Splunk Search

Splunk Search
Community Activity
mkrauss1
I try hard to group multiple key/values from a single record, then count the values and print them in a table. Say i ...
by mkrauss1 Explorer in Splunk Search 09-23-2014
2 5
2
5
nivethainspire_
Am new to splunk I need to use map in advanced xml , Is there any option without creating new moudule..
by nivethainspire_ Explorer in Splunk Search 09-23-2014
0 1
0
1
yuanliu
For example, if all events in | transaction ID contain ID but only some carry user, I want to capture those transact...
by SplunkTrust SplunkTrust in Splunk Search 09-22-2014
2 4
2
4
ahmar74
basically i want to be able to search if users have visited sites that are listed in phishtank.
by ahmar74 Explorer in Splunk Search 09-22-2014
1 5
1
5
Splunkster45
Here I am asking another question, but I think that this one will help me with other questions that I've had. Curren...
by Splunkster45 Communicator in Splunk Search 09-22-2014
0 2
0
2
wjblazek
I have search lots of transaction questions and don't see any related to this question. I have a search that defines...
by wjblazek Explorer in Splunk Search 09-22-2014
1 5
1
5
Splunkster45
Do lookup fields work in conjunction with fields that have been created in the search string? The output of user giv...
by Splunkster45 Communicator in Splunk Search 09-22-2014
0 3
0
3
mcoleman2
How do I create a table that lists which user logged in to the windows server and the time that they successfully log...
by mcoleman2 Explorer in Splunk Search 09-22-2014
1 7
1
7
albyva
I'm trying to have a Splunk Alert kick off an email (to an email script) and depending on the search query it should ...
by albyva Communicator in Splunk Search 09-22-2014
0 5
0
5
bigrichie90
I am trying to find out details of a remote session. Although the events are the same, they are separate by action (a...
by bigrichie90 Path Finder in Splunk Search 09-22-2014
0 4
0
4
internet_team
Hello, is there any way to improve this search by reducing appendcols number ? Source is the same, only download_ti...
by internet_team Explorer in Splunk Search 09-22-2014
0 2
0
2
adityapavan18
Hi PFB the snippet in my dashboard: <module name="Search" layoutPanel="panel_row2_col1" autoRun="True"> <param n...
by adityapavan18 Contributor in Splunk Search 09-22-2014
0 12
0
12
colinj
Howdy all, I'm using the following search index="summary_collaboration" source="Inbound Messages Accepted & Deliv...
by colinj Path Finder in Splunk Search 09-22-2014
0 5
0
5
KarunK
Hi All, I have a following table. Total is the sum of the cost of items by country using eventstats. Country ...
by KarunK Contributor in Splunk Search 09-21-2014
0 5
0
5
chrismok
As this sourcetype is used for other searches, the props.conf cannot be modified for adding the line merger, how to I...
by chrismok Path Finder in Splunk Search 09-20-2014
1 9
1
9
rotate
I have been thinking about about having documentation "attached" to events. For example a short explanation of a func...
by rotate Engager in Splunk Search 09-20-2014
0 2
0
2
cwl
UI から、完了するまでに時間がかかる(3時間ほど)サーチを実行したところ、サーチ自体は完了せずに Unknown sid エラーが表示されました。また、この状態で Job Inspector の画面を表示しますと 500 Inter...
by cwl Contributor in Splunk Search 09-19-2014
1 1
1
1
RVDowning
I would like to create a table similar to the following: Of Reports Created Users % >10 ...
by RVDowning Contributor in Splunk Search 09-19-2014
1 2
1
2
hcastell
Yet another Newbie question, I have the following search string that's working fine: | eval DOCSIS_TxPWR_Rdy=case(Te...
by hcastell Path Finder in Splunk Search 09-19-2014
0 3
0
3
dimoobraznii
Hi, guys I dive in Web Analytics and figure out some questions. Please, help me to find answers. All my questions wi...
by dimoobraznii Path Finder in Splunk Search 09-19-2014
0 2
0
2
jravida
Hi Folks, I've worked out a regex to pull out group names from audit logs. It works for one field with no special ch...
by jravida Communicator in Splunk Search 09-19-2014
1 6
1
6
andrewkenth
From the GUI, you should also see a "Raw Events" as an export option along with json, xml, and csv however I do not s...
by andrewkenth Communicator in Splunk Search 09-19-2014
0 3
0
3
abassili
I have defined a database input (dump type) with a simple SQL query and a key-value output format. \ The "dbx.log" f...
by abassili Explorer in Splunk Search 09-19-2014
0 11
0
11
Splunkster45
I have created a field using the rex command. I have partioned the field into two parts: admin and spss_user. However...
by Splunkster45 Communicator in Splunk Search 09-19-2014
0 5
0
5
neiljpeterson
This works in my search: rex field=source "\w:\\\[\w]*\\\(?<app_path>[^\\\]*)" But when I try to define it as a fi...
by neiljpeterson Communicator in Splunk Search 09-19-2014
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors