Splunk Search

Splunk Search
Community Activity
DaveBunn
CVE-2023-23397 is all the rage right now.Has anyone figured out a way to detect this in office content?I've checked a...
by DaveBunn Path Finder in Splunk Search 03-21-2023
0 5
0
5
bosseres
Hello everyone,  I have events which contains such fields user1=..., user2=...., user3... etc And I have lookup which...
by bosseres Contributor in Splunk Search 03-21-2023
0 3
0
3
coreyCLI
I am trying to pair down the list of ciphers we are using.  When I remove AES256-GCM-SHA384 I begin to get the below ...
by coreyCLI Communicator in Splunk Search 03-21-2023
0 4
0
4
avadhutha
I have a string like below and unable to extract accuratly with rex command please suggest  any alternative way. _raw...
by avadhutha Explorer in Splunk Search 03-21-2023
0 2
0
2
vineela
I am trying to extract the fields in json format. But not able to fetch the data.PFB screenshot for reference: vineel...
by vineela Path Finder in Splunk Search 03-21-2023
0 5
0
5
norbertt911
Hello Splunkers, I would like to have to set an alert if a sudden high amount of events are received.  I have this ba...
by norbertt911 Communicator in Splunk Search 03-21-2023
0 7
0
7
Ashwini008
Hi,I am formatting data as required and getting it in below format. Now I want to calculate average of only highlight...
by Ashwini008 Builder in Splunk Search 03-21-2023
0 4
0
4
Abass42
So I couldn't find anything in splunk community that answers my question about pushing an update to a lookup table. I...
by Abass42 Communicator in Splunk Search 03-20-2023
0 3
0
3
w564432
Hello, We have an application pulling search results from a scheduled search using Splunk API periodically, but encou...
by w564432 Explorer in Splunk Search 03-20-2023
0 2
0
2
jason_hotchkiss
Hello - I have a table with the following:host HOSTFQDNDNS_NAMEHOST_MATCHINDEXhostalphahosta.mydomain.comhostafalsein...
by jason_hotchkiss Communicator in Splunk Search 03-20-2023
0 2
0
2
MaratD
Hi all, I have the following events source_host=lioness1 source_host_description="This is the main server" source_hos...
by MaratD Explorer in Splunk Search 03-20-2023
0 7
0
7
TerryM
Individually these searches work: ```#1 sum all values in field repeat_count in all threat logs that are M,H,C severi...
by TerryM Engager in Splunk Search 03-20-2023
0 5
0
5
LogUx
Hello Splunkers!! I have mentioned below query and from the below query I want a results as shown below in the excel....
by LogUx Motivator in Splunk Search 03-20-2023
0 8
0
8
Woodpecker
Hi,I have a query which gives a table of results. Now instead of exporting the table, I need to export the raw events...
by Woodpecker Path Finder in Splunk Search 03-20-2023
0 3
0
3
Kirthika
I want X axis to be follow the same way as legend order. 
by Kirthika Path Finder in Splunk Search 03-20-2023
0 6
0
6
suspense
Hello, Good Day!I have mail logs and I need to check if sender appeared before in last 30 days.I have issues with wri...
by suspense Explorer in Splunk Search 03-20-2023
0 3
0
3
jmartens
I am trying to expand multiple fields from specific log lines using mvexpand but for some strange reason some fields ...
by jmartens Path Finder in Splunk Search 03-20-2023
0 4
0
4
drogo
Hi, I have injected NATS stream details in json format to the splunk and it look below. Wanted to extract key value p...
by drogo Explorer in Splunk Search 03-19-2023
0 6
0
6
sandeepparcha44
Hi Team, I am trying to search <string1> and <String2> from different lines in same log having 100 lines, if both mat...
by sandeepparcha44 Explorer in Splunk Search 03-19-2023
0 6
0
6
boxmetal
Hi all,I want to get data from an xml file from a selected source ( eg: Source_A, Source_B, ...). When there is no da...
by boxmetal Path Finder in Splunk Search 03-19-2023
0 1
0
1
sshubh
Hi, Here is my Data in 2 logs having 3 fields: Log1: Books Bought AccountName={} , BookIds={} (here BookId can contai...
by sshubh Explorer in Splunk Search 03-18-2023
0 5
0
5
MonkeyK
Sometimes I run a really complex query and accumulate results in a lookup table.  I recently tried doing this and inc...
by MonkeyK Builder in Splunk Search 03-18-2023
0 2
0
2
att35
We have some logs coming in the following format.    ERROR | 2023-03-16 01:27:14 EDT | field1=field1_value | field2=f...
by att35 Builder in Splunk Search 03-18-2023
0 11
0
11
clorne
Hello, I have data collected through a Splunk HEC on a Heavy Forwarder. The data has this structure: 2023-03-16T16:59...
by clorne Communicator in Splunk Search 03-18-2023
0 8
0
8
k31453
Hi, I have a particular service which we triggered occasionally and I would like to know the earliest time of every t...
by k31453 Explorer in Splunk Search 03-18-2023
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors