Splunk Search

Splunk Search
Community Activity
rwdan
Hi,THe use case is GitHub Dependabot vulnerability alerts, once recevied, searching another index with GitHub SBOM li...
by rwdan Loves-to-Learn in Splunk Search 07-04-2023
0 3
0
3
dan_growler
I am writing a search query that looks for hosts that have appeared for the first time today and their count. Here is...
by dan_growler Engager in Splunk Search 07-04-2023
1 6
1
6
KalebeRS
Hello,how can I split strings that are in the same line without delimiters into a new line?KalebeRS_0-1688469252299.p...
by KalebeRS Explorer in Splunk Search 07-04-2023
0 1
0
1
Jagaspu
Hi i need extract the below file name from extracted output  MDTM|07/02/2023 23:58:59.007|[SFTP:3460819_0:eftpos:10.1...
by Jagaspu Engager in Splunk Search 07-04-2023
0 6
0
6
heorhii12412
Hello everyone! I have Splunk events in the following format:    activity_time: 2023-06-29T12:45:06Z   event_time: 20...
by heorhii12412 Explorer in Splunk Search 07-03-2023
0 6
0
6
UdayBhaskar
 {"timestamp":"2023-06-28T11:00:13.545Z","message":"Time taken for Method1 Call : 3120","class":"com.xyz.enterprise.p...
by UdayBhaskar Engager in Splunk Search 07-03-2023
0 2
0
2
izzie123
Hello Splunkers,I had a question, I wanted to check the time on which my saved searches / scheduled reports and alert...
by izzie123 Path Finder in Splunk Search 07-03-2023
0 3
0
3
TonyJobling
I can obtain a list of fields within an index eg.index=bind_queries | stats values(*) AS * | transpose | table column...
by TonyJobling New Member in Splunk Search 07-03-2023
0 4
0
4
smith_
Hi all,I'm trying to audit correlation searches in my environment but unable to view the "Last Modified By" "Last Mod...
by smith_ Builder in Splunk Search 07-01-2023
0 3
0
3
Loepp
Hi I have a report showing who have added or removed a person to or from a group. Like :index="win*" (EventCode=4728 ...
by Loepp Observer in Splunk Search 06-30-2023
0 6
0
6
Roy_9
Hello, Can someone please help me with the Splunk search to find the list of Heavy Forwarders reporting with their IP...
by Roy_9 Motivator in Splunk Search 06-30-2023
0 4
0
4
Staale
Im trying to do this:  aid=0 Overflowexception msg="Print completed" @t<first | [search Overflowexception | stats min...
by Staale New Member in Splunk Search 06-30-2023
0 6
0
6
navan1
Hello All,I want to create an alert to find certain actions done by users from same Index.Index= myindexsourcetype= m...
by navan1 Explorer in Splunk Search 06-30-2023
0 4
0
4
man03359
Hi All,I am fairly new to Splunk and I have bit of a challenge in front of me which I am not able to resolve. I have ...
by man03359 Communicator in Splunk Search 06-30-2023
0 1
0
1
interrobang
Hey all, I've got a multisearch query using inputlookups to untangle a sprawling kafka setup, getting all the various...
by interrobang Explorer in Splunk Search 06-29-2023
0 0
0
0
gsbpp
I have the following searchindex=xoom_app_online_checkout_orchestration_api (level=ERROR AND "Failed to get open-bank...
by gsbpp Explorer in Splunk Search 06-29-2023
0 3
0
3
brajaram
My data is in JSON format, and contains arrays of JSON data that can be from 1 to N blocks. In this JSON, fields can ...
by brajaram Communicator in Splunk Search 06-29-2023
0 3
0
3
yonphang
i tried all splunk answers and doesn't seems like working for me. i have this search | rex mode=sed field=message.UA ...
by yonphang Explorer in Splunk Search 06-29-2023
0 5
0
5
smanojkumar
Hi Splunkers!    Good day!    I need a search which extracts the count of serial_number of different time range and i...
by smanojkumar Contributor in Splunk Search 06-29-2023
0 4
0
4
numeroinconnu12
Hello, Hope you are wellI want to etract only TP58304 on this line (8)TP58304 (5)endra(3)ttx(5)local(0)How can i do p...
by numeroinconnu12 Path Finder in Splunk Search 06-29-2023
0 1
0
1
krbalaji77
I have this query to find hosts from a lookup that have zero events. There are about a 100 hosts and I can see that t...
by krbalaji77 Explorer in Splunk Search 06-29-2023
0 3
0
3
domino30
We keep getting warnings such asthis thin3.PNG We have gone into the savedsaerch conf files and renames them on a dif...
by domino30 Path Finder in Splunk Search 06-29-2023
0 1
0
1
Renunaren
Hi Team, Please help us on the below issue. Below is the sample event.   message: Dataframe row : {"_c0":{"0":"{","1"...
by Renunaren Loves-to-Learn Everything in Splunk Search 06-28-2023
0 2
0
2
interrobang
I've got a multisearch query basically using inputlookups to trace a sprawling kafka setup, getting all the various l...
by interrobang Explorer in Splunk Search 06-28-2023
0 0
0
0
Goldenfit
So I have this query that creates and incident if there is 7 outlier  in the last 15 minutes: | streamstats time_wind...
by Goldenfit Explorer in Splunk Search 06-28-2023
0 0
0
0
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...