Splunk Search

Splunk Search
Community Activity
w344423
I got to calculate the rest of the row based on the first value generated in the new column called 12days. Attempted ...
by w344423 Explorer in Splunk Search 03-12-2023
1 2
1
2
sarit_s
Hello How can I trigger an alert after checking the results for 3 minuets So for example, if I want that the alert wi...
by sarit_s Communicator in Splunk Search 03-12-2023
0 1
0
1
uagraw01
Hello Splunkers!! I have two fields AND I want to concatenate both the fields.Location : 3102.01.03element : S82(=310...
by uagraw01 Motivator in Splunk Search 03-12-2023
0 4
0
4
pmittal
Hi, I am new to Splunk and have very little knowledge. I am seeking help for following use case: Query1 gives process...
by pmittal Engager in Splunk Search 03-11-2023
0 1
0
1
chaitanya1
0
1
TangSauce
Hello All,I have been scouring the community and other boards but for the life of me cannot create a SPL query to get...
by TangSauce Engager in Splunk Search 03-11-2023
0 8
0
8
akidua
I have 2 different search queries and I want to calculate sum of differences between time of event 1 and event 2 (in ...
by akidua Explorer in Splunk Search 03-10-2023
0 3
0
3
nu_learner
Hello - I need to calculate the average duration between two status types for a user type in a location in a region. ...
by nu_learner Explorer in Splunk Search 03-10-2023
0 2
0
2
sjringo
I am trying to create a search to generate an alert if I find a host that has more than 1000 events for two consecuti...
by sjringo Contributor in Splunk Search 03-10-2023
0 11
0
11
atebysandwich
I have two look up and both have a field called DNS. I need to figure out which values in those fields match. I have ...
by atebysandwich Path Finder in Splunk Search 03-10-2023
0 2
0
2
Taruchit
Hi All,I have 4 indexes: -index1index2index3index4Each index has its own search criteria, there are some common field...
by Taruchit Contributor in Splunk Search 03-10-2023
0 4
0
4
KhalidSheikh
While processing an AS request for target service krbtgt, the account XXX-G-Dashboard-Dev did not have a suitable key...
by KhalidSheikh Engager in Splunk Search 03-10-2023
0 2
0
2
zewashere
Hello, i'm new to Splunk and i need some advices.I've created a lookup named my_color_lookup, with 2 column : color,d...
by zewashere New Member in Splunk Search 03-10-2023
0 1
0
1
Vivekmishra01
I want to add new row to my search result using values from the previous result. Basically I am counting few strings ...
by Vivekmishra01 Explorer in Splunk Search 03-10-2023
0 3
0
3
jason_hotchkiss
Hello I have the following search which produces  statistics(746) in Splunk: index=my_index sourcetype=my_st id=100 h...
by jason_hotchkiss Communicator in Splunk Search 03-10-2023
0 3
0
3
cmcdole
I need to create a single field named MemberOf from the XML snippet below.  It should look like this: memberOf CN=But...
by cmcdole Path Finder in Splunk Search 03-10-2023
0 4
0
4
Ashwini008
Hi,I want to write a case condition where i can check values from Range column.For instanceIf range for both cost & p...
by Ashwini008 Builder in Splunk Search 03-10-2023
0 5
0
5
ivan5593
Hello,I'm having an issue with a field search. I have a lookup where I specify for every sourcetype which field is re...
by ivan5593 Explorer in Splunk Search 03-09-2023
0 2
0
2
SplunkDash
Hello, I have complex JSON events ingested as *.log files. I have issues (or couldn't do) with extracting fields from...
by SplunkDash Motivator in Splunk Search 03-09-2023
0 25
0
25
ckutach
I have 2 groups of data:messageId1: ['A', 'B', 'C']messageId2: ['A', 'E', 'F', 'G', 'T', 'Z'] How do I return the val...
by ckutach Engager in Splunk Search 03-09-2023
0 2
0
2
vik
I am trying to split the values in both the columns and create 5 rows by assigning respective values. I need an outpu...
by vik Explorer in Splunk Search 03-09-2023
0 2
0
2
sjim
Here's my query: index=comp_logs "processed=" | eval name=consumerGroupId | timechart span=1h sum(processed) as proce...
by sjim Loves-to-Learn in Splunk Search 03-09-2023
0 1
0
1
marcos_eng1
Hello Splunkers,  I have client that already has a IBM Qradar SIEM and wants to Integrates with Splunk SOAR (formely ...
by marcos_eng1 Explorer in Splunk Search 03-09-2023
0 1
0
1
shady6
Following is my query:index=backup | stats count by errorsI have thousands of error codes in logs and I need to trigg...
by shady6 Loves-to-Learn in Splunk Search 03-09-2023
0 1
0
1
Nico99
Hello community!I'm looking for a way to optimize this search below and I need some help : index="oswinsec" source="X...
by Nico99 Explorer in Splunk Search 03-09-2023
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...