Splunk Search

Splunk Search
Community Activity
Dustem
hi guys, I want to detect a service ticket request (Windows event code 4769) and one of the following corresponding e...
by Dustem Explorer in Splunk Search 09-07-2023
0 6
0
6
GaryZ
I'm having trouble capturing the custom key - "UserKey_ABC" in the following script.   With the following code, I'm n...
by GaryZ Path Finder in Splunk Search 09-07-2023
0 3
0
3
ft_kd02
Hi all, I've worked with multivalue fields in a limited capacity and I'm having trouble with a particular instance. G...
by ft_kd02 Path Finder in Splunk Search 09-07-2023
0 1
0
1
Olatundeny
index=xxxx sourcetype="Script:InstalledApps" DisplayName="Carbon Black Cloud Sensor 64-bit"I am trying to get the lis...
by Olatundeny Engager in Splunk Search 09-07-2023
0 5
0
5
gl89
Working my way through the Splunk e-learning offerings, I came across a lab exercise where the resulting query was ...
by gl89 Engager in Splunk Search 09-07-2023
0 4
0
4
simon_b
Hi, i have a duration in seconds and want to convert it to days, hours and minutes. The additional seconds should be ...
by simon_b Path Finder in Splunk Search 09-07-2023
0 3
0
3
phularah
I am trying to get data from 2 indexes and combine them via appendcols.The search is index="anon" sourcetype="test1" ...
by phularah Communicator in Splunk Search 09-07-2023
0 5
0
5
mafruma
I need to run a daily ldap search that will grab only the accounts that have change in the last 2 days. I can hard co...
by mafruma Explorer in Splunk Search 09-07-2023
0 5
0
5
Naga1
If I am having list of comma separated numbers in single splunk  event field:I am having too many event fields like b...
by Naga1 Loves-to-Learn Lots in Splunk Search 09-07-2023
0 18
0
18
Nikitha
If the above displayed data is the result for my stats command [stats values(Values) as Values by Category], how can ...
by Nikitha Explorer in Splunk Search 09-07-2023
0 4
0
4
harryhcg
Data: {"Field1":"xxx","message1":"{0}","message2":"xxx","message3":{"TEXT":"xxxx: xxx\r\n.xxxxx: {\"xxxxx\":{\"@CDI\"...
by harryhcg Explorer in Splunk Search 09-07-2023
0 8
0
8
bok007
Hi, Splunk defaults to 1 hour per column, how can I change that to 1 min per column to get a more detailed view?
by bok007 New Member in Splunk Search 09-07-2023
0 5
0
5
Splunk_sid
I have field in the event which has multi-line data (between double quotes) and I need to split them into individual ...
by Splunk_sid Explorer in Splunk Search 09-06-2023
0 3
0
3
short_cat
Is it possible to add some parameters in Splunk URL so that after clicking the URL, the viewer will see a well format...
by short_cat New Member in Splunk Search 09-06-2023
0 2
0
2
NunnuN
Greetings.I am quite new to Splunk and read a lot of sources.However, I have a hard time to find my answer about the ...
by NunnuN Engager in Splunk Search 09-06-2023
0 2
0
2
sjringo
I have an idea and am looking for some input on how to approach it, where to start.As mentioned in the subject.  I do...
by sjringo Contributor in Splunk Search 09-06-2023
0 3
0
3
NewToSplunk1
Goal: Being able to alert off the latest event if the event is more than 300 seconds and is not blank or "non-product...
by NewToSplunk1 Explorer in Splunk Search 09-06-2023
0 3
0
3
TorbinIT
Hello again!I'm working with two different sources of data both tracking the same thing but coming from different sou...
by TorbinIT Path Finder in Splunk Search 09-06-2023
0 2
0
2
Dustem
hi guys, I want to detect that more than 10 different ports of the same host are sniffed and scanned every 15 minutes...
by Dustem Explorer in Splunk Search 09-06-2023
0 0
0
0
Flenwy
Hello to all,i have the following Issue:I receive logs from an older machine for which I cannot adjust the logging se...
by Flenwy Explorer in Splunk Search 09-06-2023
0 6
0
6
joniba
I'm totally and utterly new to splunk. Just ran the dockerhub sample, and followed the instructions: https://hub.dock...
by joniba Engager in Splunk Search 09-06-2023
0 3
0
3
Ricco19
Is there any performance impact when used,index IN ("windows_server")OR index="windows_server"  ?
by Ricco19 Loves-to-Learn in Splunk Search 09-06-2023
0 1
0
1
avi7326
I want to calculate the error count from the logs . But the error are of two times which can be distinguish only from...
by avi7326 Path Finder in Splunk Search 09-06-2023
0 5
0
5
lucky
HI Team,how to write search query for cpu & memory utilization  please help on this  thanks
by lucky Explorer in Splunk Search 09-05-2023
0 2
0
2
sunnyleofremont
Hello,I am new to splunk and I trying to extract the fields using built-in feature.  Since the log format contain bot...
by sunnyleofremont New Member in Splunk Search 09-05-2023
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...