Splunk Search

Splunk Search
Community Activity
arunslal
Hi,I am able to run normal search using rest API using below syntax: https://SearchHead_host:8089/servicesNS/admin/se...
by arunslal Loves-to-Learn Lots in Splunk Search 03-13-2023
0 2
0
2
akidua
I have 2 queries:One is an OFF event, and one is an ON event for a cluster of machines for customers. I want to calcu...
by akidua Explorer in Splunk Search 03-13-2023
0 5
0
5
jrock
Hi all, Recently I have been working on getting a query that can help me identify the execution of malicious document...
by jrock Observer in Splunk Search 03-13-2023
0 5
0
5
neiowe
I am looking to not ingest events from a specific IP address. I have an IP address that once a week generates a LOT o...
by neiowe Path Finder in Splunk Search 03-13-2023
0 25
0
25
danutmatei
Hi, I have a policy.csv file with 2 columns: user                   tags Andre               IT Kleo                 ...
by danutmatei Explorer in Splunk Search 03-13-2023
0 11
0
11
Raj
Hi All, I'm looking to find all the latest entry of user, There should be no double entry for any userProfile -----> ...
by Raj Builder in Splunk Search 03-13-2023
0 1
0
1
amitrinx
Hi, I have a combination of consumer limits e.g, A=1000 b=500 c=500 d=200 rest=100So basically i want a list of all c...
by amitrinx Explorer in Splunk Search 03-13-2023
0 1
0
1
rohit_d
I have splunk query which runs every 5 minutes and alert if certain keyword is not logged in index in last 5 minutes....
by rohit_d Engager in Splunk Search 03-13-2023
0 1
0
1
uagraw01
Hello Splunkers!! I have below value S000081(=00003102+LCC000060-0000550S00003)I want to replace above value withS81(...
by uagraw01 Motivator in Splunk Search 03-13-2023
0 8
0
8
the_wolverine
*Forcefully terminated search process with sid=1517416303.2383_ABC123 since its physical memory usage (36521.336000 M...
by the_wolverine Champion in Splunk Search 03-13-2023
0 5
0
5
uagraw01
Hello Splunkers!!   I want a list of dashboards and those dashboards are using saved searches & macros. How I can ach...
by uagraw01 Motivator in Splunk Search 03-12-2023
0 1
0
1
w344423
I got to calculate the rest of the row based on the first value generated in the new column called 12days. Attempted ...
by w344423 Explorer in Splunk Search 03-12-2023
1 2
1
2
sarit_s
Hello How can I trigger an alert after checking the results for 3 minuets So for example, if I want that the alert wi...
by sarit_s Communicator in Splunk Search 03-12-2023
0 1
0
1
uagraw01
Hello Splunkers!! I have two fields AND I want to concatenate both the fields.Location : 3102.01.03element : S82(=310...
by uagraw01 Motivator in Splunk Search 03-12-2023
0 4
0
4
pmittal
Hi, I am new to Splunk and have very little knowledge. I am seeking help for following use case: Query1 gives process...
by pmittal Engager in Splunk Search 03-11-2023
0 1
0
1
chaitanya1
0
1
TangSauce
Hello All,I have been scouring the community and other boards but for the life of me cannot create a SPL query to get...
by TangSauce Engager in Splunk Search 03-11-2023
0 8
0
8
akidua
I have 2 different search queries and I want to calculate sum of differences between time of event 1 and event 2 (in ...
by akidua Explorer in Splunk Search 03-10-2023
0 3
0
3
nu_learner
Hello - I need to calculate the average duration between two status types for a user type in a location in a region. ...
by nu_learner Explorer in Splunk Search 03-10-2023
0 2
0
2
sjringo
I am trying to create a search to generate an alert if I find a host that has more than 1000 events for two consecuti...
by sjringo Contributor in Splunk Search 03-10-2023
0 11
0
11
atebysandwich
I have two look up and both have a field called DNS. I need to figure out which values in those fields match. I have ...
by atebysandwich Path Finder in Splunk Search 03-10-2023
0 2
0
2
Taruchit
Hi All,I have 4 indexes: -index1index2index3index4Each index has its own search criteria, there are some common field...
by Taruchit Contributor in Splunk Search 03-10-2023
0 4
0
4
KhalidSheikh
While processing an AS request for target service krbtgt, the account XXX-G-Dashboard-Dev did not have a suitable key...
by KhalidSheikh Engager in Splunk Search 03-10-2023
0 2
0
2
zewashere
Hello, i'm new to Splunk and i need some advices.I've created a lookup named my_color_lookup, with 2 column : color,d...
by zewashere New Member in Splunk Search 03-10-2023
0 1
0
1
Vivekmishra01
I want to add new row to my search result using values from the previous result. Basically I am counting few strings ...
by Vivekmishra01 Explorer in Splunk Search 03-10-2023
0 3
0
3
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...