Splunk Search

Splunk Search
Community Activity
security_mike
Hello,I'm trying to search in the Authentication data model for authentication attempts where the username is wrong. ...
by security_mike Explorer in Splunk Search 04-03-2023
0 1
0
1
Erfan
Hi I am trying to whitelist some traffic from my search. So I decided to create a look up table including src ip, dst...
by Erfan Explorer in Splunk Search 04-03-2023
0 7
0
7
smanojkumar
Hi There,    I had a dashboard that is having a pop up, when the single value is selected, it will display the drop d...
by smanojkumar Contributor in Splunk Search 04-03-2023
0 3
0
3
kirthika26
How to represent good visualization with the following fields DeviceID, Software Version (Eg 1.22.2222.34) , Software...
by kirthika26 Explorer in Splunk Search 04-03-2023
0 8
0
8
AL3Z
Hi,Could anyone over here  able to write an spl query for usecase in splunk ES like when single user triggers alert s...
by AL3Z Builder in Splunk Search 04-03-2023
0 0
0
0
SplunkDash
Hello,I have some issues with field extraction using props.conf and transforms.conf files. Sample data (3 sample even...
by SplunkDash Motivator in Splunk Search 04-02-2023
0 5
0
5
AL3Z
Hi, I have created a dynamic lookup table in one of the search head  using a search ,now i want  it to move to anothe...
by AL3Z Builder in Splunk Search 04-02-2023
0 1
0
1
AL3Z
Hi, I'm trying to find the alerts by user between the period of 2 hours like Alert1,Alert2 Here I need a spl query fo...
by AL3Z Builder in Splunk Search 04-02-2023
0 10
0
10
gorkazabarte
I have many event with the following format:  EVENT 1 {<!-- -->     'colors': [          {'color': 'red', 'appearances': 3}, ...
by gorkazabarte New Member in Splunk Search 04-01-2023
0 2
0
2
Minarai
Hi. Lets say there are fields named "raw". The values are like this. http-header1&#61;value1|http-header2&#61;value2.. Number...
by Minarai Explorer in Splunk Search 04-01-2023
0 8
0
8
letmein
 I have some JSON (raw event) like below, this is one event: {<!-- -->     "place": "bar",     "stock": [                    ...
by letmein Engager in Splunk Search 04-01-2023
0 7
0
7
POR160893
Hi,I have the following query:| tstats count where index&#61;dns earliest&#61;-90d latest&#61;now() groupby _time span&#61;1d| fields...
by POR160893 Builder in Splunk Search 03-31-2023
0 1
0
1
az365
HI,I am new to Splunk. If criteria is met, I notice my search results include my previous searches stored in Splunk's...
by az365 Engager in Splunk Search 03-31-2023
0 1
0
1
zegg
If there are events like these.And I want  to find Fieldnames which have "abc"Event 1 File : abcdefgURL : 1232323232....
by zegg Engager in Splunk Search 03-31-2023
0 1
0
1
jialiu907
I am new to Splunk and I wanted to make a dashboard to showcase the count of Linux machines and their distributions i...
by jialiu907 Path Finder in Splunk Search 03-31-2023
0 1
0
1
damode
How to modify the below query to exclude private ip address range from source IPs (src_ip) ? index&#61;cisco eventtype&#61;c...
by damode Motivator in Splunk Search 03-31-2023
0 3
0
3
brdr
I have a field to evaluate if the value of the field is an IP address or a hostname. if it is an IP address do someth...
by brdr Contributor in Splunk Search 03-31-2023
0 4
0
4
sreelakshmi
Column1                       column2               column3 abc                                            1 def     ...
by sreelakshmi Engager in Splunk Search 03-31-2023
0 3
0
3
karthi2809
29-Mar-2023 04:56:35:PM: |CPU Utilization % Average ------- 11 Expected result:11
by karthi2809 Builder in Splunk Search 03-30-2023
0 3
0
3
KSPriya
Hey ya, Good day!!! Trying a built a use case scenario for MFA login attempts from unauthorized IPs. Looking out here...
by KSPriya Explorer in Splunk Search 03-30-2023
0 1
0
1
MScottFoley
Is something like this possible?    index&#61;main sourcetype&#61;iis host IN (| inputlookup serverlistA.csv)    I think the...
by MScottFoley Path Finder in Splunk Search 03-30-2023
0 3
0
3
wiederkehrc
Hi,we have a Data Model based search that we filter based on a lookup (with match_type WILDCARD) that matches differe...
by wiederkehrc Explorer in Splunk Search 03-30-2023
0 3
0
3
Renunaren
Hi Team, Below is the raw text that has been received into our splunk portal. It has a field called name of the job. ...
by Renunaren Loves-to-Learn Everything in Splunk Search 03-30-2023
0 3
0
3
rajs115
Hi,   I am trying to find a query to extract specific code from the raw splunk data. Below is the raw content. raw: [...
by rajs115 Path Finder in Splunk Search 03-30-2023
0 2
0
2
lboro_garyp
Hi folks, I'm analysing Cisco CallManager telephone call details records that have  been ingested to Splunk. I need t...
by lboro_garyp Path Finder in Splunk Search 03-30-2023
0 4
0
4
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...