Splunk Search

Splunk Search
Community Activity
Niro
Hello, I have an alert that sends an email when there are x authentication failures , this works fine and returns use...
by Niro Explorer in Splunk Search 08-04-2023
0 6
0
6
isxtn
So, this PCRE regex works in testers, but not on Splunk.    ^((http[s]?):\/)?\/?([^:\/\s]+)((\w+)*\/){2})   Should re...
by isxtn Explorer in Splunk Search 08-04-2023
0 2
0
2
t-
Needing some help building a dashboard that will display the Dat Set Version of all Linux machines on the network. An...
by t- New Member in Splunk Search 08-04-2023
0 2
0
2
lemospt
Hi, i have the following case,An operation has multiple events and every event of an operation is related by field Pu...
by lemospt Explorer in Splunk Search 08-04-2023
0 2
0
2
jhilton90
I am ingesting advanced hunting logs and I have a main dashboard where I present the number of events per Event Categ...
by jhilton90 Path Finder in Splunk Search 08-04-2023
0 7
0
7
eholz1
Hello All,I would like some suggestions. I am trying to search the Cisco ASA sourcetype in Splunk for the current use...
by eholz1 Builder in Splunk Search 08-04-2023
0 2
0
2
robertgiffin
I have a set of data that I upload into Splunk every morning as a .csv file because the tool doesn't feed the particu...
by robertgiffin Explorer in Splunk Search 08-04-2023
0 4
0
4
Talking_Master
Hi Iam looking to create an if statement:  if value  contains part of another value  it changes it too another value....
by Talking_Master Explorer in Splunk Search 08-04-2023
0 3
0
3
Questioner
I want to rename row value by data case. (It is line chart)The line chart row name changed  by token $value$if value ...
by Questioner Path Finder in Splunk Search 08-04-2023
0 6
0
6
stwong
Hello,We've an application with logs looks like following.  See below for some sample cases of single connection.With...
by stwong Communicator in Splunk Search 08-04-2023
0 3
0
3
scumbum
My event data contains the following:target: [      {        alternateId: application1       detailEntry: {        } ...
by scumbum New Member in Splunk Search 08-04-2023
0 1
0
1
kevin_larsson
I have need of creating a dashboard that will compare 2 sets of data from different times. Thus, I need to bypass the...
by kevin_larsson New Member in Splunk Search 08-04-2023
0 1
0
1
RubenElias
Hii all... Hope you can help me with two questions 1)Trying to create a query to find if the target user that set to ...
by RubenElias Loves-to-Learn Everything in Splunk Search 08-04-2023
0 1
0
1
isxtn
I am trying to dig through some records and trying to get the q (query) from the raw data, but I keep getting data ba...
by isxtn Explorer in Splunk Search 08-03-2023
0 1
0
1
power12
I am trying to make first two columns of a table output to be sticky...I can do one by using      <html> <st...
by power12 Communicator in Splunk Search 08-03-2023
0 3
0
3
atebysandwich
I have two fields: Network_Address and Netmask. The Network_Address field has the network address of the network as f...
by atebysandwich Path Finder in Splunk Search 08-03-2023
0 8
0
8
jpvlsmv
The documentation (9.0.2 Search Reference)  describes a function ipmask(<mask>,<ip>) that is supposed to apply the gi...
by jpvlsmv Path Finder in Splunk Search 08-03-2023
1 2
1
2
bosseres
Hello, everyone! I have search, which ends in such way ... | table id, name| outputlookup my_lookup.csv so my search ...
by bosseres Contributor in Splunk Search 08-03-2023
0 5
0
5
sarit_s
Hello I have sources that contain white spaces and I wand to count them What is the regex to find all the sources wit...
by sarit_s Communicator in Splunk Search 08-03-2023
0 5
0
5
sahil237888
Need help in creating splunk query to show value of fields as Zero having null values and for numeric it should show ...
by sahil237888 Path Finder in Splunk Search 08-03-2023
0 3
0
3
Thulasinathan_M
Hello Splunk Experts, I'm searching for ERRORS and WARN in the application from different servers and trying to colle...
by Thulasinathan_M Contributor in Splunk Search 08-03-2023
0 5
0
5
ktc78
Hi all,I just upgraded splunk enterprise from 8.1.2 to 8.2.6.1And I found some of big searches return below message w...
by ktc78 Explorer in Splunk Search 08-03-2023
0 3
0
3
DG3bran
hello engineers good afternoon I have a problem I hope you can help me to solve it. How can I do to validate if the i...
by DG3bran Explorer in Splunk Search 08-02-2023
0 7
0
7
power12
Hello Splunkers ,I have created a script and places in    <splunk_home>/etc/apps/search/bin/seq.py    Below is the sc...
by power12 Communicator in Splunk Search 08-02-2023
0 1
0
1
psimoes
I'm trying to do a simple query to get a hostname from events in a different sourcetype. I have a event in sourcetype...
by psimoes Loves-to-Learn in Splunk Search 08-02-2023
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...