Splunk Search

Splunk Search
Community Activity
leotoa
Hello all, I've recently observed activity that smells like beaconing. After trying to modify the searches provided ...
by leotoa New Member in Splunk Search 11-18-2015
0 1
0
1
jamesmarlowww
Can I set a token using a field found in a lookup table? I've been researching online, but I haven't found a real sol...
by jamesmarlowww Path Finder in Splunk Search 11-18-2015
1 6
1
6
stanvv
Hi, I only want to index files containing the string #! in the first 5 characters of the file. Therefore, I created ...
by stanvv New Member in Splunk Search 11-18-2015
0 7
0
7
the_wolverine
Do these settings take effect on both SH and indexer? # the maximum number of concurrent searches per CPU max_search...
by the_wolverine Champion in Splunk Search 11-18-2015
1 1
1
1
track16
I have a search: sourcetype="my_data"| stats count by queue which aggregates data in a table by the field queue. ...
by track16 Engager in Splunk Search 11-18-2015
0 4
0
4
tmarlette
I have a long, that gets pretty long, and currently splunk is ingesting it as a whole. this log gets up a couple hund...
by tmarlette Motivator in Splunk Search 11-18-2015
0 8
0
8
mjd555
So I have the following search: Index="Cyber" sourcetype=Response queue = "Incident" status ="resolved" | dedup tic...
by mjd555 Path Finder in Splunk Search 11-18-2015
1 10
1
10
pmccomb
I have email address' that are used as user names in two different source types in two different indices. I am tryi...
by pmccomb Explorer in Splunk Search 11-18-2015
0 8
0
8
akawacz
Hello, I would like to find the difference between values in a couple of fields for two months. I figured out how t...
by akawacz Path Finder in Splunk Search 11-18-2015
0 3
0
3
howyagoin
Hi, Obviously Splunk has some native understanding of LDAP for authentication, but my desire is to use it to look up...
by howyagoin Contributor in Splunk Search 11-18-2015
2 2
2
2
lassel
Hi, I want to do this, but I'd prefer to do it in Simple XML. Is it possible? http://docs.splunk.com/Documentation/S...
by lassel Communicator in Splunk Search 11-18-2015
0 2
0
2
steenbergend
Hello, I'm trying to solve for a standard error formula in the number of observations I have for all hbss dlp events...
by steenbergend New Member in Splunk Search 11-17-2015
0 2
0
2
splunker1981
Evening Splunk experts, I am stuck trying to perform an extraction. I am using the built-in tool, but it keeps gene...
by splunker1981 Path Finder in Splunk Search 11-17-2015
0 7
0
7
rlaan
I am experiencing a problem with finding logs using keyword searching for anomalies in log files. The search string b...
by rlaan Path Finder in Splunk Search 11-17-2015
0 3
0
3
bruceclarke
I have an HTML panel and custom javascript on my dashboard. The panel has a few inputs that I want the user to popula...
by bruceclarke Contributor in Splunk Search 11-17-2015
0 1
0
1
br0dy
I'm trying to find which hosts a particular user has logged in to. I have the user's name, but I cannot figure out th...
by br0dy New Member in Splunk Search 11-17-2015
0 2
0
2
ciir
Hi @ all, I'm using this search: sourcetype=wineventlog:system (EventCode=20001) | table _time, EventCode, Computer...
by ciir Explorer in Splunk Search 11-17-2015
0 7
0
7
k2skaterii
I am running version 6.3.0 on my indexer and all my universal forwarders. I'm currently trying to get things configu...
by k2skaterii Path Finder in Splunk Search 11-17-2015
0 3
0
3
edlam
I ran below search over 11 millions record to plot a graph:- sourcetype="syslog" | search query: | timechart count b...
by edlam New Member in Splunk Search 11-17-2015
0 3
0
3
pinalshah341
I have a search: index="production" [search source="port-120" "Decision Received: REJECT"| fields x_reqid] | rex fi...
by pinalshah341 Loves-to-Learn in Splunk Search 11-16-2015
0 4
0
4
jcrombie
Using Splunk 6.3 I have a search that extracts from JSON from a log entry (packed as log4j), then rex out a Lat Long...
by jcrombie New Member in Splunk Search 11-16-2015
0 3
0
3
BrandSentiment
I have created a delim operator as follows: | makemv delim="," TONE which returns the following values in the TO...
by BrandSentiment Explorer in Splunk Search 11-16-2015
0 3
0
3
aniketb
My logs have the following info: userid, version, timestamp What is the best way to get a report of what product ve...
by aniketb Path Finder in Splunk Search 11-16-2015
0 2
0
2
slatta
I have many events, but only want to select those that have the same docId in order to compare the Durations of 2 dif...
by slatta Explorer in Splunk Search 11-16-2015
0 1
0
1
pc1234
how can i determine which events contain values that are > the avg value for all the events? I'd also like to count ...
by pc1234 Explorer in Splunk Search 11-16-2015
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors