Splunk Search

Splunk Search
Community Activity
Wendy
Hi there, need a bit of help here.  Context:  Our organisation recently changed the `index` thus we need to update al...
by Wendy Explorer in Splunk Search 07-30-2023
0 5
0
5
sravan
I want to find time difference between two events (duration some operation took) and plot a graph which shows how muc...
by sravan Explorer in Splunk Search 07-30-2023
0 5
0
5
Anu1184
Hi , I am trying to extract aggregated errors from json message log coming from splunk event and categorising them ba...
by Anu1184 Explorer in Splunk Search 07-30-2023
0 3
0
3
Anu1184
I am retrieving operation details like operation name, total time etc from json message log coming as a part of splun...
by Anu1184 Explorer in Splunk Search 07-29-2023
0 2
0
2
jip31
Hi I need help to extract and to filter fields with rex and regex 1) i need to use a rex field on path wich end by "....
by jip31 Motivator in Splunk Search 07-28-2023
0 8
0
8
mikeyty07
I 've  two fields one is _time and another one is received_time.  I want to get the time differences between these tw...
by mikeyty07 Communicator in Splunk Search 07-28-2023
0 7
0
7
deepaksn1214
I m having a hard time trying to extract a string from a field from a splunk search using splunk regex , can someone ...
by deepaksn1214 Engager in Splunk Search 07-28-2023
0 1
0
1
eholz1
Hello Members, I have seen and used the accum command, but it does not quite give me what I want. I have this search ...
by eholz1 Builder in Splunk Search 07-28-2023
0 4
0
4
treven
I am attempting to extract attachment fields from our email logs using regex. Attachments like .jpg, .png, pdf, etc. ...
by treven Explorer in Splunk Search 07-28-2023
0 8
0
8
sh254087
I'm facing a weird issue. I'm not able to calculate percentage value when I use two variables/fields.I have a lookup ...
by sh254087 Communicator in Splunk Search 07-28-2023
0 2
0
2
Satheesh_red
Hi, Alert Query to monitor CPU usage every 5 minutes and send an email if it matches 5 of 6 bad samples (i.e., if my ...
by Satheesh_red Path Finder in Splunk Search 07-28-2023
0 9
0
9
jip31
HiI use a | stats min(_time) as time_min stats max(_time) as time_max command in my searchThe time is displayed in Un...
by jip31 Motivator in Splunk Search 07-28-2023
0 4
0
4
RemyaT
I have a Splunk query that helps me to visualize different APIs vs Time as below. Using this query I could see each l...
by RemyaT Explorer in Splunk Search 07-28-2023
0 2
0
2
Satheesh_red
Hi,I'm attempting to calculate the average of the last six CPU event values. If the average of those six events is gr...
by Satheesh_red Path Finder in Splunk Search 07-27-2023
0 1
0
1
BinaryAddict
I'm wanting to avoid using saved searches and lookup tables as much if possible so it's easily maintainable by anyone...
by BinaryAddict Engager in Splunk Search 07-27-2023
0 2
0
2
Steve_A200
I am still trying to get my head around regular expressions in splunk, and would like to use regex that could parse t...
by Steve_A200 Path Finder in Splunk Search 07-27-2023
0 3
0
3
Altexec
Hello,I have an index with a field that record how long a computer has been running. Basically, when I display the in...
by Altexec New Member in Splunk Search 07-27-2023
0 1
0
1
DanAlexander
Hi All,Can anyone help me create a regex to extract the bolded parts from the following _raw log, please?meta sequenc...
by DanAlexander Communicator in Splunk Search 07-27-2023
0 7
0
7
GregSmith
I have a savedsearch running on a 5 minute cron schedule iteratively working through a list of previously saved searc...
by GregSmith Explorer in Splunk Search 07-27-2023
0 2
0
2
Ramana246
0
2
pierre_weg
Hi guys!I have a static snapshot lookup that stores a lot of information about vulnerabilities actives on my hosts in...
by pierre_weg Path Finder in Splunk Search 07-27-2023
0 2
0
2
mk00928640
Hello everyonePlease assist me in solving the problem below.I'm attempting to determine how to track it in Splunk if ...
by mk00928640 New Member in Splunk Search 07-27-2023
0 6
0
6
ykmohank
Hi, I want to do a search having multiple strings. Example: Consider,I am looking for SearchKey1 and SerachKey2 I...
by ykmohank New Member in Splunk Search 07-27-2023
0 3
0
3
leonuz01
Hi, I need help! I have this query. Ticket_Encryption_Type=0x17 Account_Domain="ad.contoso.com" but I need, pull all ...
by leonuz01 Engager in Splunk Search 07-26-2023
0 1
0
1
Teemanny
I have the code below and I need to get the statuses yesterday and today with respect to API value.My current search ...
by Teemanny Engager in Splunk Search 07-26-2023
0 7
0
7
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors