Splunk Search

Splunk Search
Community Activity
suspense
Hello, Syntax:     index=security sourcetype=EDR:* | eval dest=coalesce(ip,ipaddress) | stats values(sourcetype) val...
by suspense Explorer in Splunk Search 04-04-2023
0 7
0
7
Raj
Hi,Could any one able to write the query for the use case if user triggers both alerts (alert_name="*pdm*" AND alert_...
by Raj Builder in Splunk Search 04-04-2023
0 14
0
14
RanjiRaje
Hi, I need your suggestion here. Please guide me I have a lookup file with list of hosts. I need to compare it with s...
by RanjiRaje Explorer in Splunk Search 04-03-2023
0 5
0
5
Minarai
By default, only labels are displayed on pie chart when using top command.Is there any way to add count and percent t...
by Minarai Explorer in Splunk Search 04-03-2023
0 1
0
1
Vivekmishra01
I am trying to run a query like below but I am limited to 10000 sub search result. Is there a way to make this query ...
by Vivekmishra01 Explorer in Splunk Search 04-03-2023
0 10
0
10
Renunaren
Hi Team,   We have a splunk dashboard panel which has a requirement that is. The dashboard panel has a title which ne...
by Renunaren Loves-to-Learn Everything in Splunk Search 04-03-2023
0 3
0
3
security_mike
Hello,I'm trying to search in the Authentication data model for authentication attempts where the username is wrong. ...
by security_mike Explorer in Splunk Search 04-03-2023
0 1
0
1
Erfan
Hi I am trying to whitelist some traffic from my search. So I decided to create a look up table including src ip, dst...
by Erfan Explorer in Splunk Search 04-03-2023
0 7
0
7
smanojkumar
Hi There,    I had a dashboard that is having a pop up, when the single value is selected, it will display the drop d...
by smanojkumar Contributor in Splunk Search 04-03-2023
0 3
0
3
kirthika26
How to represent good visualization with the following fields DeviceID, Software Version (Eg 1.22.2222.34) , Software...
by kirthika26 Explorer in Splunk Search 04-03-2023
0 8
0
8
Raj
Hi,Could anyone over here  able to write an spl query for usecase in splunk ES like when single user triggers alert s...
by Raj Builder in Splunk Search 04-03-2023
0 0
0
0
SplunkDash
Hello,I have some issues with field extraction using props.conf and transforms.conf files. Sample data (3 sample even...
by SplunkDash Motivator in Splunk Search 04-02-2023
0 5
0
5
Raj
Hi, I have created a dynamic lookup table in one of the search head  using a search ,now i want  it to move to anothe...
by Raj Builder in Splunk Search 04-02-2023
0 1
0
1
Raj
Hi, I'm trying to find the alerts by user between the period of 2 hours like Alert1,Alert2 Here I need a spl query fo...
by Raj Builder in Splunk Search 04-02-2023
0 10
0
10
gorkazabarte
I have many event with the following format:  EVENT 1 {<!-- -->     'colors': [          {'color': 'red', 'appearances': 3}, ...
by gorkazabarte New Member in Splunk Search 04-01-2023
0 2
0
2
Minarai
Hi. Lets say there are fields named "raw". The values are like this. http-header1&#61;value1|http-header2&#61;value2.. Number...
by Minarai Explorer in Splunk Search 04-01-2023
0 8
0
8
letmein
 I have some JSON (raw event) like below, this is one event: {<!-- -->     "place": "bar",     "stock": [                    ...
by letmein Engager in Splunk Search 04-01-2023
0 7
0
7
POR160893
Hi,I have the following query:| tstats count where index&#61;dns earliest&#61;-90d latest&#61;now() groupby _time span&#61;1d| fields...
by POR160893 Builder in Splunk Search 03-31-2023
0 1
0
1
az365
HI,I am new to Splunk. If criteria is met, I notice my search results include my previous searches stored in Splunk's...
by az365 Engager in Splunk Search 03-31-2023
0 1
0
1
zegg
If there are events like these.And I want  to find Fieldnames which have "abc"Event 1 File : abcdefgURL : 1232323232....
by zegg Engager in Splunk Search 03-31-2023
0 1
0
1
jialiu907
I am new to Splunk and I wanted to make a dashboard to showcase the count of Linux machines and their distributions i...
by jialiu907 Path Finder in Splunk Search 03-31-2023
0 1
0
1
damode
How to modify the below query to exclude private ip address range from source IPs (src_ip) ? index&#61;cisco eventtype&#61;c...
by damode Motivator in Splunk Search 03-31-2023
0 3
0
3
brdr
I have a field to evaluate if the value of the field is an IP address or a hostname. if it is an IP address do someth...
by brdr Contributor in Splunk Search 03-31-2023
0 4
0
4
sreelakshmi
Column1                       column2               column3 abc                                            1 def     ...
by sreelakshmi Engager in Splunk Search 03-31-2023
0 3
0
3
karthi2809
29-Mar-2023 04:56:35:PM: |CPU Utilization % Average ------- 11 Expected result:11
by karthi2809 Builder in Splunk Search 03-30-2023
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors