Splunk Search

Splunk Search
Community Activity
badbuda
hey, I need to build a report, that contains approx 500 thousand events. the requirement is  that the report will con...
by badbuda Loves-to-Learn Lots in Splunk Search 03-23-2023
0 6
0
6
NJ
Hi everyone!I'm still fairly new to Splunk so sorry if it is a simple question.I have some logs that does not show th...
by NJ Path Finder in Splunk Search 03-22-2023
0 7
0
7
nikita29
Hi, I want to use Splunk for logs for Heroku apps. How to integrate Splunk with Heroku. Can you please help me with i...
by nikita29 Loves-to-Learn in Splunk Search 03-22-2023
0 6
0
6
fboeje
Hi all, We receive the warning : The current bundle directory contains a large lookup file that might cause bundle re...
by fboeje Explorer in Splunk Search 03-22-2023
0 6
0
6
DougiieDee
I have this working query which needs some additional detailing.index=_internal earliest=-1h@h latest=@h| lookup api ...
by DougiieDee Explorer in Splunk Search 03-22-2023
0 1
0
1
mikeyty07
is there a way to alert an email if today's hourly stats are 25% higher than the previous week same day hourly stats?
by mikeyty07 Communicator in Splunk Search 03-22-2023
0 5
0
5
knanaiah001
Hi,Can someone suggest me on how to enable drilldown for specific column .For example ,if i have 5 columns and i have...
by knanaiah001 Explorer in Splunk Search 03-22-2023
0 5
0
5
amitrinx
Hi I have a lookup having two fields| inputlookup ID-Client-Lookup.csv | fields ClientId ClientNameI have a base sear...
by amitrinx Explorer in Splunk Search 03-22-2023
0 3
0
3
alakhotia
I want to have a table or chart where I can see the failure % of the past 30 days, vs. today, and output the differen...
by alakhotia Explorer in Splunk Search 03-22-2023
0 5
0
5
jasmartin
Hello, I am attempting to replace a large unwieldy macro with a data model. Part of the macro is a rex command that f...
by jasmartin Explorer in Splunk Search 03-22-2023
0 4
0
4
nmayafit
Hi. Subject is confusing so here goes. I have 3 log lines: org=A Status=Success org=A Status=Fail org=B Status=Succes...
by nmayafit Path Finder in Splunk Search 03-22-2023
0 8
0
8
apand84
Hi Everyone,  I am looking for idea to implement a case where subqueries  will be run based on the user choice from c...
by apand84 Engager in Splunk Search 03-21-2023
0 1
0
1
Mike6960
I created a outputlookup  file with just one column ...My search | table D_ID  | outputlookup Total.csv I want to use...
by Mike6960 Path Finder in Splunk Search 03-21-2023
0 15
0
15
pm2012
Hey SMEs, Has anyone having any prior experience of migrating existing Qradar data to Splunk. Any docs or something u...
by pm2012 Explorer in Splunk Search 03-21-2023
0 4
0
4
algol2
I'm new to Splunk, so apologies if this is a silly question. I have a log file that reads:     2023-03-22 00:57:09,51...
by algol2 Engager in Splunk Search 03-21-2023
0 3
0
3
just4bs
I have a .csv file that I have uploaded as a lookup file that works fine when I run a search.  If I ask another user ...
by just4bs New Member in Splunk Search 03-21-2023
0 2
0
2
Hisae
Hello Everyone, I am trying to find outliers in connection duration on a specific subnet but having trouble getting t...
by Hisae Engager in Splunk Search 03-21-2023
0 2
0
2
changwoo
What are the big differences?
by changwoo Communicator in Splunk Search 03-21-2023
1 5
1
5
DaveBunn
CVE-2023-23397 is all the rage right now.Has anyone figured out a way to detect this in office content?I've checked a...
by DaveBunn Path Finder in Splunk Search 03-21-2023
0 5
0
5
bosseres
Hello everyone,  I have events which contains such fields user1=..., user2=...., user3... etc And I have lookup which...
by bosseres Contributor in Splunk Search 03-21-2023
0 3
0
3
coreyCLI
I am trying to pair down the list of ciphers we are using.  When I remove AES256-GCM-SHA384 I begin to get the below ...
by coreyCLI Communicator in Splunk Search 03-21-2023
0 4
0
4
avadhutha
I have a string like below and unable to extract accuratly with rex command please suggest  any alternative way. _raw...
by avadhutha Explorer in Splunk Search 03-21-2023
0 2
0
2
vineela
I am trying to extract the fields in json format. But not able to fetch the data.PFB screenshot for reference: not a...
by vineela Path Finder in Splunk Search 03-21-2023
0 5
0
5
norbertt911
Hello Splunkers, I would like to have to set an alert if a sudden high amount of events are received.  I have this ba...
by norbertt911 Communicator in Splunk Search 03-21-2023
0 7
0
7
Ashwini008
Hi,I am formatting data as required and getting it in below format. Now I want to calculate average of only highlight...
by Ashwini008 Builder in Splunk Search 03-21-2023
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...