Splunk Search

Splunk Search
Community Activity
nmayafit
Hi. Subject is confusing so here goes. I have 3 log lines: org=A Status=Success org=A Status=Fail org=B Status=Succes...
by nmayafit Path Finder in Splunk Search 03-22-2023
0 8
0
8
apand84
Hi Everyone,  I am looking for idea to implement a case where subqueries  will be run based on the user choice from c...
by apand84 Engager in Splunk Search 03-21-2023
0 1
0
1
Mike6960
I created a outputlookup  file with just one column ...My search | table D_ID  | outputlookup Total.csv I want to use...
by Mike6960 Path Finder in Splunk Search 03-21-2023
0 15
0
15
pm2012
Hey SMEs, Has anyone having any prior experience of migrating existing Qradar data to Splunk. Any docs or something u...
by pm2012 Explorer in Splunk Search 03-21-2023
0 4
0
4
algol2
I'm new to Splunk, so apologies if this is a silly question. I have a log file that reads:     2023-03-22 00:57:09,51...
by algol2 Engager in Splunk Search 03-21-2023
0 3
0
3
just4bs
I have a .csv file that I have uploaded as a lookup file that works fine when I run a search.  If I ask another user ...
by just4bs New Member in Splunk Search 03-21-2023
0 2
0
2
Hisae
Hello Everyone, I am trying to find outliers in connection duration on a specific subnet but having trouble getting t...
by Hisae Engager in Splunk Search 03-21-2023
0 2
0
2
changwoo
What are the big differences?
by changwoo Communicator in Splunk Search 03-21-2023
1 5
1
5
DaveBunn
CVE-2023-23397 is all the rage right now.Has anyone figured out a way to detect this in office content?I've checked a...
by DaveBunn Path Finder in Splunk Search 03-21-2023
0 5
0
5
bosseres
Hello everyone,  I have events which contains such fields user1=..., user2=...., user3... etc And I have lookup which...
by bosseres Contributor in Splunk Search 03-21-2023
0 3
0
3
coreyCLI
I am trying to pair down the list of ciphers we are using.  When I remove AES256-GCM-SHA384 I begin to get the below ...
by coreyCLI Communicator in Splunk Search 03-21-2023
0 4
0
4
avadhutha
I have a string like below and unable to extract accuratly with rex command please suggest  any alternative way. _raw...
by avadhutha Explorer in Splunk Search 03-21-2023
0 2
0
2
vineela
I am trying to extract the fields in json format. But not able to fetch the data.PFB screenshot for reference: not a...
by vineela Path Finder in Splunk Search 03-21-2023
0 5
0
5
norbertt911
Hello Splunkers, I would like to have to set an alert if a sudden high amount of events are received.  I have this ba...
by norbertt911 Communicator in Splunk Search 03-21-2023
0 7
0
7
Ashwini008
Hi,I am formatting data as required and getting it in below format. Now I want to calculate average of only highlight...
by Ashwini008 Builder in Splunk Search 03-21-2023
0 4
0
4
Abass42
So I couldn't find anything in splunk community that answers my question about pushing an update to a lookup table. I...
by Abass42 Communicator in Splunk Search 03-20-2023
0 3
0
3
w564432
Hello, We have an application pulling search results from a scheduled search using Splunk API periodically, but encou...
by w564432 Explorer in Splunk Search 03-20-2023
0 2
0
2
jason_hotchkiss
Hello - I have a table with the following:host HOSTFQDNDNS_NAMEHOST_MATCHINDEXhostalphahosta.mydomain.comhostafalsein...
by jason_hotchkiss Communicator in Splunk Search 03-20-2023
0 2
0
2
MaratD
Hi all, I have the following events source_host=lioness1 source_host_description="This is the main server" source_hos...
by MaratD Explorer in Splunk Search 03-20-2023
0 7
0
7
TerryM
Individually these searches work: ```#1 sum all values in field repeat_count in all threat logs that are M,H,C severi...
by TerryM Engager in Splunk Search 03-20-2023
0 5
0
5
LogUx
Hello Splunkers!! I have mentioned below query and from the below query I want a results as shown below in the excel....
by LogUx Motivator in Splunk Search 03-20-2023
0 8
0
8
Woodpecker
Hi,I have a query which gives a table of results. Now instead of exporting the table, I need to export the raw events...
by Woodpecker Path Finder in Splunk Search 03-20-2023
0 3
0
3
Kirthika
I want X axis to be follow the same way as legend order. 
by Kirthika Path Finder in Splunk Search 03-20-2023
0 6
0
6
suspense
Hello, Good Day!I have mail logs and I need to check if sender appeared before in last 30 days.I have issues with wri...
by suspense Explorer in Splunk Search 03-20-2023
0 3
0
3
jmartens
I am trying to expand multiple fields from specific log lines using mvexpand but for some strange reason some fields ...
by jmartens Path Finder in Splunk Search 03-20-2023
0 4
0
4
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...