Splunk Search

Splunk Search
Community Activity
dmacgillivray
Hello Splunkers, I am trying to follow the logic from the below URL to anonymize some field data on the fly. http://...
by dmacgillivray Communicator in Splunk Search 11-12-2014
0 3
0
3
mfscully
I have a log that has the following: Blah blah bloh HandleBusInfoMessage=31951592=460892.509; nextcommand Blah Handle...
by mfscully Explorer in Splunk Search 11-12-2014
0 4
0
4
dilipbailwal
Here is the sample data AppPoolName : TestApp PrivateMemory : 2000 State : Started Application : IdentityType : Netw...
by dilipbailwal Path Finder in Splunk Search 11-12-2014
0 5
0
5
ashnet16
When running the regex below, the search doesn't return any results even though the reg ex string works well on the ...
by ashnet16 Path Finder in Splunk Search 11-12-2014
0 7
0
7
Meena27
Hi, We have set to receive alerts like Brute force, Port Scanning from external IPs. Is there anyway or query in S...
by Meena27 Explorer in Splunk Search 11-11-2014
1 3
1
3
rafamss
Hi guys, How to extract one portion of the data model when I have the name of the field. Sample: field: status, wit...
by rafamss Contributor in Splunk Search 11-11-2014
0 2
0
2
Bhuavana
Hi, Please let me know the regex to extract text from 2 or 3 more lines. For below log text : ClientIp=06516217500...
by Bhuavana Explorer in Splunk Search 11-11-2014
0 2
0
2
Bhuavana
Hi, I have five different types of exceptions and for that messages are logged as shown below : ClientIp=0651621750...
by Bhuavana Explorer in Splunk Search 11-10-2014
0 4
0
4
dmacgillivray
Hello, thanks for everyones assistance on MV_ADD=True response on my last question regarding multivalued pairs.. Now ...
by dmacgillivray Communicator in Splunk Search 11-10-2014
0 4
0
4
caffein
When sharing a search result I would like to disable clicking on the individual table cells. I would still like to be...
by caffein Path Finder in Splunk Search 11-10-2014
1 4
1
4
thezero
I am attempting to get first 3 events for each user field for which user count>3. Basically what I am looking for...
by thezero Path Finder in Splunk Search 11-10-2014
1 7
1
7
HeinzWaescher
Hi, is it possible to use the delete command after a lookup? sourcetype=sourceA | lookup delete_lookup.csv key OU...
by HeinzWaescher Motivator in Splunk Search 11-10-2014
0 2
0
2
ohuchi
データサマリーで表示されるホスト、ソース、ソースタイプにおいて、不要なデータを削除しようと思います。 現在V6.1.4(Windows 7)ですが、昔(V5)は、"| delete"を指定した場合、論理削除だけで物理削除は行われず表示...
by ohuchi Explorer in Splunk Search 11-09-2014
0 2
0
2
horst_poehlmann
I have a problem with my checkpoint logs and automatic lookup tables (although the problem is not specific to checkpo...
by horst_poehlmann Explorer in Splunk Search 11-09-2014
0 3
0
3
vasanthmss
Hi Splunkers, I would like to extract the following xml while indexing.. fields: host=0.0.0.1 source=mysource sour...
by vasanthmss Motivator in Splunk Search 11-09-2014
1 3
1
3
splunker12er
In order to be a selected field , doest that field must exist in every events ? Now host, source, sourcetype are the...
by splunker12er Motivator in Splunk Search 11-09-2014
0 2
0
2
shellnight
I need to combine a normal search for 24 hr period with all events and a subsearch on threshold based event where it ...
by shellnight Explorer in Splunk Search 11-09-2014
0 10
0
10
sumitnagal
I have log coming in this format. this value is dynamic and keep changing in terms of Form and numbers Counts=[100A=0...
by sumitnagal Path Finder in Splunk Search 11-08-2014
0 1
0
1
chrismok
alt textIf I use this, no event return sourcetype=abc source="*"+strftime(now(),"%Y%m%d")+"*" But when I modify th...
by chrismok Path Finder in Splunk Search 11-07-2014
0 23
0
23
dhavamanis
we are getting this error more frequently, can you please tell us the optimized settings to avoid this error, The sp...
by dhavamanis Builder in Splunk Search 11-07-2014
0 5
0
5
nfieglein
I have a multivalue field which contains date strings. I would like to find the earliest one of the field and set a n...
by nfieglein Path Finder in Splunk Search 11-07-2014
0 5
0
5
ben_leung
In _raw: string1=key1|key2|key3|key4|key5|key6 string2=value1|value2|value3|value4|value5|value6 I want to manipula...
by ben_leung Builder in Splunk Search 11-07-2014
1 8
1
8
koushiknandan
Hi, Though I'm receiving the same output for both my queries, curious to know the difference (executions, time taken...
by koushiknandan New Member in Splunk Search 11-07-2014
0 1
0
1
pete_charlton
I am running a report that outputs a date and time format form one of my logs, and sending it in email to a customer....
by pete_charlton Explorer in Splunk Search 11-07-2014
0 6
0
6
jetzt82
AUTOLOGIN..10100000000001..Polaris/5.0 (pc, Windows 7/6.1, ja-JP) PolarisOfficeLink/1.8.14..**1415285996**..192.168.0...
by jetzt82 Explorer in Splunk Search 11-06-2014
1 2
1
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors