Splunk Search

Splunk Search
Community Activity
alexspunkshell
I am trying to extract 2 fields from my logs.  Logs:   10.218.136.20 - - [30/Jun/2023:02:36:32 +0000] "GET /api/v2/ru...
by alexspunkshell Contributor in Splunk Search 07-04-2023
0 10
0
10
nateNpgh
I need to extract a time value from log file where the time value appears with a few different variations of characte...
by nateNpgh Loves-to-Learn Lots in Splunk Search 07-04-2023
0 4
0
4
jiaqya
I ran a search which should show more than 10000 rows, but I get only 10000 rows back on the result. Is this a limita...
by jiaqya Builder in Splunk Search 07-04-2023
1 11
1
11
dennislevine
I need to create a search that determines if an admin users password is changed. The current search pulls the domain ...
by dennislevine New Member in Splunk Search 07-04-2023
0 3
0
3
DanAlexander
Hi All,I need a regex that can extract particular bits from proxy events equally e.g. there are different types of ev...
by DanAlexander Communicator in Splunk Search 07-04-2023
0 7
0
7
manojkumarmr
Hello Splunk Experts,We are using Splunk ODBC to extract data from Splunk and load data to Qliksense. It was working ...
by manojkumarmr New Member in Splunk Search 07-04-2023
0 0
0
0
sekhar463
hai all,i am using below splunk search to know the status if not running but its not giving if process was not runnin...
by sekhar463 Path Finder in Splunk Search 07-04-2023
0 3
0
3
rwdan
Hi,THe use case is GitHub Dependabot vulnerability alerts, once recevied, searching another index with GitHub SBOM li...
by rwdan Loves-to-Learn in Splunk Search 07-04-2023
0 3
0
3
dan_growler
I am writing a search query that looks for hosts that have appeared for the first time today and their count. Here is...
by dan_growler Engager in Splunk Search 07-04-2023
1 6
1
6
KalebeRS
Hello,how can I split strings that are in the same line without delimiters into a new line?Have this lines that conta...
by KalebeRS Explorer in Splunk Search 07-04-2023
0 1
0
1
Jagaspu
Hi i need extract the below file name from extracted output  MDTM|07/02/2023 23:58:59.007|[SFTP:3460819_0:eftpos:10.1...
by Jagaspu Engager in Splunk Search 07-04-2023
0 6
0
6
heorhii12412
Hello everyone! I have Splunk events in the following format:    activity_time: 2023-06-29T12:45:06Z   event_time: 20...
by heorhii12412 Explorer in Splunk Search 07-03-2023
0 6
0
6
UdayBhaskar
 {"timestamp":"2023-06-28T11:00:13.545Z","message":"Time taken for Method1 Call : 3120","class":"com.xyz.enterprise.p...
by UdayBhaskar Engager in Splunk Search 07-03-2023
0 2
0
2
izzie123
Hello Splunkers,I had a question, I wanted to check the time on which my saved searches / scheduled reports and alert...
by izzie123 Path Finder in Splunk Search 07-03-2023
0 3
0
3
TonyJobling
I can obtain a list of fields within an index eg.index=bind_queries | stats values(*) AS * | transpose | table column...
by TonyJobling New Member in Splunk Search 07-03-2023
0 4
0
4
AL3Z
Hi all,I'm trying to audit correlation searches in my environment but unable to view the "Last Modified By" "Last Mod...
by AL3Z Builder in Splunk Search 07-01-2023
0 3
0
3
Loepp
Hi I have a report showing who have added or removed a person to or from a group. Like :index="win*" (EventCode=4728 ...
by Loepp Observer in Splunk Search 06-30-2023
0 6
0
6
Roy_9
Hello, Can someone please help me with the Splunk search to find the list of Heavy Forwarders reporting with their IP...
by Roy_9 Motivator in Splunk Search 06-30-2023
0 4
0
4
Staale
Im trying to do this:  aid=0 Overflowexception msg="Print completed" @t<first | [search Overflowexception | stats min...
by Staale New Member in Splunk Search 06-30-2023
0 6
0
6
navan1
Hello All,I want to create an alert to find certain actions done by users from same Index.Index= myindexsourcetype= m...
by navan1 Explorer in Splunk Search 06-30-2023
0 4
0
4
man03359
Hi All,I am fairly new to Splunk and I have bit of a challenge in front of me which I am not able to resolve. I have ...
by man03359 Communicator in Splunk Search 06-30-2023
0 1
0
1
interrobang
Hey all, I've got a multisearch query using inputlookups to untangle a sprawling kafka setup, getting all the various...
by interrobang Explorer in Splunk Search 06-29-2023
0 0
0
0
gsbpp
I have the following searchindex=xoom_app_online_checkout_orchestration_api (level=ERROR AND "Failed to get open-bank...
by gsbpp Explorer in Splunk Search 06-29-2023
0 3
0
3
brajaram
My data is in JSON format, and contains arrays of JSON data that can be from 1 to N blocks. In this JSON, fields can ...
by brajaram Communicator in Splunk Search 06-29-2023
0 3
0
3
yonphang
i tried all splunk answers and doesn't seems like working for me. i have this search | rex mode=sed field=message.UA ...
by yonphang Explorer in Splunk Search 06-29-2023
0 5
0
5
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...