 09-19-2023
0 1
0
1
Yashvik
Hello All,I need to identify the top log sources which are sending large data to Splunk. Tried Licence master dashboa...
by Yashvik Explorer in Splunk Search 09-19-2023
0 8
0
8
neerajs_81
Hi All, just wondering if anyone has a search that shows which user deleted another user in Linux  ?Typically in the ...
by neerajs_81 Builder in Splunk Search 09-19-2023
0 3
0
3
ssaenger
Hi All,i have read similar posts but none that will get me to an answer.My log entry is this;2023-09-19 16:17:01,306 ...
by ssaenger Communicator in Splunk Search 09-19-2023
0 4
0
4
rjdefrancisco
The following works fine in the Search app:   ... | makemv delim=";" hashes | ...   The equivalent curl call   curl ....
by rjdefrancisco Explorer in Splunk Search 09-19-2023
0 2
0
2
thisissplunk
I want to list about 10 unique values of a certain field in a stats command. I cannot figure out how to do this. I fi...
by thisissplunk Builder in Splunk Search 09-19-2023
1 8
1
8
jip31
HiI have a basic questions about the inputs.conf fileIn our apps, we have a inputs.conf file under etc/apps/test/inpu...
by jip31 Motivator in Splunk Search 09-19-2023
0 1
0
1
MG
I have the actual list of indexes in a lookup file. I ran below query to find the list of indexes with the latest ing...
by MG Engager in Splunk Search 09-19-2023
0 8
0
8
RahulMisra
I have an output of   index=feds  | fillnull value="" | table httpRequest.clientIp labels{}.name awswaf:clientip:geo:...
by RahulMisra Engager in Splunk Search 09-19-2023
0 5
0
5
MScottFoley
I have logs with a Customer field where the name of the customer is not consistent.    customer=Bobs Pizza  customer=...
by MScottFoley Path Finder in Splunk Search 09-19-2023
0 5
0
5
ivan123357
Hi! I am faced with the following task and do not understand which way to go. I want to create an alert that will be ...
by ivan123357 Explorer in Splunk Search 09-19-2023
0 3
0
3
aditsss
Hi Team,Below is my querysearch index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settl...
by aditsss Motivator in Splunk Search 09-19-2023
0 6
0
6
kteng2024
I am looking for indexes which are utilizing only 10%-20% of storage allocated to them. Can i please know is there an...
by kteng2024 Path Finder in Splunk Search 09-19-2023
0 3
0
3
Marta88
Hi, I would like to know the difference between version 1 and version 2 of the stats command. Thank you Kind regards ...
by Marta88 Explorer in Splunk Search 09-19-2023
1 3
1
3
tayshawn
Hello everyone! We have a container service running on AWS ECS with Splunk log driver enabled (via HEC token). At mom...
by tayshawn New Member in Splunk Search 09-18-2023
0 1
0
1
BeaGarcia
Hello! I want to count how many different kind of errors appeared for different services. At the moment, I'm searchin...
by BeaGarcia New Member in Splunk Search 09-18-2023
0 1
0
1
Roy_9
Hello, I am trying to find the dates  when the host stopped sending logs to splunk in the last 6 months.I have used t...
by Roy_9 Motivator in Splunk Search 09-18-2023
0 4
0
4
JakeConcur
Incident: ERROR LookupOperator - The lookup table 'dropdownsLookup' does not exist. It is referenced by configuration...
by JakeConcur Engager in Splunk Search 09-18-2023
1 4
1
4
yuvrajsharma_13
Need help to write a generic query to capture PII Data ( social security numbers / credit card numbers /  email addre...
by yuvrajsharma_13 Explorer in Splunk Search 09-18-2023
0 1
0
1
Techie
Hi - I would like to join and sum the results and output The searches:index=test_index sourcetype="test_source"  clas...
by Techie Engager in Splunk Search 09-18-2023
0 8
0
8
vader13
I have six different SPL queries that I run on a specific IP Address.  Is it possible to save a search as a report, s...
by vader13 Explorer in Splunk Search 09-18-2023
0 2
0
2
Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...