Splunk Search

Splunk Search
Community Activity
Niro
Hello,I'm trying to set up an alert when someone creates or modifies an Active Directory account with a uidNumber tha...
by Niro Explorer in Splunk Search 08-13-2023
0 2
0
2
Skwerl23
i'm trying to grab all items based on a field. the field is a "index" identifier from my data. but i only want the mo...
by Skwerl23 Loves-to-Learn Lots in Splunk Search 08-13-2023
0 3
0
3
rms_rms
Show if field "subject" contains one or more camel case strings like: LuckyChance to Receive a FREE IpadPro! ClaimNow...
by rms_rms Explorer in Splunk Search 08-13-2023
0 4
0
4
grotti
I have this current search:index=web| eval Year=strftime(_time,"%Y")| eval Month=date_month| eval success=if(status=2...
by grotti Engager in Splunk Search 08-13-2023
0 1
0
1
ishanmeena
Is there a way we can run selected correlation searches in a certain time-frame at once or in queue?Use Case: In case...
by ishanmeena Observer in Splunk Search 08-13-2023
0 5
0
5
sbondred
I have 2 lookup files aslookup1.csv andlookup2.csvlookup1.csv has the data as belowname, designation, server, ipaddre...
by sbondred Explorer in Splunk Search 08-12-2023
0 4
0
4
Gggflyer
I created a search to list servers and the last time a windows log reported.  command i am using is  Tstats latest(_t...
by Gggflyer New Member in Splunk Search 08-12-2023
0 3
0
3
iamsplunker
Hello Splunk Community,  I'm trying to extract fields from the cloudwatch events like 1)region 2)arn 3) startTime 4) ...
by iamsplunker Communicator in Splunk Search 08-12-2023
0 4
0
4
Simple_Search
Hey ya'll - I am attempting to create an efficient search to detect password compromises within some environments, th...
by Simple_Search Path Finder in Splunk Search 08-11-2023
0 1
0
1
AL3Z
Hi,I want to create an alert that triggers when a user_name  exist in a lookup table (e.g. group_names.csv). But I'm ...
by AL3Z Builder in Splunk Search 08-11-2023
0 1
0
1
mahesh27
I have mstats query it was working fine till last week but suddenly now the success count is not showing up correctly...
by mahesh27 Communicator in Splunk Search 08-11-2023
0 1
0
1
yohhpark
I have a search that takes quite some time to run.*using py to run the search with splunk api it returns by saying it...
by yohhpark Path Finder in Splunk Search 08-11-2023
0 3
0
3
nags
I have CSV File with delimiter "|" like sample below for new ingestion. I wanted to use standard sourcetype csv. But ...
by nags Engager in Splunk Search 08-11-2023
0 1
0
1
FelixLeh
We had a problem that certain fields weren't searchable. index=foo bar=* did not show any result even though interest...
by FelixLeh Contributor in Splunk Search 08-11-2023
0 1
0
1
vinothkumark
Hi All, I have a requirement to add new members to the existing SH Cluster.I have gone through the below link where i...
by vinothkumark Path Finder in Splunk Search 08-11-2023
0 2
0
2
naresh_553
Hi , Im trying to extract distinct email is as column and preparing some counts .For this im thinking to extract the ...
by naresh_553 New Member in Splunk Search 08-11-2023
0 2
0
2
itnewbie
I have a "Severity Level" field in both index A and index B.Their structure is like:  ==index A=== Severity Level 1 2...
by itnewbie Explorer in Splunk Search 08-11-2023
0 2
0
2
user33
Hi all. I’m kind of new to Splunk. I have data by day - this is the response time for each API call by day. I want to...
by user33 Path Finder in Splunk Search 08-10-2023
0 5
0
5
Jouman
Hi all,I have an table with the start time and stop time in each case as below.IDCase NameStart TimeStop Timeuser_1Ca...
by Jouman Path Finder in Splunk Search 08-10-2023
0 1
0
1
Jouman
Hi all,I am in a trouble to extract values from a structure. Here is the structure of a event:       Event{ ID: user...
by Jouman Path Finder in Splunk Search 08-10-2023
0 2
0
2
michaudel
I got a question where someone is looking for the hits to a page, but only on Fridays between 6PM and 2 AM the follow...
by michaudel Explorer in Splunk Search 08-10-2023
1 5
1
5
adminpulse
Hello, When i getting results while doing search query, the complete pages doesn't display. For example, I searched 9...
by adminpulse Loves-to-Learn Lots in Splunk Search 08-10-2023
0 0
0
0
venky1544
Hello splunkers, i have a simple timechart query for avg USED_SPACE of disks for last 4 days  index=abc sourectype=di...
by venky1544 Builder in Splunk Search 08-10-2023
0 4
0
4
jpillai
We have an index, say 'index1' that has log retention upto 7 days. As the log volume is huge, we dont want to retain ...
by jpillai Path Finder in Splunk Search 08-10-2023
0 11
0
11
devsru
Hi All,I am trying to pass a token link to another dashboard panel. My requirement is when I pass Windows Server Toke...
by devsru Explorer in Splunk Search 08-10-2023
0 20
0
20
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors