Splunk Search

Splunk Search
Community Activity
chrisschum
We have a standard configuration for our workstations. Several of the fields are static but some are dynamic (but the...
by chrisschum Path Finder in Splunk Search 03-27-2023
0 2
0
2
woodlandrelic
HI  So I have this dashboard showing the below.  HBSS      ACAS        CMRSACAS    CMRSHBSS89              92        ...
by woodlandrelic Path Finder in Splunk Search 03-27-2023
0 2
0
2
yohhpark
Search 1. | inputlookup test1.csv | table ITEM1 ITEM2   Search 2. | inputlookup test2.csv | table ITEM 1 ITEM3   Conc...
by yohhpark Path Finder in Splunk Search 03-27-2023
0 4
0
4
apignata
I have the following JSON structure in my events. I am trying to figure out an SPL Query to format the JSON in a tabl...
by apignata Explorer in Splunk Search 03-27-2023
0 1
0
1
vickycoder27
I have a curl response which is json string[], I am able to fetch the data using split(), mvexpand() and then substri...
by vickycoder27 Explorer in Splunk Search 03-26-2023
0 4
0
4
itsmevic
I'm running the below query to find out when was the last time an index checked in. However, in using this query the ...
by itsmevic Communicator in Splunk Search 03-26-2023
0 5
0
5
bt149
I have a log set from FW's. These logs have a field called "src."  From what I can tell, this field is populated with...
by bt149 Path Finder in Splunk Search 03-25-2023
0 4
0
4
SplunkNewbie100
Hi all,   I  want to replace random substrings in path: C:\Users\sjfklsj\Appdata\.... -> C:\Users\---\Appdata\.... C:...
by SplunkNewbie100 New Member in Splunk Search 03-25-2023
0 2
0
2
bosseres
Hello everyone In the result of my search I got such results (last command was stats values(list) as list, values(sta...
by bosseres Contributor in Splunk Search 03-25-2023
0 3
0
3
Sven1
I am working to merge two searches. The first search outputs one or more account names:     index=x sourcetype=y | ta...
by Sven1 Path Finder in Splunk Search 03-24-2023
0 12
0
12
Abhineet
Hi,  looking for splunk query having field name similar to field in lookup file with respective value in lookup file....
by Abhineet Loves-to-Learn Everything in Splunk Search 03-24-2023
0 6
0
6
pierre_weg
Hello fellows!I have a sourcetype called cmdb with a field called BIA to any src_host. After this join index=lab sour...
by pierre_weg Path Finder in Splunk Search 03-24-2023
0 6
0
6
Veeru
Actually I want to pass the time from first query to second and get results out on basis of first query time.First qu...
by Veeru Path Finder in Splunk Search 03-24-2023
0 1
0
1
iwascar
Hi everyone,I have a column called "SCRN_NM"  (name of screen)and only want to extract English data, not non-English ...
by iwascar New Member in Splunk Search 03-24-2023
0 1
0
1
shashilendraman
how to search value of "Dst_IP" field from "ASA" index to "otx" index "indicator" field and display the scrip" field ...
by shashilendraman Explorer in Splunk Search 03-24-2023
1 5
1
5
surabhi
Hi,   We have a platform where lot of dashboards are populated using splunk searches via splunk api call. All the que...
by surabhi New Member in Splunk Search 03-24-2023
0 0
0
0
pm2012
Hi SMEs, I have a unique requirement which need one of my extracted filed name = actual_time to be mapped with _time ...
by pm2012 Explorer in Splunk Search 03-24-2023
0 1
0
1
mag314
How do you filter out IPv6 and internal routed 169.254.0.0/16 from a multi-value field?Data ExampleHOST              ...
by mag314 Explorer in Splunk Search 03-23-2023
0 1
0
1
Zarack
I have some Checkpoint logs (Firewall) that are generating an alert (Data hygiene - events in the future), I would li...
by Zarack Engager in Splunk Search 03-23-2023
0 1
0
1
sjaworski
I am trying to store a list of searches in a lookup table and then pass each search to the map command. |inputlook...
by sjaworski Communicator in Splunk Search 03-23-2023
3 10
3
10
mikeyty07
I have 2 kind of logs where there are two types of uri which i want to rex into different fields {logType=DOWNSTREAM_...
by mikeyty07 Communicator in Splunk Search 03-23-2023
1 4
1
4
ttovarzoll
I am trying to build an Alert for login failures in AWS CloudTrail. In general I have it working -- but my joins are ...
by ttovarzoll Path Finder in Splunk Search 03-23-2023
0 3
0
3
krishanp
Hello, I am attempting to start a Splunk docker container (search head) and add it as a search peer to an existing en...
by krishanp Explorer in Splunk Search 03-23-2023
0 2
0
2
dpuhr
Hi,I am looking for a solution to a problem that has been addressed here: Using a column of field names to dynamicall...
by dpuhr Explorer in Splunk Search 03-23-2023
0 8
0
8
Konrad_Schlude
I'm looking for a way to search for freetext after a join.It is easy when the field is known. For instance, there is ...
by Konrad_Schlude Explorer in Splunk Search 03-23-2023
0 3
0
3
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...