Splunk Search

Splunk Search
Community Activity
RolandBird
I need a search that can identify when a new TCP session from an IP Address is established but the previous TCP sessi...
by RolandBird New Member in Splunk Search 08-30-2013
0 4
0
4
Nicksyboy
I recently came across a Splunk expression, as rex "(?i)\".*? (?P/\w+/((\w+\.\d+)|(\w+\d+))/((\w+/)|(\w+/\w+/)|((\w...
by Nicksyboy Explorer in Splunk Search 08-30-2013
0 8
0
8
cthacker
I'm trying to filter out my logs for all non campus/company IPs. I'd like to be able to do different searches for "a...
by cthacker Explorer in Splunk Search 08-30-2013
0 4
0
4
albyva
How would you structure a macro to list dozens of IP Subnets? For example: If you want a macro to list the following...
by albyva Communicator in Splunk Search 08-29-2013
0 3
0
3
btorresgil
I have set up a table in a view. However, with the search in place, over time, the memory on the Splunk server is co...
by btorresgil Builder in Splunk Search 08-29-2013
1 1
1
1
hartfoml
I have a search that shows me the 90 day trend of my Splunk license use. index="_internal" source="*metrics.log" per...
by hartfoml Motivator in Splunk Search 08-29-2013
0 2
0
2
chowell
I'm currently indexing DHCP stats, used and free for each scope, every five minutes. Now, if I want to chart this inf...
by chowell Explorer in Splunk Search 08-29-2013
0 1
0
1
lionel319
I'd like to create a savedsearch within an app, and have it run periodically. Is there a way to automate it so that i...
by lionel319 Explorer in Splunk Search 08-29-2013
1 1
1
1
ericrobinson
Not a splunk newbie, but I cant seem to figure out how to format my timechart values to be readable. The default form...
by ericrobinson Path Finder in Splunk Search 08-29-2013
0 4
0
4
hartfoml
I have a lookup table with two values in the lookup table that I want to use in the end report. Example: (table with...
by hartfoml Motivator in Splunk Search 08-29-2013
0 5
0
5
sir_reel
Need some help breaking an event out into multiple events. For example the following event: 7368:20130826:133019.2...
by sir_reel Explorer in Splunk Search 08-29-2013
1 3
1
3
hartfoml
I am looking for the group name from the phonehome command. I tried the auto extractor and it was only marginally he...
by hartfoml Motivator in Splunk Search 08-29-2013
0 4
0
4
fahrenheit
Hi, I am trying correlate data from ip watchlist app and events of firewall. the search: (index=test sourcetype=cis...
by fahrenheit New Member in Splunk Search 08-29-2013
0 9
0
9
DTERM
I have the following code that works fine in a view and chart... <searchTemplate>index=MyApp Alert_Type<2 earlies...
by DTERM Contributor in Splunk Search 08-28-2013
0 1
0
1
echojacques
I have a nullQueue setup in my transforms.conf and this regex works perfectly to drop all "service=53" OR "dst=10.10....
by echojacques Builder in Splunk Search 08-28-2013
0 3
0
3
royimad
Is there a reverse regular expression that start with an end line and begin with a characters Example: I have a regul...
by royimad Builder in Splunk Search 08-28-2013
1 10
1
10
mkwan0
I am running a query against a webserver access log. I need to group all responses greater than 5 seconds, and deter...
by mkwan0 New Member in Splunk Search 08-28-2013
0 2
0
2
TylerTreat
Ok, Great! So we just got splunk running. Now what. I've gone out and told it to grab AD data, so I thought Hey, how...
by TylerTreat Explorer in Splunk Search 08-28-2013
1 10
1
10
yuwtennis
Hi ! I would like to ask question whether following calculation is possible or not? For following case, customer t...
by yuwtennis Communicator in Splunk Search 08-28-2013
0 10
0
10
Cris
Is it possible to change the Master node server ip? I have to change the current Master node with a new machine but I...
by Cris Explorer in Splunk Search 08-28-2013
0 2
0
2
sbsbb
I'm making a timechart, returning a unknown number of columns. So I don't know how there named. I make appendcol, to ...
by sbsbb Builder in Splunk Search 08-28-2013
0 2
0
2
matthewparry
Hi, Does anyone know if there is support to grab the messages from a queue for example in ActiveMQ? Thanks Matt
by matthewparry Path Finder in Splunk Search 08-27-2013
0 5
0
5
crazyeva
Hi, I want to get a chart as 'timechart avgcount span=1d' or 'stats avgcount by _time, span=1d' in which, avgcount me...
by crazyeva Contributor in Splunk Search 08-27-2013
0 7
0
7
rdownie
index=abc [index=def a=b | fields c,d,e | format] will create something like index=abc (c=blah) AND (d=foo) AND (e=...
by rdownie Communicator in Splunk Search 08-27-2013
0 2
0
2
Cuyose
Splunk doesn't seem to work with the AS operator in SQl, but rather expects you to RENAME after the query. But what ...
by Cuyose Builder in Splunk Search 08-27-2013
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors