Splunk Search

Splunk Search
Community Activity
Sekhar
my query below (Index=x source=xtype valid) or (index=y source= ytype  passed) | eval which=if(match(_raw, " valid"),...
by Sekhar Explorer in Splunk Search 05-19-2023
0 2
0
2
Renunaren
Hi Team, We have dashboard which will contains the daily job related information. In that we have two panels like bel...
by Renunaren Loves-to-Learn Everything in Splunk Search 05-18-2023
0 1
0
1
splunkcol
 I currently have a Heavy Forwarder that forwards logs to Splunk Cloud but the heavy forwarder version is at version ...
by splunkcol Builder in Splunk Search 05-18-2023
0 1
0
1
splunkcol
Hello, I have noticed that the Elasticsplunk app no longer exists https://splunkbase.splunk.com/app/3493 I do not kno...
by splunkcol Builder in Splunk Search 05-18-2023
0 2
0
2
bluewizard
.... url = "abc-jjjj-j-xyz.exmaple.come"|eval s1 = abc|eval s2 = efg|eval s3 = xyz|eval symbol ="-" how do i do somet...
by bluewizard Explorer in Splunk Search 05-18-2023
0 3
0
3
kp3343
Hi, I am doing rex on a field that looks like this (showing multiple events below) a#1|b#30|c#6|d#9 b#5|d#7|e#5|f#4 a...
by kp3343 Engager in Splunk Search 05-18-2023
0 1
0
1
tcpcannon
I want to search from a lookup table, get a field, and compare it to a search and pull the fields from that search ba...
by tcpcannon Loves-to-Learn Lots in Splunk Search 05-18-2023
0 0
0
0
smith_
Hi, Need a search for the below usecase Search for alert_type=ufa and alert_name="  suspicious  Downloads"Please incl...
by smith_ Builder in Splunk Search 05-18-2023
0 1
0
1
gkiffney
We're heavy SplunkCloud users and have run into a roadblock. We have a lookup CSV file that needs to be updated dail...
by gkiffney Engager in Splunk Search 05-18-2023
9 8
9
8
beetlegeuse
I'm using a pretty straightforward query to see how many unique HTTP status codes are thrown from an IIS server durin...
by beetlegeuse Path Finder in Splunk Search 05-18-2023
0 4
0
4
corti77
Hi,I am creating a query to identify users connected to our Exchange on-prem servers using Microsoft Modern Authentic...
by corti77 Contributor in Splunk Search 05-18-2023
0 7
0
7
ran_deep
We have logs from multiple region, but only want to report those between respective regions working hours.Created fol...
by ran_deep New Member in Splunk Search 05-18-2023
0 1
0
1
bhaskar5428
Hi Team, Am using below query and wanted to create table out of raw data  splunk query - index=* ("Exception occurred...
by bhaskar5428 Explorer in Splunk Search 05-18-2023
0 9
0
9
Siri9996
HI Team,   I am posting only part of the query to avoid confusion. the sourcetype logs data for past 10 days everyday...
by Siri9996 Engager in Splunk Search 05-18-2023
0 7
0
7
inventsekar
Hi.. Spent some one or two hrs, but no luck, hence posting here.. the sample logs:1.1.1. test log a 1.1.1. test log a...
by SplunkTrust SplunkTrust in Splunk Search 05-17-2023
0 3
0
3
newrose
I'm trying to use a Python script with a custom module for a external lookup on Splunk. When running/opt/splunk/bin/s...
by newrose Explorer in Splunk Search 05-17-2023
0 5
0
5
sekhar463
Hi I have some data events with Date value  How to create splunk search if value of MAX_POSITION_DATE  for TABLE2 SHO...
by sekhar463 Path Finder in Splunk Search 05-17-2023
0 8
0
8
Goldenfit
So i am trying to link this to a token from another panel but since "message_id" is a created field, it doesn't work....
by Goldenfit Explorer in Splunk Search 05-17-2023
0 4
0
4
dtibi
I'm trying to evaluate the date string to a time format sing the strptime()the format I have is:  Tue_Oct_25_03:57:49...
by dtibi Explorer in Splunk Search 05-17-2023
0 9
0
9
evelenke
Hi, Splunkers! Looking for easy way to get results from any lookup table like it might be: | inputlookup mylookup |...
by evelenke Contributor in Splunk Search 05-17-2023
0 8
0
8
happylearning
let's say i have 1 index and we have multiple users, i want to assign a role so that user A can only view 5 interesti...
by happylearning Loves-to-Learn in Splunk Search 05-17-2023
0 2
0
2
jamin358
I have a search that makes a decision based on time since an event.    | eval diff = now() - _time   and then make so...
by jamin358 Explorer in Splunk Search 05-17-2023
0 1
0
1
LealP
Hi, Below is an example of my use case: timestampmessageIdcorrelationIdregioncategorytrace17/05/2023 00:001correlatio...
by LealP Explorer in Splunk Search 05-17-2023
0 1
0
1
hariskhan
Hello everybody, I am sizing hardware for splunk enterprise and enterprise security solution. We are designing that f...
by hariskhan Explorer in Splunk Search 05-16-2023
0 6
0
6
soulmaker24
Hello, I am trying to figured out how I could list a report by showing the total number of policies in my query.  I h...
by soulmaker24 Engager in Splunk Search 05-16-2023
0 2
0
2
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Note: This post outlines a proposed architecture and serves as an interest check. If we secure commitments ...