Splunk Search

Splunk Search
Community Activity
bigrichie90
I have this query in which I join with another query. I want to take the earliest event of the first query, go back a...
by bigrichie90 Path Finder in Splunk Search 10-22-2014
0 5
0
5
kpavan
Hi All, Need to find Windows Edition through splunk query like Windows 2003, Vista, 2008 etc.. I checked query ind...
by kpavan Path Finder in Splunk Search 10-22-2014
0 1
0
1
atanasmitev
I have a _raw field with the following data in: .............. "Stuff\":\"CAPITALS_AND_UNDERSCORES\", .........
by atanasmitev Path Finder in Splunk Search 10-22-2014
1 2
1
2
smudge797
I need to extract the email address from the following logs, either in a search or via props.conf - transforms.conf ...
by smudge797 Path Finder in Splunk Search 10-22-2014
1 9
1
9
tpflicke
I've got a large number of logs which look similar to: INFO com.this.that.SomeLogger 2014-05-08 08:29:49,997 [CSP-1...
by tpflicke Path Finder in Splunk Search 10-22-2014
0 2
0
2
markthompson
Hi, I have a field called Submit Date and it's format is like this: 10/21/2014 11:26:05 AM I'm trying to separate th...
by markthompson Builder in Splunk Search 10-22-2014
1 3
1
3
myahes
using this articles advice (http://blogs.splunk.com/2012/02/19/compare-two-time-ranges-in-one-report/) i am trying ...
by myahes Explorer in Splunk Search 10-21-2014
0 2
0
2
mohankesireddy
I have two sets of data, both sets have a common field with common value, when i use join command i am able to find t...
by mohankesireddy Path Finder in Splunk Search 10-21-2014
1 2
1
2
menonmanish
Can the universal forwarder monitor event logs and filter out events using REGEX in whitelist for eg: [WinEventLog://...
by menonmanish Path Finder in Splunk Search 10-21-2014
0 1
0
1
abhayneilam
Hi, I want to replace all ":*" character means :: ::: :::: and so on with only singel ":" character. for Location fi...
by abhayneilam Contributor in Splunk Search 10-21-2014
2 6
2
6
avinashreddy539
Hi, I am new to splunk and need help with my use case below. Whenever a request is made to my application, it will c...
by avinashreddy539 New Member in Splunk Search 10-21-2014
0 3
0
3
abelnation
I have records of 3 forms: {<!-- --> "event": "START|MIDDLE|END", "wasSuccessful": true/false, "trans_id": &lt;int&gt;...
by abelnation Explorer in Splunk Search 10-21-2014
1 2
1
2
sshkaya3344
Device Table1 Table2 Table3 Table4 Table5 Name1 XP XP XP XP XP Name2 7 7 XP Null ...
by sshkaya3344 Engager in Splunk Search 10-21-2014
2 3
2
3
sjanwity
I have a table which stores updates done on a database (see my previous questions for more details). I want to create...
by sjanwity Communicator in Splunk Search 10-21-2014
1 5
1
5
sjanwity
I have a table which returns multiple columns and I want to implement a text filter on each of these columns. Current...
by sjanwity Communicator in Splunk Search 10-21-2014
0 4
0
4
anthony_copus
Hi, I currently need to create a search which takes the id values from a new_user event on 1 day, then searches for ...
by anthony_copus Explorer in Splunk Search 10-21-2014
0 1
0
1
vince2010091
Hello, I've a decimal time in my logs like 1.51 that equal 1h30/1:30 or 4.3 equal 4h20/4:20 So i try to get a norma...
by vince2010091 Path Finder in Splunk Search 10-21-2014
0 2
0
2
dominiquevocat
I have a numeric value representing flags. It is the value in userAccountControl defined as follows: typedef enum {...
by SplunkTrust SplunkTrust in Splunk Search 10-21-2014
1 2
1
2
mrabbani
What features will be disabled in trial version of Splunk after 60 days? And What are the features which Enterprise h...
by mrabbani New Member in Splunk Search 10-21-2014
0 1
0
1
james_westwood
index&#61;"bigip-asm" web_application_name&#61;HTTPCLASS_PROD_SOAENTRYPOINT_EXTERNAL_LIVE request_status&#61;alerted OR blocked |...
by james_westwood Engager in Splunk Search 10-21-2014
0 4
0
4
TobiasBoone
cs_username field contains multiple formats of username in the form of: username domain\usernam username&#64;domain.com ...
by TobiasBoone Communicator in Splunk Search 10-20-2014
0 3
0
3
Brittany_Carr
My logs currently capture transaction summaries. The transaction summaries can have 0 to n number of integration. Fo...
by Brittany_Carr Explorer in Splunk Search 10-20-2014
0 3
0
3
ginger8990
How to mask index and search time data? How to verify if it is masked?
by ginger8990 Explorer in Splunk Search 10-20-2014
0 2
0
2
sjanwity
This is an extension of the question http://answers.splunk.com/answers/171571/using-splunk-to-create-and-view-table-m...
by sjanwity Communicator in Splunk Search 10-20-2014
1 11
1
11
bigrichie90
I have a query that pulls up IPs' but with no hostname. I have a separate query that can correlate each IP to a host ...
by bigrichie90 Path Finder in Splunk Search 10-20-2014
0 4
0
4
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...