Splunk Search

Splunk Search
Community Activity
jonvijay1993
I have a multiselect for software version (version is just yyyy.mm.dd or an alphanumeric string).If the user selects ...
by jonvijay1993 Explorer in Splunk Search 04-17-2023
0 4
0
4
Sekhar
We have two events query Start event Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
dvg06
Hi Legends How do I give bit more meaningful names for fields last_sum and first_sum in below query? i.e. something l...
by dvg06 Path Finder in Splunk Search 04-16-2023
1 1
1
1
GarzaREG
I have a requirement where I have been asked to monitor for new users getting added to Sudoer.  Are there specific ac...
by GarzaREG New Member in Splunk Search 04-16-2023
0 2
0
2
RanjiRaje
Hi All, I am facing some issue in using lookup command. Need your suggestions here please.. I have a lookup file as b...
by RanjiRaje Explorer in Splunk Search 04-15-2023
0 7
0
7
willsy
Hello,Trying to complete a search that uses metrics to monitor when a device has not been connected for the last 90 d...
by willsy Communicator in Splunk Search 04-15-2023
0 2
0
2
khourihan_splun
I have a search that returns unique visitors query over 30 days' worth of logs : Using dc() it was a lot slower. Here...
by khourihan_splun Splunk Employee Splunk Employee in Splunk Search 04-15-2023
5 3
5
3
Macphisto
I have a 2015 log that I need to analyze  I have a 2015 Aruba log I need to analyze.  The log does not have the year,...
by Macphisto Loves-to-Learn Lots in Splunk Search 04-15-2023
0 7
0
7
super_edition
Hello Everyone, Below is the set of the log response pattern: "message":{"input":"999.111.000.999 - - [06/Apr/2023:05...
by super_edition Path Finder in Splunk Search 04-15-2023
0 10
0
10
yoshileigh66
I have noticed that the event_ids that I cannot find documentation for are associated with two eventtypes together. H...
by yoshileigh66 Explorer in Splunk Search 04-15-2023
0 2
0
2
Sekhar
I have two events one is  Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd 2nd event ...
by Sekhar Explorer in Splunk Search 04-14-2023
0 3
0
3
kgorzynski
Some Splunk customers have encountered the following error message when performing searches: The search job with sid=...
by kgorzynski Splunk Employee Splunk Employee in Splunk Search 04-14-2023
1 0
1
0
hawkik1
I am attempting (for the first tiume) to convert the following regex search to work in transforms.conf, but can't see...
by hawkik1 Loves-to-Learn Everything in Splunk Search 04-14-2023
0 6
0
6
beepbop
I have a field called APM_ID and i want to get the output for only APMs from this field (for eg: A1002, A0001) and wa...
by beepbop Explorer in Splunk Search 04-14-2023
0 2
0
2
karu0711
I am running search.basesearch  |eventstats count values(date) as Date by ID  result I get count 2 or 3 or 1how do I ...
by karu0711 Communicator in Splunk Search 04-14-2023
0 3
0
3
Izz-
index=* success="false" process_name="C:\\Windows\\System32\\svchost.exe"| stats count as failedAttempts by user| sor...
by Izz- New Member in Splunk Search 04-14-2023
0 1
0
1
balu1211
Hi,I'm looking for the search to  exclude the ips  present in the  lookup table  ips                             comm...
by balu1211 Path Finder in Splunk Search 04-14-2023
0 7
0
7
JLopez
Hi Splunkers,I want to create a search that send results to an "On call" system only for out of hours during monday t...
by JLopez Explorer in Splunk Search 04-14-2023
0 4
0
4
Ana01
Hello!I've been trying to solve this problem for a couple days now but can't seem to figure it out.So basically I wan...
by Ana01 Loves-to-Learn Everything in Splunk Search 04-14-2023
0 4
0
4
balu1211
0
17
kell_cena
10.179.130.56 - - [14/Apr/2023:01:59:28.233 +0800] "POST /services/broker/phonehome/connection_10.179.130.56_8089_10....
by kell_cena Explorer in Splunk Search 04-13-2023
0 2
0
2
aohls
I am doing some analysis on our existing searches. What I would like to do is run the saved search when I get the res...
by aohls Contributor in Splunk Search 04-13-2023
0 2
0
2
freefall
Hi,I have 2 queries , let's call them query_a & query_b.query_a - gives me a table containing all the userAgent's tha...
by freefall Observer in Splunk Search 04-13-2023
0 5
0
5
monicateja
1. How to get total sum of call_Duration of time for all call_Name mentioned below in splunk from ms to seconds with ...
by monicateja Explorer in Splunk Search 04-13-2023
0 5
0
5
karu0711
I have lookup table like  Date       ID              Name  02/04    12547     xxx02/04     12458    xxx02/04      145...
by karu0711 Communicator in Splunk Search 04-13-2023
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors