Splunk Search

Splunk Search
Community Activity
dsms
Hello I want to find in subsearch autonomous_system for the IP address which I provided (in this example for 1.1.1.1...
by dsms Engager in Splunk Search 09-11-2023
0 2
0
2
Akmal57
I have asset management data that i need to create weekly reports. When i make query for the data like query below: i...
by Akmal57 Path Finder in Splunk Search 09-11-2023
0 2
0
2
lucky
Hi  I need regular expression to extract field "timed out " by using below log .... "Description":"Job-2069950 Error ...
by lucky Explorer in Splunk Search 09-11-2023
0 22
0
22
dvg06
Hi Splunkers Need some help with a timechart query please. index=linux host IN (a,b,c,d,e) | timechart span=1week eva...
by dvg06 Path Finder in Splunk Search 09-10-2023
1 1
1
1
darphboubou
Hi, We wonder how to monitor the smbV1 access in a domain. We are already enabled the eventcode 3000 log on windows l...
by darphboubou Explorer in Splunk Search 09-10-2023
0 3
0
3
rick1168
how to  calculate the count for each field in the past 3 days. If the count for all 3 days is 0, and the count for to...
by rick1168 Engager in Splunk Search 09-10-2023
0 5
0
5
LearningGuy
Hello,How to perform lookup on inconsistent IPv6 format in CSV file from index?For example:Index has collapsed format...
by LearningGuy Motivator in Splunk Search 09-08-2023
0 9
0
9
alex4
I want to use the new search signature="test" in the below search. I don't want to add this new signature to the exis...
by alex4 Loves-to-Learn Lots in Splunk Search 09-08-2023
0 0
0
0
happylearning
I have indexes created and i have 2 csv first is ipv6.csv and its has coulmn called ip and second csv is cmd.csv it c...
by happylearning Loves-to-Learn in Splunk Search 09-08-2023
0 1
0
1
Bastiaan
Hello all,I'm quite new to the wonderful world of Splunk, but not new to monitoring or IT in general. We are optimizi...
by Bastiaan Engager in Splunk Search 09-08-2023
0 5
0
5
suvi6789
Hi, I want to create a table in the below format and provide the count for them.I have multiple fields in my index an...
by suvi6789 Path Finder in Splunk Search 09-08-2023
0 3
0
3
itnewbie
I have "Product Brand" multiselect filter in a Splunk dashboard. It is a dynamic filter rather than static. I also ha...
by itnewbie Explorer in Splunk Search 09-08-2023
0 2
0
2
Dustem
hi guys, I want to detect a service ticket request (Windows event code 4769) and one of the following corresponding e...
by Dustem Explorer in Splunk Search 09-07-2023
0 6
0
6
GaryZ
I'm having trouble capturing the custom key - "UserKey_ABC" in the following script.   With the following code, I'm n...
by GaryZ Path Finder in Splunk Search 09-07-2023
0 3
0
3
ft_kd02
Hi all, I've worked with multivalue fields in a limited capacity and I'm having trouble with a particular instance. G...
by ft_kd02 Path Finder in Splunk Search 09-07-2023
0 1
0
1
Olatundeny
index=xxxx sourcetype="Script:InstalledApps" DisplayName="Carbon Black Cloud Sensor 64-bit"I am trying to get the lis...
by Olatundeny Engager in Splunk Search 09-07-2023
0 5
0
5
gl89
Working my way through the Splunk e-learning offerings, I came across a lab exercise where the resulting query was ...
by gl89 Engager in Splunk Search 09-07-2023
0 4
0
4
simon_b
Hi, i have a duration in seconds and want to convert it to days, hours and minutes. The additional seconds should be ...
by simon_b Path Finder in Splunk Search 09-07-2023
0 3
0
3
phularah
I am trying to get data from 2 indexes and combine them via appendcols.The search is index="anon" sourcetype="test1" ...
by phularah Communicator in Splunk Search 09-07-2023
0 5
0
5
mafruma
I need to run a daily ldap search that will grab only the accounts that have change in the last 2 days. I can hard co...
by mafruma Explorer in Splunk Search 09-07-2023
0 5
0
5
Naga1
If I am having list of comma separated numbers in single splunk  event field:I am having too many event fields like b...
by Naga1 Loves-to-Learn Lots in Splunk Search 09-07-2023
0 18
0
18
Nikitha
If the above displayed data is the result for my stats command [stats values(Values) as Values by Category], how can ...
by Nikitha Explorer in Splunk Search 09-07-2023
0 4
0
4
harryhcg
Data: {"Field1":"xxx","message1":"{0}","message2":"xxx","message3":{"TEXT":"xxxx: xxx\r\n.xxxxx: {\"xxxxx\":{\"@CDI\"...
by harryhcg Explorer in Splunk Search 09-07-2023
0 8
0
8
bok007
Hi, Splunk defaults to 1 hour per column, how can I change that to 1 min per column to get a more detailed view?
by bok007 New Member in Splunk Search 09-07-2023
0 5
0
5
Splunk_sid
I have field in the event which has multi-line data (between double quotes) and I need to split them into individual ...
by Splunk_sid Explorer in Splunk Search 09-06-2023
0 3
0
3
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...