Splunk Search

Splunk Search
Community Activity
sulaimancds
1st query       index=mail NOT [ | inputlookup suspicoussubject_keywords.csv | rename keyword AS query | fields query...
by sulaimancds Engager in Splunk Search 03-13-2023
0 21
0
21
same
I am trying to extract only the top values ​​from fields such as argument, uri, and method for the WAF log.Currently,...
by same Engager in Splunk Search 03-13-2023
0 3
0
3
atebysandwich
I have a lookup of hosts with a field Last_Scan_Datetime and the field values were formated using strftime(_time, "%Y...
by atebysandwich Path Finder in Splunk Search 03-13-2023
0 2
0
2
pierre_weg
Hi guys!I have a sourcetype "A" with some info about infrastructure. Host IP is one of this info. I have another sour...
by pierre_weg Path Finder in Splunk Search 03-13-2023
0 3
0
3
agoktas
Hello, I want to alter the radial gauge (default is 100). We expect about 5,000 log entries/lines per hour and I am c...
by agoktas Communicator in Splunk Search 03-13-2023
0 3
0
3
atebysandwich
I have two lookups. One lookup has Hostnames and IPs and the other has hostnames. I would like to run a search so I c...
by atebysandwich Path Finder in Splunk Search 03-13-2023
0 1
0
1
arunslal
Hi,I am able to run normal search using rest API using below syntax: https://SearchHead_host:8089/servicesNS/admin/se...
by arunslal Loves-to-Learn Lots in Splunk Search 03-13-2023
0 2
0
2
akidua
I have 2 queries:One is an OFF event, and one is an ON event for a cluster of machines for customers. I want to calcu...
by akidua Explorer in Splunk Search 03-13-2023
0 5
0
5
jrock
Hi all, Recently I have been working on getting a query that can help me identify the execution of malicious document...
by jrock Observer in Splunk Search 03-13-2023
0 5
0
5
neiowe
I am looking to not ingest events from a specific IP address. I have an IP address that once a week generates a LOT o...
by neiowe Path Finder in Splunk Search 03-13-2023
0 25
0
25
danutmatei
Hi, I have a policy.csv file with 2 columns: user                   tags Andre               IT Kleo                 ...
by danutmatei Explorer in Splunk Search 03-13-2023
0 11
0
11
smith_
Hi All, I'm looking to find all the latest entry of user, There should be no double entry for any userProfile -----> ...
by smith_ Builder in Splunk Search 03-13-2023
0 1
0
1
amitrinx
Hi, I have a combination of consumer limits e.g, A=1000 b=500 c=500 d=200 rest=100So basically i want a list of all c...
by amitrinx Explorer in Splunk Search 03-13-2023
0 1
0
1
rohit_d
I have splunk query which runs every 5 minutes and alert if certain keyword is not logged in index in last 5 minutes....
by rohit_d Engager in Splunk Search 03-13-2023
0 1
0
1
LogUx
Hello Splunkers!! I have below value S000081(=00003102+LCC000060-0000550S00003)I want to replace above value withS81(...
by LogUx Motivator in Splunk Search 03-13-2023
0 8
0
8
the_wolverine
*Forcefully terminated search process with sid=1517416303.2383_ABC123 since its physical memory usage (36521.336000 M...
by the_wolverine Champion in Splunk Search 03-13-2023
0 5
0
5
LogUx
Hello Splunkers!!   I want a list of dashboards and those dashboards are using saved searches & macros. How I can ach...
by LogUx Motivator in Splunk Search 03-12-2023
0 1
0
1
w344423
I got to calculate the rest of the row based on the first value generated in the new column called 12days. Attempted ...
by w344423 Explorer in Splunk Search 03-12-2023
1 2
1
2
sarit_s
Hello How can I trigger an alert after checking the results for 3 minuets So for example, if I want that the alert wi...
by sarit_s Communicator in Splunk Search 03-12-2023
0 1
0
1
LogUx
Hello Splunkers!! I have two fields AND I want to concatenate both the fields.Location : 3102.01.03element : S82(=310...
by LogUx Motivator in Splunk Search 03-12-2023
0 4
0
4
pmittal
Hi, I am new to Splunk and have very little knowledge. I am seeking help for following use case: Query1 gives process...
by pmittal Engager in Splunk Search 03-11-2023
0 1
0
1
chaitanya1
0
1
TangSauce
Hello All,I have been scouring the community and other boards but for the life of me cannot create a SPL query to get...
by TangSauce Engager in Splunk Search 03-11-2023
0 8
0
8
akidua
I have 2 different search queries and I want to calculate sum of differences between time of event 1 and event 2 (in ...
by akidua Explorer in Splunk Search 03-10-2023
0 3
0
3
nu_learner
Hello - I need to calculate the average duration between two status types for a user type in a location in a region. ...
by nu_learner Explorer in Splunk Search 03-10-2023
0 2
0
2
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...