Splunk Search

Splunk Search
Community Activity
MonkeyK
I've been trying to write an alert that notifies our SOC when someone tries to obfuscate their command with base64 en...
by MonkeyK Builder in Splunk Search 03-15-2023
0 8
0
8
adamscaa1
I have a lookup file of HostNames HostNameHost1Host2Host3Host4Host5   I would like to create a search to include even...
by adamscaa1 Explorer in Splunk Search 03-15-2023
0 7
0
7
Renunaren
The above snippet consists of the raw data in the events in our splunk environment. Need Help in extracting the jobId...
by Renunaren Loves-to-Learn Everything in Splunk Search 03-15-2023
0 2
0
2
sphiwee
I have current search index="intau_workfusion" host=* sourcetype="services_status.out.log" service="HTTP/1.1" status=...
by sphiwee Contributor in Splunk Search 03-15-2023
0 4
0
4
dieguiariel
Hi! im working on an alert for access from different countries for certain users in a short time period. The alert an...
by dieguiariel Path Finder in Splunk Search 03-15-2023
0 3
0
3
dmbrcx
Hi, I am using tstats to search the Network Datamodel for outbound SMB traffic (port 445) to external IP address rang...
by dmbrcx Explorer in Splunk Search 03-14-2023
0 2
0
2
awant68
Hello, I am stuck on a query and need someone's help please.  The goal of the query is to perform a lookup on column ...
by awant68 Explorer in Splunk Search 03-14-2023
0 6
0
6
kalaiyarasi
Hi, I have onboarded data via DBConnect through Rising Column for which we have configured the Risinig Column value a...
by kalaiyarasi Loves-to-Learn Lots in Splunk Search 03-14-2023
0 1
0
1
isaiz
I created a summary index with a custom _raw from a tstats search from 03/14/2023 16:30:00 to 03/14/2023 16:35:00:| t...
by isaiz Loves-to-Learn Lots in Splunk Search 03-14-2023
0 0
0
0
JoshSaunders
I have a specific event that I'm looking to do an average count for the past 5 business days. Right now, I'm able to ...
by JoshSaunders Explorer in Splunk Search 03-14-2023
0 10
0
10
potnuru
Is there any command in Splunk for Looping other than Map command ? Requirement is described as below: I can't prov...
by potnuru Path Finder in Splunk Search 03-14-2023
0 12
0
12
uagraw01
Hello Splunkers!! I have qlick view search. And I want to use same kind of search in Splunk. Please help me how can I...
by uagraw01 Motivator in Splunk Search 03-14-2023
0 6
0
6
lennys26
I am building a query where I want to use a top 10 list of values from a lookup table, and then run a search against ...
by lennys26 Communicator in Splunk Search 03-14-2023
0 6
0
6
amitrinx
I have three queries:Overall Traffic to LogOn pagesourcetype="od" operation=LogOn http_method=GET http_url="*LogOn*" ...
by amitrinx Explorer in Splunk Search 03-14-2023
0 3
0
3
Vish
I have a bar chart in splunk which has x-axis as each week from 2019 to 2023 and y-axis as count of data.Now i want t...
by Vish Explorer in Splunk Search 03-14-2023
0 1
0
1
sulaimancds
1st query       index=mail NOT [ | inputlookup suspicoussubject_keywords.csv | rename keyword AS query | fields query...
by sulaimancds Engager in Splunk Search 03-13-2023
0 21
0
21
same
I am trying to extract only the top values ​​from fields such as argument, uri, and method for the WAF log.Currently,...
by same Engager in Splunk Search 03-13-2023
0 3
0
3
atebysandwich
I have a lookup of hosts with a field Last_Scan_Datetime and the field values were formated using strftime(_time, "%Y...
by atebysandwich Path Finder in Splunk Search 03-13-2023
0 2
0
2
pierre_weg
Hi guys!I have a sourcetype "A" with some info about infrastructure. Host IP is one of this info. I have another sour...
by pierre_weg Path Finder in Splunk Search 03-13-2023
0 3
0
3
agoktas
Hello, I want to alter the radial gauge (default is 100). We expect about 5,000 log entries/lines per hour and I am c...
by agoktas Communicator in Splunk Search 03-13-2023
0 3
0
3
atebysandwich
I have two lookups. One lookup has Hostnames and IPs and the other has hostnames. I would like to run a search so I c...
by atebysandwich Path Finder in Splunk Search 03-13-2023
0 1
0
1
arunslal
Hi,I am able to run normal search using rest API using below syntax: https://SearchHead_host:8089/servicesNS/admin/se...
by arunslal Loves-to-Learn Lots in Splunk Search 03-13-2023
0 2
0
2
akidua
I have 2 queries:One is an OFF event, and one is an ON event for a cluster of machines for customers. I want to calcu...
by akidua Explorer in Splunk Search 03-13-2023
0 5
0
5
jrock
Hi all, Recently I have been working on getting a query that can help me identify the execution of malicious document...
by jrock Observer in Splunk Search 03-13-2023
0 5
0
5
neiowe
I am looking to not ingest events from a specific IP address. I have an IP address that once a week generates a LOT o...
by neiowe Path Finder in Splunk Search 03-13-2023
0 25
0
25
Get Updates on the Splunk Community!

Quantify Your Splunk Investment Impact: Introducing Savings Metrics to Value Insights

Building on the foundation established in our initial Value Insights releases, we are introducing the Savings ...

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...
Top Solution Authors