Splunk Search

Splunk Search
Community Activity
pradiptam
Hi, I was able to run search queries in Splunk and the fields were getting automatically extracted in the Interestin...
by pradiptam Explorer in Splunk Search 01-01-2016
0 3
0
3
sc0tt
I would like to calculate the duration between the last two events in a transaction. An example transaction looks som...
by sc0tt Builder in Splunk Search 12-31-2015
0 1
0
1
jsven7
Suppose I have a field like this: a1234 Is there a way to grab all the letters that are immediately followed by numb...
by jsven7 Communicator in Splunk Search 12-31-2015
0 5
0
5
amylala
I want to calculate successRate for a combination of hotelId and useId with data model. It works with following query...
by amylala Explorer in Splunk Search 12-31-2015
0 4
0
4
vad34
Hi, Is it possible to define Server Class via IP address and not via host name in Select Forwarders section when cre...
by vad34 Path Finder in Splunk Search 12-31-2015
0 6
0
6
moe44688
Hi, I am using regex to extract a field. However, I need to make it permanent so that I don't have use regex in futur...
by moe44688 New Member in Splunk Search 12-31-2015
0 2
0
2
vad34
Hello Can someone write here the steps and what files do i have to edit in order filter windows events ? Tnx
by vad34 Path Finder in Splunk Search 12-31-2015
0 15
0
15
sdaruna
Hi, I need to index whole file data into splunk for a reason and i need to break that while searching. I understood ...
by sdaruna Explorer in Splunk Search 12-30-2015
0 3
0
3
sttang88
Hi everyone! I'm trying to use a transaction to group logs that match the following business-logic: all triggered a...
by sttang88 New Member in Splunk Search 12-30-2015
0 2
0
2
muellernc
I added a field cluster to all my events, so that I can search for results in a Hadoop cluster specified. I edited in...
by muellernc Engager in Splunk Search 12-30-2015
0 3
0
3
zamkov
I am trying to group a set of results by a field. I'd like to do this using a table, but don't think its possible. Si...
by zamkov Explorer in Splunk Search 12-30-2015
0 4
0
4
chburnett
So a sample of the data I'm working with is as follows TImestamp | ID | Amount 2015-12-30 09:50:45 | 1 | 28668 201...
by chburnett New Member in Splunk Search 12-30-2015
0 2
0
2
mikesangray
I've got a search that does a |table prior to doing an |eval for ldapfilter. The search results are displayed in a se...
by mikesangray Path Finder in Splunk Search 12-30-2015
0 2
0
2
SwatiApte
Hi, We want to represent two Criticality Zones for an attribute on a Chart. Based on a Critical Threshold Series (w...
by SwatiApte Path Finder in Splunk Search 12-30-2015
1 2
1
2
keerthana_k
Hi, I would like to know if there is a limit to the number of OR conditions that we can include as part of a search ...
by keerthana_k Communicator in Splunk Search 12-30-2015
0 5
0
5
muthvin
how to remove last character of a field value from the search results
by muthvin New Member in Splunk Search 12-30-2015
0 3
0
3
lbogle
Hello Splunkers, I am running two separate searches, both of which are running fine. The results of these two search...
by lbogle Contributor in Splunk Search 12-29-2015
0 1
0
1
daniel333
Is there a trick to adding search peers with a search head cluster? I have to add 20 new indexers very soon and I don...
by daniel333 Builder in Splunk Search 12-29-2015
0 3
0
3
bharathkumarnec
Hello All, Need help in building a search. Below is my log file events format: Event 1 -- RequestType1 Event 2 -- R...
by bharathkumarnec Contributor in Splunk Search 12-29-2015
0 2
0
2
JSkier
I have two indexes for ids (suricata) and proxy (Cisco WSA), I'd like to correlate when splunk finds an IDS alert and...
by JSkier Communicator in Splunk Search 12-29-2015
0 5
0
5
sandyganti13
Would it be something like: sourcetype="/var/log/secure" eventtype="su_authentication"
by sandyganti13 New Member in Splunk Search 12-29-2015
0 2
0
2
anphan1992
Hi, In my data I have a "Status" field. The status can be in one of 3 states: Connected, Connecting, Disconnected. I ...
by anphan1992 Engager in Splunk Search 12-29-2015
0 1
0
1
tjr1775
Hello All, been banging the head against the desk for awhile on this one; tried join, transaction, and a few other th...
by tjr1775 Path Finder in Splunk Search 12-29-2015
3 9
3
9
CYBR_AH
Hi All, I'm wondering what would be the best way to download the latest CSV from http://cyberthreatalliance.org/cryp...
by CYBR_AH Explorer in Splunk Search 12-29-2015
0 3
0
3
omuelle1
Hi, I have an issue with a search, that I also use as an alert, which is not finding current events: So the searc...
by omuelle1 Communicator in Splunk Search 12-29-2015
0 2
0
2
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors