Splunk Search

Splunk Search
Community Activity
yohhpark
Let say I have a result belowindex = indextestsource=stestbunch of evals = evalssourcetype=sttext| table ID Status Re...
by yohhpark Path Finder in Splunk Search 03-28-2023
0 6
0
6
salv1
Hello fellow splunkers, I'm posting here because I would gladly have help with the following query. Let's say I have ...
by salv1 Engager in Splunk Search 03-28-2023
0 1
0
1
DPOIRE
I have this search that is working and returning a average Delay value:Search Command | eval epoch_timestamp=strptime...
by DPOIRE Path Finder in Splunk Search 03-28-2023
0 3
0
3
sarit_s
Hello I need to add alert action to many alerts,Is it possible to add the same action to all of the alerts in one tim...
by sarit_s Communicator in Splunk Search 03-28-2023
0 1
0
1
michaelnorup
My regex from the message field looks like this.   | rex field=Message "\W(?<Hostname>\S+)\s\w+\W(?<Build>\S+)\s\w+\W...
by michaelnorup Communicator in Splunk Search 03-28-2023
0 4
0
4
klay824
Hi, I have a query that is making two different searches and displaying the stats of each. Example:index="example" TE...
by klay824 Explorer in Splunk Search 03-28-2023
0 6
0
6
TrangCIC81
Hello All, I have been able to create a table that lists the top users that have been uploading files the most to clo...
by TrangCIC81 Communicator in Splunk Search 03-28-2023
0 4
0
4
drogo
Hello, I want to extract fiends from below log format. Can someone please help. Log format - 2023-03-21 04:14:13.859,...
by drogo Explorer in Splunk Search 03-27-2023
0 5
0
5
chrisschum
We have a standard configuration for our workstations. Several of the fields are static but some are dynamic (but the...
by chrisschum Path Finder in Splunk Search 03-27-2023
0 2
0
2
woodlandrelic
HI  So I have this dashboard showing the below.  HBSS      ACAS        CMRSACAS    CMRSHBSS89              92        ...
by woodlandrelic Path Finder in Splunk Search 03-27-2023
0 2
0
2
yohhpark
Search 1. | inputlookup test1.csv | table ITEM1 ITEM2   Search 2. | inputlookup test2.csv | table ITEM 1 ITEM3   Conc...
by yohhpark Path Finder in Splunk Search 03-27-2023
0 4
0
4
apignata
I have the following JSON structure in my events. I am trying to figure out an SPL Query to format the JSON in a tabl...
by apignata Explorer in Splunk Search 03-27-2023
0 1
0
1
vickycoder27
I have a curl response which is json string[], I am able to fetch the data using split(), mvexpand() and then substri...
by vickycoder27 Explorer in Splunk Search 03-26-2023
0 4
0
4
itsmevic
I'm running the below query to find out when was the last time an index checked in. However, in using this query the ...
by itsmevic Communicator in Splunk Search 03-26-2023
0 5
0
5
bt149
I have a log set from FW's. These logs have a field called "src."  From what I can tell, this field is populated with...
by bt149 Path Finder in Splunk Search 03-25-2023
0 4
0
4
SplunkNewbie100
Hi all,   I  want to replace random substrings in path: C:\Users\sjfklsj\Appdata\.... -> C:\Users\---\Appdata\.... C:...
by SplunkNewbie100 New Member in Splunk Search 03-25-2023
0 2
0
2
bosseres
Hello everyone In the result of my search I got such results (last command was stats values(list) as list, values(sta...
by bosseres Contributor in Splunk Search 03-25-2023
0 3
0
3
Sven1
I am working to merge two searches. The first search outputs one or more account names:     index=x sourcetype=y | ta...
by Sven1 Path Finder in Splunk Search 03-24-2023
0 12
0
12
Abhineet
Hi,  looking for splunk query having field name similar to field in lookup file with respective value in lookup file....
by Abhineet Loves-to-Learn Everything in Splunk Search 03-24-2023
0 6
0
6
pierre_weg
Hello fellows!I have a sourcetype called cmdb with a field called BIA to any src_host. After this join index=lab sour...
by pierre_weg Path Finder in Splunk Search 03-24-2023
0 6
0
6
Veeru
Actually I want to pass the time from first query to second and get results out on basis of first query time.First qu...
by Veeru Path Finder in Splunk Search 03-24-2023
0 1
0
1
iwascar
Hi everyone,I have a column called "SCRN_NM"  (name of screen)and only want to extract English data, not non-English ...
by iwascar New Member in Splunk Search 03-24-2023
0 1
0
1
shashilendraman
how to search value of "Dst_IP" field from "ASA" index to "otx" index "indicator" field and display the scrip" field ...
by shashilendraman Explorer in Splunk Search 03-24-2023
1 5
1
5
surabhi
Hi,   We have a platform where lot of dashboards are populated using splunk searches via splunk api call. All the que...
by surabhi New Member in Splunk Search 03-24-2023
0 0
0
0
pm2012
Hi SMEs, I have a unique requirement which need one of my extracted filed name = actual_time to be mapped with _time ...
by pm2012 Explorer in Splunk Search 03-24-2023
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...