Splunk Search

Splunk Search
Community Activity
HelloItsMe76
Hello all. I have a log file that looks like this;   PROCESS UP STATUS RESTARTS AGEPROCESS1 2/2 Running 0 6d19hPROCES...
by HelloItsMe76 Explorer in Splunk Search 05-22-2023
0 3
0
3
Runals
I'm trying to at least initially to get a list of fields for each of the Splunk CIM data models by using a REST searc...
by Runals Motivator in Splunk Search 05-22-2023
3 3
3
3
loganramirez
I have index with json data that represents call data (phone calls), but there is nothing native in the index that re...
by loganramirez Path Finder in Splunk Search 05-22-2023
0 3
0
3
SharmaS2
Hi,data is got getting indexed when we are adding csv file from add data under settings .. its events count is showin...
by SharmaS2 Explorer in Splunk Search 05-22-2023
0 5
0
5
Amirahussein
We are currently required to upgrade our Splunk environment from version 8.2.4 to version 9.x, and we are concerned a...
by Amirahussein Path Finder in Splunk Search 05-22-2023
0 1
0
1
londonColney
We have configured some program to run as a service in Unix server.  I want to configure an alert in Splunk that when...
by londonColney Loves-to-Learn in Splunk Search 05-21-2023
0 0
0
0
londonColney
I wanted to know how we can construct a search query for a service which is running on a centOS server and the utiliz...
by londonColney Loves-to-Learn in Splunk Search 05-21-2023
0 2
0
2
john-doe
Hello Folks, I am new with Splunk. I am looking to build a query to detect lateral movement using Windows Service cre...
by john-doe Engager in Splunk Search 05-20-2023
0 3
0
3
qcjacobo2577
I recently enabled Splunk tokens (using SAML authentication) and am able to successfully execute basic API calls (suc...
by qcjacobo2577 Path Finder in Splunk Search 05-19-2023
0 1
0
1
jialiu907
I am having trouble with using the time chart command effectively to make count of all workstations and with them bro...
by jialiu907 Path Finder in Splunk Search 05-19-2023
0 9
0
9
patientsplunker
Hello,I am trying to use Streamstats with Sum(value) and I want to reset that sum after it reaches a certain threshol...
by patientsplunker Loves-to-Learn Everything in Splunk Search 05-19-2023
0 12
0
12
VK_27
We have a job which is getting terminated intermittently , even though when this search gets executed successfully it...
by VK_27 Loves-to-Learn in Splunk Search 05-19-2023
0 2
0
2
jamie1
Hi There, I am currently looking at a search within Splunk Security Essentials (Concentration of Attacker Tools by Fi...
by jamie1 Communicator in Splunk Search 05-19-2023
0 2
0
2
sjringo
I found the following search to identify Missing / New sourcetypes and made a few changes.I am getting data and my ne...
by sjringo Contributor in Splunk Search 05-19-2023
0 4
0
4
silence09
Hello, Not sure if something similar has been posted but what i'm trying to do is a partial match of all the ids in o...
by silence09 Engager in Splunk Search 05-19-2023
0 5
0
5
verothor
Hi all, I want to ask if it's even possible to somehow alternate the values in stacked bar chart, that one week the f...
by verothor Path Finder in Splunk Search 05-19-2023
0 4
0
4
Sekhar
my query below (Index=x source=xtype valid) or (index=y source= ytype  passed) | eval which=if(match(_raw, " valid"),...
by Sekhar Explorer in Splunk Search 05-19-2023
0 2
0
2
Renunaren
Hi Team, We have dashboard which will contains the daily job related information. In that we have two panels like bel...
by Renunaren Loves-to-Learn Everything in Splunk Search 05-18-2023
0 1
0
1
splunkcol
 I currently have a Heavy Forwarder that forwards logs to Splunk Cloud but the heavy forwarder version is at version ...
by splunkcol Builder in Splunk Search 05-18-2023
0 1
0
1
splunkcol
Hello, I have noticed that the Elasticsplunk app no longer exists https://splunkbase.splunk.com/app/3493 I do not kno...
by splunkcol Builder in Splunk Search 05-18-2023
0 2
0
2
bluewizard
.... url = "abc-jjjj-j-xyz.exmaple.come"|eval s1 = abc|eval s2 = efg|eval s3 = xyz|eval symbol ="-" how do i do somet...
by bluewizard Explorer in Splunk Search 05-18-2023
0 3
0
3
kp3343
Hi, I am doing rex on a field that looks like this (showing multiple events below) a#1|b#30|c#6|d#9 b#5|d#7|e#5|f#4 a...
by kp3343 Engager in Splunk Search 05-18-2023
0 1
0
1
tcpcannon
I want to search from a lookup table, get a field, and compare it to a search and pull the fields from that search ba...
by tcpcannon Loves-to-Learn Lots in Splunk Search 05-18-2023
0 0
0
0
Raj
Hi, Need a search for the below usecase Search for alert_type=ufa and alert_name="  suspicious  Downloads"Please incl...
by Raj Builder in Splunk Search 05-18-2023
0 1
0
1
gkiffney
We're heavy SplunkCloud users and have run into a roadblock. We have a lookup CSV file that needs to be updated dail...
by gkiffney Engager in Splunk Search 05-18-2023
9 8
9
8
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...
Top Solution Authors