Splunk Search

Splunk Search
Community Activity
BinaryAddict
I'm wanting to avoid using saved searches and lookup tables as much if possible so it's easily maintainable by anyone...
by BinaryAddict Engager in Splunk Search 07-27-2023
0 2
0
2
Steve_A200
I am still trying to get my head around regular expressions in splunk, and would like to use regex that could parse t...
by Steve_A200 Path Finder in Splunk Search 07-27-2023
0 3
0
3
Altexec
Hello,I have an index with a field that record how long a computer has been running. Basically, when I display the in...
by Altexec New Member in Splunk Search 07-27-2023
0 1
0
1
DanAlexander
Hi All,Can anyone help me create a regex to extract the bolded parts from the following _raw log, please?meta sequenc...
by DanAlexander Communicator in Splunk Search 07-27-2023
0 7
0
7
GregSmith
I have a savedsearch running on a 5 minute cron schedule iteratively working through a list of previously saved searc...
by GregSmith Explorer in Splunk Search 07-27-2023
0 2
0
2
Ramana246
0
2
pierre_weg
Hi guys!I have a static snapshot lookup that stores a lot of information about vulnerabilities actives on my hosts in...
by pierre_weg Path Finder in Splunk Search 07-27-2023
0 2
0
2
mk00928640
Hello everyonePlease assist me in solving the problem below.I'm attempting to determine how to track it in Splunk if ...
by mk00928640 New Member in Splunk Search 07-27-2023
0 6
0
6
ykmohank
Hi, I want to do a search having multiple strings. Example: Consider,I am looking for SearchKey1 and SerachKey2 I...
by ykmohank New Member in Splunk Search 07-27-2023
0 3
0
3
leonuz01
Hi, I need help! I have this query. Ticket_Encryption_Type=0x17 Account_Domain="ad.contoso.com" but I need, pull all ...
by leonuz01 Engager in Splunk Search 07-26-2023
0 1
0
1
Teemanny
I have the code below and I need to get the statuses yesterday and today with respect to API value.My current search ...
by Teemanny Engager in Splunk Search 07-26-2023
0 7
0
7
Neel881
Hello everyone, I am trying to SUM the columns.  index="nzc-neel-uttar" source="http:kyhkp" | timechart span=1d count...
by Neel881 Path Finder in Splunk Search 07-26-2023
0 3
0
3
Naji
When I ran the following query:     index="myindex" sourcetype="hamlet" environment=staging | top limit=10 client | e...
by Naji Explorer in Splunk Search 07-26-2023
0 4
0
4
mahesh27
my query: index=abd ("start app" AND "app listed") |rex field=_raw "APP:\s+(<application1>\S+)" |rex field=_raw ...
by mahesh27 Communicator in Splunk Search 07-26-2023
0 4
0
4
Vig95
Hi,I am new to splunk, could you please help me with below SPL, I am trying to use stats and table commandWe have 4 e...
by Vig95 Engager in Splunk Search 07-26-2023
0 3
0
3
john_c_calhoun
I'm trying to create something that displays long term outages: any index that hasn't had traffic in the last hour.I'...
by john_c_calhoun Explorer in Splunk Search 07-26-2023
0 1
0
1
sravan
In the below graph i see values displayed on top of each bar. How do i remove them?   
by sravan Explorer in Splunk Search 07-26-2023
0 1
0
1
Abhinav
Hi, Against my corporate account I want to enable webhook action to get all responses against a query in my Java API ...
by Abhinav Loves-to-Learn in Splunk Search 07-26-2023
0 0
0
0
bluewizard
I have the following search to track search usage, i have a list of user who i want to track in a csv file. However, ...
by bluewizard Explorer in Splunk Search 07-26-2023
0 2
0
2
Harish2
index=abc sourcetype=app_logs |stats count as events by host, host_ip |where events >0  When i schedule this as alert...
by Harish2 Path Finder in Splunk Search 07-26-2023
0 2
0
2
AA1
0
1
jip31
HiI have a field called ObjectD which is always different for each eventsBut in this field, there is always à charact...
by jip31 Motivator in Splunk Search 07-25-2023
0 18
0
18
Kirthika
I have the following query,   index="xxxx" source="*$Device_ID$*xxxx*" | eval Device_ID=mvindex(split(source,"/"),5) ...
by Kirthika Path Finder in Splunk Search 07-25-2023
0 6
0
6
anmar02930
I have a search that has "index=A", "Source=A", "Source=B" and both sources have the column "Address"I want to compar...
by anmar02930 Engager in Splunk Search 07-25-2023
0 1
0
1
swe
hi there, I want to display an image based on the result of a search. My dashboard has a "base search" which is use...
by swe Path Finder in Splunk Search 07-25-2023
1 6
1
6
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors