Splunk Search

Splunk Search
Community Activity
AnilPujar
is there any function available in splunk which converts the data in string format to json, which is actually json da...
by AnilPujar Path Finder in Splunk Search 07-24-2023
0 3
0
3
Falko
I tried to determine the size of my indexes in preparation for a Splunk Cloud Migration. I figured I could use the "e...
by Falko Explorer in Splunk Search 07-24-2023
0 0
0
0
zacksoft_wf
I am running this in Splunk ES (Enterprise Security). My objective is to find out those savedsearch_name whose averag...
by zacksoft_wf Contributor in Splunk Search 07-24-2023
0 1
0
1
jwalzerpitt
I am trying to run the following tstats search: | tstats summariesonly=true estdc(Malware_Attacks.dest) as "infected...
by jwalzerpitt Influencer in Splunk Search 07-24-2023
0 5
0
5
cinimins
Hello,I would like to make a stacked column chart with number of errors by hour and error type (warning, error, etc)T...
by cinimins Explorer in Splunk Search 07-24-2023
0 2
0
2
csar5634
Hi and just reaching out as stumped. Very grateful for assistance. This query returns the following in the statistics...
by csar5634 Explorer in Splunk Search 07-23-2023
0 6
0
6
sigma
1) I want to list top 10 usernames those got most 403 status codes.     for example a username named sigma got 2000 o...
by sigma Path Finder in Splunk Search 07-23-2023
0 4
0
4
sekhar123
where can i find all the Splunk queries and how to use them?
by sekhar123 New Member in Splunk Search 07-22-2023
0 3
0
3
smith_
Hi,I'm trying to figure out the query  to identify when users are connecting to the VPN or not.
by smith_ Builder in Splunk Search 07-22-2023
0 23
0
23
jip31
HiIs anybody can tell me what is the goal of this regex?| regex ImagePath="\\\\\\\\"As far as I know, it seems to sea...
by jip31 Motivator in Splunk Search 07-21-2023
0 4
0
4
pjhawar
We generally follow a pattern of logging in a key=value pattern.I am curious if we should totally avoid logs that are...
by pjhawar New Member in Splunk Search 07-21-2023
0 3
0
3
jwhughes58
I've got a feed that is sending non-compliant json since spath doesn't work on it.  I put together this searchindex=d...
by jwhughes58 Contributor in Splunk Search 07-21-2023
0 1
0
1
JohnEGones
Hi people,I wonder whether it is possible to run a query that generates a set of n-sample of events for each sourcety...
by JohnEGones Communicator in Splunk Search 07-21-2023
0 3
0
3
ghostrider
I have a splunk event with below format:{<!-- -->message{<!-- -->DATE: 2023-07-20T11:53:04}}I want to find all the events that have t...
by ghostrider Path Finder in Splunk Search 07-21-2023
0 1
0
1
amoldesai
Hi, I have a query written to find average exceptions per device on monthly basis for my use case. The query return...
by amoldesai Explorer in Splunk Search 07-21-2023
0 5
0
5
Talking_Master
I am getting a value from my data that a number buts actually the duration how do I convert into minuets hours and da...
by Talking_Master Explorer in Splunk Search 07-21-2023
0 1
0
1
ravik453
I'm trying to complete the lab for my cybersecurity course. I googled few thing for this question, but this question ...
by ravik453 New Member in Splunk Search 07-21-2023
0 1
0
1
drih
Helloversion 9.0.0We are using v1.2 of the browscap add-on and are having issues with it performing searches.  The ad...
by drih Engager in Splunk Search 07-21-2023
0 1
0
1
chr1s
Grateful if anyone can help or guide me in the right direction.I am running a search against a lookup table. The outp...
by chr1s Engager in Splunk Search 07-21-2023
0 9
0
9
Sanshan
There is a complicated requirement for me, the splunk beginner. Hope you can give me some advice. The splunk version:...
by Sanshan Observer in Splunk Search 07-20-2023
0 3
0
3
ilya_resh
Hi, Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.I want t...
by ilya_resh Engager in Splunk Search 07-20-2023
0 0
0
0
iguardia
I would like to forward logs from sources coming from udp inputs in a Heavy Forwarder to two splunk clouds with diffe...
by iguardia Loves-to-Learn Lots in Splunk Search 07-20-2023
0 0
0
0
Subbu
I am beginner and i want to create something like this my Splunk search1 is  index&#61;XXX source&#61;"/opt/middleware/ibm/"...
by Subbu Loves-to-Learn in Splunk Search 07-20-2023
0 3
0
3
RemyaT
I have a query to find the maximum event count that has happened in a minute over time as belowindex&#61;"xxx" "headers.a...
by RemyaT Explorer in Splunk Search 07-20-2023
0 2
0
2
danielbb
We have a large (~500 line) report being used to calculate CVE scores and fill a summary index daily, with vulnerabil...
by danielbb Motivator in Splunk Search 07-20-2023
0 0
0
0
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors