Splunk Search

Splunk Search
Community Activity
djce
Splunk recently fell over because the dispatch directory (on an ext2 filesystem) hit 32000 directory entries, so the ...
by djce Engager in Splunk Search 04-19-2016
3 5
3
5
OD_jfraher
This is the criteria I'm using: index=bcoat_logs sc_filter_result!=DENIED cs_host!="-" | stats count(cs_host) by cs_...
by OD_jfraher New Member in Splunk Search 04-18-2016
0 1
0
1
Catie_Carmody
The below returns the correct results, but I only get the RequestOne, RequestTwo, and meetscriteria fields when field...
by Catie_Carmody Engager in Splunk Search 04-18-2016
0 2
0
2
xvxt006
Hi, i have a simple query where i am getting response times by host. i want to get the sum of hosts as a filed. I ha...
by xvxt006 Contributor in Splunk Search 04-18-2016
0 7
0
7
monteirolopes
Hi, In my log, I have the same name field for three distinct values in the same event. For example: ... Security ID...
by monteirolopes Communicator in Splunk Search 04-18-2016
0 5
0
5
rafamss
Hi guys, I'm having a problem with my environment, we have 15 machines, 1 Master, 1 Deploy, 1 Universal Forwarder, 6...
by rafamss Contributor in Splunk Search 04-18-2016
5 4
5
4
LCM
As a note: 17:30 CET - 4,825 questions, 1,069 unanswered!?! There are so many answered questions still "open" / unti...
by LCM Contributor in Splunk Search 04-18-2016
5 7
5
7
Branden
Hello! I have some Windows event log data with 5 different event codes. I need to count by each of the event codes a...
by Branden Builder in Splunk Search 04-18-2016
0 2
0
2
helpmejesus
Hey fellow Splunkers, I have a very complex problem which I am attempting to solve and thought it couldn't hurt to a...
by helpmejesus Explorer in Splunk Search 04-18-2016
0 5
0
5
thom_larner
Hi all, I'm trying to build a simple dashboard that shows a simple graph of bytes sent by a web server. I realize th...
by thom_larner Engager in Splunk Search 04-18-2016
0 1
0
1
citizencrane
I have 2 searches which from the log I calculate a difference of a number at the current time and the beginning of th...
by citizencrane New Member in Splunk Search 04-18-2016
0 2
0
2
evan_roggenkamp
I am trying to build a table that will show the active alerts for SNMP trap data ingested via a text file. I can bu...
by evan_roggenkamp Path Finder in Splunk Search 04-18-2016
0 5
0
5
arkonner
I am using the search below for the locked out accounts - Should be possible to sort the result by the user with high...
by arkonner Path Finder in Splunk Search 04-18-2016
1 4
1
4
mcrawford44
I'm attempting to locate systems that have not logged into AD for 90 days. I am using the following search; index=f...
by mcrawford44 Communicator in Splunk Search 04-18-2016
0 4
0
4
Kavey
Hi everyone, I am currently trying to extract the date from the filename so I can use it for all events include in t...
by Kavey Path Finder in Splunk Search 04-18-2016
2 3
2
3
withool000
I am looking for the best solution for segregate data into multiple indexes. There are IP addresses (very vary) being...
by withool000 New Member in Splunk Search 04-17-2016
0 2
0
2
srinathd
How to extract xml data contained in AUDDET_STR field in the following event using transforms.conf settings? "2016-0...
by srinathd Contributor in Splunk Search 04-17-2016
0 1
0
1
cadence_asif
Hello Experts, Can you please help me with a search to join these four lookups on login (unique field). Lookups LOO...
by cadence_asif Observer in Splunk Search 04-16-2016
0 2
0
2
rusty009
I am trying to run a search which sets a new value depending on another field value. Below is my serach: index = my...
by rusty009 Path Finder in Splunk Search 04-16-2016
0 5
0
5
packet_hunter
Scenario: I am matching dns queries to the domains listed in malware_domainsdm.csv. The .csv has multiple fields th...
by packet_hunter Contributor in Splunk Search 04-15-2016
0 2
0
2
samarkumar
Hi I created a report with Table data and bar chart together. When I embed this report and use iframe codes in the...
by samarkumar Path Finder in Splunk Search 04-15-2016
0 1
0
1
ssackrider
How to count how many events are over 1 yr old? And better yet, how to show a pie chart comparing against the entire...
by ssackrider Explorer in Splunk Search 04-15-2016
0 2
0
2
jj85
I have created a search that searches for any Windows logon events in my environment. index=windows EventID=528 OR...
by jj85 Engager in Splunk Search 04-15-2016
0 3
0
3
phudinhha
Good afternoon, everyone I'm looking for a solution for my idea like this: Today, I want to create a first baseline ...
by phudinhha Explorer in Splunk Search 04-15-2016
0 2
0
2
hmdoan
I need to calculate some MTTR numbers based on NOC work shifts. In particular these shifts: First Front: Sun-Wed 07...
by hmdoan Explorer in Splunk Search 04-15-2016
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors