Splunk Search

Splunk Search
Community Activity
kyi
Hello All,We have a extracted field (example field name "Field1) with multiple value such as YYN, YNN, NYN etc.Based ...
by kyi Explorer in Splunk Search 05-11-2023
0 4
0
4
tonyfer
index=* "23.216.147.64"   Above is my filter, I'm trying to get all the records of that IP address; is this filter co...
by tonyfer Observer in Splunk Search 05-11-2023
0 5
0
5
SplunkDash
Hello,We need to ingest Cloudflare logs using the Cloudflare TA. Do you have any recommendation on how we proceed wit...
by SplunkDash Motivator in Splunk Search 05-11-2023
0 0
0
0
Abhineet
Need splunk query to parse json Data into table format. raw data/event in splunk: <158>May 09 04:33:46 detailedSwitch...
by Abhineet Loves-to-Learn Everything in Splunk Search 05-11-2023
0 5
0
5
TAOFernandes
Hi I'm trying to identify   the registry key use for persistence,  what filter do  I need to apply apply? index=* Tha...
by TAOFernandes Engager in Splunk Search 05-11-2023
0 3
0
3
Karanreddy
Hi,  Can someone please help me to build a table using following JSON My search results  as follows      { [-] doc...
by Karanreddy Engager in Splunk Search 05-11-2023
0 2
0
2
mikeyty07
I am planning to build a dashboard where all the extracted traceId # are collected and injected to another search cri...
by mikeyty07 Communicator in Splunk Search 05-11-2023
0 3
0
3
jamin358
I'm creating a bunch of status dashboards where I need to search for a specific set of hosts and persist a result (ad...
by jamin358 Explorer in Splunk Search 05-11-2023
0 3
0
3
Splunk2095
Hi All, I ran into a tricky one and can’t wrap my head around it (or if it is even possible).  The use case is as fol...
by Splunk2095 Engager in Splunk Search 05-11-2023
0 6
0
6
atebysandwich
I have events that where hostnames  show up more than once and I would like to combine them. The fields available are...
by atebysandwich Path Finder in Splunk Search 05-11-2023
0 1
0
1
CodingMaestro
I have a splunk dashboard that looks like below,  And i have added the text filter. But when i try to search of the ...
by CodingMaestro Path Finder in Splunk Search 05-11-2023
0 6
0
6
foxglove
Hello all. I've been having some trouble with a tricky query. Essentially, I want to return all events that contain a...
by foxglove Engager in Splunk Search 05-11-2023
0 3
0
3
ABHAYA
I am using above splunk query   stats count by BankType.  I am getting result as   SBI   27 AXIS   15 CITI   12. but ...
by ABHAYA Path Finder in Splunk Search 05-11-2023
0 1
0
1
s0k0
I have created a post curl to add data in Splunk, internally my api hits Splunk api and in that api I send data in bo...
by s0k0 Observer in Splunk Search 05-11-2023
0 7
0
7
SplunkDash
Hey, I have issues with parsing events, multiple events/records (raw data) are within the same event. Sample data and...
by SplunkDash Motivator in Splunk Search 05-11-2023
0 10
0
10
splunker-2021
When I run | makeresults command then collect it to summary index there is no result. I am testing this to Search Hea...
by splunker-2021 Loves-to-Learn Everything in Splunk Search 05-11-2023
0 8
0
8
ABHAYA
for e.g. input :   I am getting result in an table format like  statuscodeUSB   35 but i wan to transform the result ...
by ABHAYA Path Finder in Splunk Search 05-11-2023
0 7
0
7
Arishtat
I have three types of data entries.     { <Irrelevant field omitted> "parameters": [ { "LicenseNumber": "123456" } ],...
by Arishtat Engager in Splunk Search 05-11-2023
0 3
0
3
djohnson99
Hello!I'm looking to get a time range from two events, one from a standard search, the other from a different search ...
by djohnson99 Explorer in Splunk Search 05-11-2023
0 4
0
4
MarcG
I'm attempting to chart a maximum duration by server and event_type, and I'd like to display the duration in HH:MM:SS...
by MarcG Explorer in Splunk Search 05-11-2023
0 7
0
7
uhaba
Hi, Looking for help on how to detect systems where a monitored value has decreased compared to yesterday's average v...
by uhaba Explorer in Splunk Search 05-10-2023
0 2
0
2
beaverjustin1
If I have queries with Lists/Arrays containing events :line.Data = [eventOne, eventThree];  line.Data = [eventOne, ev...
by beaverjustin1 Engager in Splunk Search 05-10-2023
0 2
0
2
beaverjustin1
If I have queries with dictionaries containing events as the key and frequencies as the value:line.Data = {"eventOne"...
by beaverjustin1 Engager in Splunk Search 05-10-2023
0 2
0
2
sabasiddiqui
How can we filter our query in days like Monday to Friday and calculate their average value. For eg, I am getting dat...
by sabasiddiqui Loves-to-Learn in Splunk Search 05-10-2023
0 6
0
6
Vish
I have added a Time filter for my charts in splunk but i want the default to be from 01-JAN-23, But the issue is when...
by Vish Explorer in Splunk Search 05-10-2023
0 4
0
4
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Solution Authors