Splunk Search

Splunk Search
Community Activity
Thulasinathan_M
Hi Splunk Experts,I've a big list of rex commands in my search query. While using dashboard I added those rex command...
by Thulasinathan_M Contributor in Splunk Search 08-25-2023
0 2
0
2
splunk219783
I thought this would be easy but i'm struggling.  I have a CSV of firewall rules from yesterday, and a CSV of Firewal...
by splunk219783 Path Finder in Splunk Search 08-25-2023
0 1
0
1
RahulMisra
I have a lookup file( with one column combinedrules{}) which would be dynamic and i want to run a scheduled search to...
by RahulMisra Engager in Splunk Search 08-25-2023
0 10
0
10
sekhar463
hi All, i am using below search to get status if any offline  and i want to create alert if status offline for more t...
by sekhar463 Path Finder in Splunk Search 08-25-2023
0 18
0
18
mikfro
HiWe have logs of images created in a series, like below. They are identified by a unique series id, the number of ev...
by mikfro Loves-to-Learn in Splunk Search 08-25-2023
0 2
0
2
superuser88
 INDEX Name generated (10 million new records every day)INDEX Fields username, secret, key Lookup file secrets.csv wi...
by superuser88 Engager in Splunk Search 08-25-2023
0 4
0
4
rstrong30
I simply need to timechart the numeric values from field that is being returned.  For exampleindex=proxy | timechart ...
by rstrong30 Loves-to-Learn in Splunk Search 08-24-2023
0 1
0
1
superuser88
I have two indexesIndex accounts: [user. payroll]Index employees: [user, emp_details, emp_information] I am trying to...
by superuser88 Engager in Splunk Search 08-24-2023
0 2
0
2
dural_yyz
I'm looking specifically at the index for _configtracker to audit changes to serverclass.conf file.  Because the natu...
by dural_yyz Motivator in Splunk Search 08-24-2023
0 3
0
3
Woodpecker
Hi,is it possible to search a field value and then count it for example first today and then add the count of the sam...
by Woodpecker Path Finder in Splunk Search 08-24-2023
0 0
0
0
muqeeiz
Hi, I have the following log lines:2023-08-23 06:27:13,551 DEBUG [org.keycloak.protocol.oidc.utils.RedirectUtils] (ex...
by muqeeiz Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
Splunk_321
I have a splunk query to get execution time of methods shown below   basesearch | where like(method,"A") OR like(met...
by Splunk_321 Path Finder in Splunk Search 08-24-2023
0 1
0
1
dwelbba00
I'm working on building a dashboard that will take a base report and parse it into different items that can be flagge...
by dwelbba00 New Member in Splunk Search 08-24-2023
0 5
0
5
hitong
Hi,   When I extract any fields from json log, following error is generated  "The extraction failed. If you are extra...
by hitong Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
woodlandrelic
HiI am trying to add % to the "by percent" column only.  I can't seem to get it to show.Thanks  
by woodlandrelic Path Finder in Splunk Search 08-23-2023
0 3
0
3
LearningGuy
Hello,How to join data from index and dbxquery without using JOIN, APPEND or stats command?Issue with JOIN:  limit of...
by LearningGuy Motivator in Splunk Search 08-23-2023
0 12
0
12
abi2023
| timechart span=1mon count by status | addtotals row=t col=f labelfield=Total True False "Not available" fieldname="...
by abi2023 Path Finder in Splunk Search 08-23-2023
0 2
0
2
mninansplunk
Hello,I'm still in the learning process of Splunk searches and I have been tasked to create a table that contains onl...
by mninansplunk Path Finder in Splunk Search 08-23-2023
0 5
0
5
pmunaret
Hi all, I encountered the problem in MLTK that the data from the search is passed in multiple chunks to my custom cla...
by pmunaret Explorer in Splunk Search 08-23-2023
1 2
1
2
saurabhkunte
Hello,I have a lookup file with data in following format name _timesrv-a.xyz.com 2017.07.23srv-b.wxyz.com 2017.07.23 ...
by saurabhkunte Path Finder in Splunk Search 08-23-2023
1 9
1
9
humi
Hi all, i count the number of ssl-login-fail for each hour. index... host... action="ssl-login-fail" | timechart span...
by humi Explorer in Splunk Search 08-23-2023
0 3
0
3
sulaimancds
index=o365 [ | inputlookup watchlistriskyusers.csv | rename email AS query | fields query ] sourcetype="o365:manageme...
by sulaimancds Engager in Splunk Search 08-23-2023
0 7
0
7
Coder1a
Hello, I am new to splunk rex, so need help for regex. In logs, i have extracted  string, however again i need to ext...
by Coder1a Loves-to-Learn in Splunk Search 08-23-2023
0 1
0
1
sahil237888
Need help in creating a query to get the result from one sourcetype and get other field values based on the output fr...
by sahil237888 Path Finder in Splunk Search 08-23-2023
0 2
0
2
Coder1a
Hello, I am new to splunk rex, need help for below to extract a value from string. rex "Error while calling database ...
by Coder1a Loves-to-Learn in Splunk Search 08-23-2023
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...