Splunk Search

Splunk Search
Community Activity
sigma
1) I want to list top 10 usernames those got most 403 status codes.     for example a username named sigma got 2000 o...
by sigma Path Finder in Splunk Search 07-23-2023
0 4
0
4
sekhar123
where can i find all the Splunk queries and how to use them?
by sekhar123 New Member in Splunk Search 07-22-2023
0 3
0
3
smith_
Hi,I'm trying to figure out the query  to identify when users are connecting to the VPN or not.
by smith_ Builder in Splunk Search 07-22-2023
0 23
0
23
jip31
HiIs anybody can tell me what is the goal of this regex?| regex ImagePath="\\\\\\\\"As far as I know, it seems to sea...
by jip31 Motivator in Splunk Search 07-21-2023
0 4
0
4
pjhawar
We generally follow a pattern of logging in a key=value pattern.I am curious if we should totally avoid logs that are...
by pjhawar New Member in Splunk Search 07-21-2023
0 3
0
3
jwhughes58
I've got a feed that is sending non-compliant json since spath doesn't work on it.  I put together this searchindex=d...
by jwhughes58 Contributor in Splunk Search 07-21-2023
0 1
0
1
JohnEGones
Hi people,I wonder whether it is possible to run a query that generates a set of n-sample of events for each sourcety...
by JohnEGones Communicator in Splunk Search 07-21-2023
0 3
0
3
ghostrider
I have a splunk event with below format:{<!-- -->message{<!-- -->DATE: 2023-07-20T11:53:04}}I want to find all the events that have t...
by ghostrider Path Finder in Splunk Search 07-21-2023
0 1
0
1
amoldesai
Hi, I have a query written to find average exceptions per device on monthly basis for my use case. The query return...
by amoldesai Explorer in Splunk Search 07-21-2023
0 5
0
5
Talking_Master
I am getting a value from my data that a number buts actually the duration how do I convert into minuets hours and da...
by Talking_Master Explorer in Splunk Search 07-21-2023
0 1
0
1
ravik453
I'm trying to complete the lab for my cybersecurity course. I googled few thing for this question, but this question ...
by ravik453 New Member in Splunk Search 07-21-2023
0 1
0
1
drih
Helloversion 9.0.0We are using v1.2 of the browscap add-on and are having issues with it performing searches.  The ad...
by drih Engager in Splunk Search 07-21-2023
0 1
0
1
chr1s
Grateful if anyone can help or guide me in the right direction.I am running a search against a lookup table. The outp...
by chr1s Engager in Splunk Search 07-21-2023
0 9
0
9
Sanshan
There is a complicated requirement for me, the splunk beginner. Hope you can give me some advice. The splunk version:...
by Sanshan Observer in Splunk Search 07-20-2023
0 3
0
3
ilya_resh
Hi, Distributed deployment that includes SH Cluster and IDX Cluster, HEC on IDXs is used to receive the data.I want t...
by ilya_resh Engager in Splunk Search 07-20-2023
0 0
0
0
iguardia
I would like to forward logs from sources coming from udp inputs in a Heavy Forwarder to two splunk clouds with diffe...
by iguardia Loves-to-Learn Lots in Splunk Search 07-20-2023
0 0
0
0
Subbu
I am beginner and i want to create something like this my Splunk search1 is  index&#61;XXX source&#61;"/opt/middleware/ibm/"...
by Subbu Loves-to-Learn in Splunk Search 07-20-2023
0 3
0
3
RemyaT
I have a query to find the maximum event count that has happened in a minute over time as belowindex&#61;"xxx" "headers.a...
by RemyaT Explorer in Splunk Search 07-20-2023
0 2
0
2
danielbb
We have a large (~500 line) report being used to calculate CVE scores and fill a summary index daily, with vulnerabil...
by danielbb Motivator in Splunk Search 07-20-2023
0 0
0
0
Nagalakshmi
Hi Team,we are trying to add new field  as a display name into interesting field from below raw eventDisplayName: sam...
by Nagalakshmi Path Finder in Splunk Search 07-20-2023
0 3
0
3
lemospt
Hi,   i have a field with the models, like below, and with this info i want to define a new field like brand. i trie...
by lemospt Explorer in Splunk Search 07-20-2023
0 3
0
3
mbasharat
Hi, I have below scenario. Image_Name and Name_Space are being ingested with below variations in table A. Image_name ...
by mbasharat Builder in Splunk Search 07-20-2023
0 16
0
16
venky1544
i have two drop down panels  Basically when i select any value in Monitored statistics the Divisor value should chang...
by venky1544 Builder in Splunk Search 07-20-2023
0 1
0
1
ldnail_at_TI
Today I have a custom sourcetype &#61; custom:access_combined this is routed in its entirety at the heavy forwarder to tw...
by ldnail_at_TI Path Finder in Splunk Search 07-20-2023
0 3
0
3
AJSCSA
Would someone be able to help me understand how do to this?  I would like to modify the built in dashboard in the Inf...
by AJSCSA Loves-to-Learn Lots in Splunk Search 07-20-2023
0 1
0
1
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...