Splunk Search

Splunk Search
Community Activity
woodcock
Many people ask questions here that are tricky enough that the only way to get an answer that works is to play around...
by Esteemed Legend in Splunk Search 04-05-2023
3 12
3
12
TorbinIT
So I've recently got into a new job, where I'm learning Splunk and learning how to support splunk searches and dashbo...
by TorbinIT Path Finder in Splunk Search 04-05-2023
0 2
0
2
Taruchit
Hello All,I need your help to understand the impact of time ranges selected by users while running their search query...
by Taruchit Contributor in Splunk Search 04-05-2023
0 2
0
2
Ciarán
Could someone have a look at the following query and see why it does not give me the results I expect based on the do...
by Ciarán Explorer in Splunk Search 04-05-2023
0 14
0
14
f_666dhn
I have field log-sshd like this:log-sshd="Apr 5 xx:xx:xx serverhost sshd[xxxx]: Failed password for user xxx from xx....
by f_666dhn Explorer in Splunk Search 04-05-2023
0 2
0
2
Abass42
I have this report that i received an error from. Ive seen the error from different searches, but i just started to l...
by Abass42 Communicator in Splunk Search 04-04-2023
0 3
0
3
shreyasamin64
REX command to create a field domain from websiteEX:  input : https://www.youtube.com/sd/td/gs-intro         output: ...
by shreyasamin64 Explorer in Splunk Search 04-04-2023
0 4
0
4
VijayA
Hi All,  I'm searching 2 different logs, which contain the "Severity" as common field. I want to extract,  if log1 - ...
by VijayA Explorer in Splunk Search 04-04-2023
0 7
0
7
Dharani
Hi,   I have service name verb, object and outcome. I need to show the statistics in pie chart.  For example, index=a...
by Dharani Path Finder in Splunk Search 04-04-2023
0 4
0
4
suspense
Hello, Syntax:     index=security sourcetype=EDR:* | eval dest=coalesce(ip,ipaddress) | stats values(sourcetype) val...
by suspense Explorer in Splunk Search 04-04-2023
0 7
0
7
smith_
Hi,Could any one able to write the query for the use case if user triggers both alerts (alert_name="*pdm*" AND alert_...
by smith_ Builder in Splunk Search 04-04-2023
0 14
0
14
RanjiRaje
Hi, I need your suggestion here. Please guide me I have a lookup file with list of hosts. I need to compare it with s...
by RanjiRaje Explorer in Splunk Search 04-03-2023
0 5
0
5
Minarai
By default, only labels are displayed on pie chart when using top command.Is there any way to add count and percent t...
by Minarai Explorer in Splunk Search 04-03-2023
0 1
0
1
Vivekmishra01
I am trying to run a query like below but I am limited to 10000 sub search result. Is there a way to make this query ...
by Vivekmishra01 Explorer in Splunk Search 04-03-2023
0 10
0
10
Renunaren
Hi Team,   We have a splunk dashboard panel which has a requirement that is. The dashboard panel has a title which ne...
by Renunaren Loves-to-Learn Everything in Splunk Search 04-03-2023
0 3
0
3
security_mike
Hello,I'm trying to search in the Authentication data model for authentication attempts where the username is wrong. ...
by security_mike Explorer in Splunk Search 04-03-2023
0 1
0
1
Erfan
Hi I am trying to whitelist some traffic from my search. So I decided to create a look up table including src ip, dst...
by Erfan Explorer in Splunk Search 04-03-2023
0 7
0
7
smanojkumar
Hi There,    I had a dashboard that is having a pop up, when the single value is selected, it will display the drop d...
by smanojkumar Contributor in Splunk Search 04-03-2023
0 3
0
3
kirthika26
How to represent good visualization with the following fields DeviceID, Software Version (Eg 1.22.2222.34) , Software...
by kirthika26 Explorer in Splunk Search 04-03-2023
0 8
0
8
smith_
Hi,Could anyone over here  able to write an spl query for usecase in splunk ES like when single user triggers alert s...
by smith_ Builder in Splunk Search 04-03-2023
0 0
0
0
SplunkDash
Hello,I have some issues with field extraction using props.conf and transforms.conf files. Sample data (3 sample even...
by SplunkDash Motivator in Splunk Search 04-02-2023
0 5
0
5
smith_
Hi, I have created a dynamic lookup table in one of the search head  using a search ,now i want  it to move to anothe...
by smith_ Builder in Splunk Search 04-02-2023
0 1
0
1
smith_
Hi, I'm trying to find the alerts by user between the period of 2 hours like Alert1,Alert2 Here I need a spl query fo...
by smith_ Builder in Splunk Search 04-02-2023
0 10
0
10
gorkazabarte
I have many event with the following format:  EVENT 1 {<!-- -->     'colors': [          {'color': 'red', 'appearances': 3}, ...
by gorkazabarte New Member in Splunk Search 04-01-2023
0 2
0
2
Minarai
Hi. Lets say there are fields named "raw". The values are like this. http-header1&#61;value1|http-header2&#61;value2.. Number...
by Minarai Explorer in Splunk Search 04-01-2023
0 8
0
8
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...