Splunk Search

Splunk Search
Community Activity
greentomatoes
Hi everyone,I am currently trying to create a table that shows the count of activity by user as well as the occurrenc...
by greentomatoes Engager in Splunk Search 04-10-2023
0 2
0
2
SabariRajanT
Hi Team, In below query I am trying to pull all the host from various index and match those host in a list lookup fil...
by SabariRajanT Path Finder in Splunk Search 04-10-2023
0 4
0
4
srv007
I have a splunk search query which shows the details but the problem here is it only shows the results if the hostnam...
by srv007 Path Finder in Splunk Search 04-10-2023
0 5
0
5
TrangCIC81
I have done a search as below to create a table in Dashboard to list the top 20 users that upload files the most to c...
by TrangCIC81 Communicator in Splunk Search 04-10-2023
0 4
0
4
smanojkumar
Hi All,      I had a panel "OS", that gives the value os in single value visualization,  based on the value of os,  i...
by smanojkumar Contributor in Splunk Search 04-10-2023
0 1
0
1
Anidy21
I want to create this graph in splunk can some one please help me .Required graph The one that i am getting after wri...
by Anidy21 Engager in Splunk Search 04-09-2023
0 5
0
5
fikristar
I am very new to Splunk I need to create a stacked bar/area chart where I have two separate searches. I'd like to s...
by fikristar Explorer in Splunk Search 04-09-2023
1 6
1
6
vineela
Hi All,       I have a log which is in Json format. I used spath and extracted the fields. But there is no field valu...
by vineela Path Finder in Splunk Search 04-08-2023
0 6
0
6
solaced
Could someone help me with such a query? I am running a scheduled search every 30 minutes which aims to find duplicat...
by solaced Explorer in Splunk Search 04-07-2023
0 3
0
3
Sathiya123
<search>| eval vm_unit=case(vmSize="Standard_F16s_v2",2,vmSize="Standard_F8s_v2",1,vmSize="Standard_F4s",0.5,vmSize="...
by Sathiya123 Explorer in Splunk Search 04-07-2023
0 18
0
18
clio706
お世話になります。 現在、あるログの集計をしております。 接続元IPアドレスと、接続日時をキーにして、初回接続日から10日間経過後も接続しているログのみを抽出出来るようにしたいですが、上手く抽出することが出来ません。 ※合計接続日数は...
by clio706 Explorer in Splunk Search 04-07-2023
0 3
0
3
NgSplunk
集計軸が違う場合にCount数を加工して出力する方法についてお教え下さい。 index「接続情報」のデータ項目は「タイムスタンプ、ユーザ名、接続プロトコル」になります。またデータイメージは下記にタイムスタンプが付加された物になります。...
by NgSplunk New Member in Splunk Search 04-07-2023
0 1
0
1
James1
Hello, I am trying to use the custom splunk visualisation.  I have formatted my search as the following:   index=my_i...
by James1 New Member in Splunk Search 04-07-2023
0 1
0
1
RanjiRaje
Hi everyone, My post is huge. sorry for that. I need suggestion from you for the query I framed.I have 2 lookup used ...
by RanjiRaje Explorer in Splunk Search 04-07-2023
0 2
0
2
smanojkumar
Hi There,     I had a panel "OS", that gives the value os,  based on the value of os,  if it were "Windows" it should...
by smanojkumar Contributor in Splunk Search 04-07-2023
0 8
0
8
balu1211
Hi there! I was wondering if there's a specific app available in Splunk Enterprise Security that can provide CPU info...
by balu1211 Path Finder in Splunk Search 04-06-2023
0 2
0
2
pacifiquen
Hello Team, can anyone help me with the extraction of new field   input: site: mclaudelinemugasqiln.platinilemu.com:1...
by pacifiquen Explorer in Splunk Search 04-06-2023
0 3
0
3
Tom_Lundie
A newly created KVStore collection is not returning matches for a lookup command, despite the fact it's populated. Fo...
by Tom_Lundie Contributor in Splunk Search 04-06-2023
0 1
0
1
stwong
Hi all, I try to group events using transaction.  Since there are multiple endswith condition, i tried following to m...
by stwong Communicator in Splunk Search 04-06-2023
0 6
0
6
AL3Z
Hi,I'm trying to write the spl query on  usecase like  alertname!="*pdm*"  triggerred by user in between like 2 hours...
by AL3Z Builder in Splunk Search 04-06-2023
0 4
0
4
wpb162
I have a user who wants to send a table resulting from | stats values() to a summary index via the collect command, b...
by wpb162 Explorer in Splunk Search 04-06-2023
0 3
0
3
ns102
Hi, I have the following event (XML) in Splunk, how can I create a dashboard of this XML? <JOBAPPLICATION="AFT-DTA"CR...
by ns102 Explorer in Splunk Search 04-06-2023
0 5
0
5
quasikaze
The quotes can only be seen in the search.log in one of the SearchParser component events. My ultimate goal is to b...
by quasikaze Explorer in Splunk Search 04-06-2023
2 9
2
9
numeroinconnu12
Hello, thank you in advance for your feedback. I would like to sort the date so that my graph is coherent, can you pl...
by numeroinconnu12 Path Finder in Splunk Search 04-06-2023
0 4
0
4
cyrus_thesplunk
Currently in my logs I am getting the hostname of the users but not their usernames. I created a lookup table that co...
by cyrus_thesplunk Engager in Splunk Search 04-06-2023
0 4
0
4
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...