Splunk Search

Splunk Search
Community Activity
danutmatei
Hello, I have a data model named firewall_logs with firewall data in which the interesting fields are: file_hash, url...
by danutmatei Explorer in Splunk Search 02-22-2023
0 0
0
0
JBlackberg
Very strange scenario. I'll use a rex statement to retrieve data and it works perfectly. If I copy and paste the rex ...
by JBlackberg Engager in Splunk Search 02-22-2023
0 5
0
5
GhanaRusk
I've a query   index="main" app="student-api" "tags.path"=/enroll "response"=succcess   which also gives a trace_id a...
by GhanaRusk Engager in Splunk Search 02-22-2023
0 11
0
11
Kitag345
I need to create a correlation search that would trigger an alert if it found a match from IPs from: | inputlookup ip...
by Kitag345 Explorer in Splunk Search 02-21-2023
0 1
0
1
Navanitha
Good day,I have a usecase explained below -Index A has Reporting_Host (mix of IP address, hostname, FQDN) and Index C...
by Navanitha Path Finder in Splunk Search 02-21-2023
0 5
0
5
thisissplunk
I'm trying to do a DOES NOT match() instead of a match(). http://docs.splunk.com/Documentation/Splunk/6.1/SearchRefer...
by thisissplunk Builder in Splunk Search 02-21-2023
1 4
1
4
atebysandwich
I'm trying to figure out the percent of successful authentications from out vulnerability scans. There is a field nam...
by atebysandwich Path Finder in Splunk Search 02-21-2023
0 3
0
3
kbarton
Hi,I am new to Splunk so please forgive me.I had created a field field, where if the hostname contains "*-us*" then r...
by kbarton New Member in Splunk Search 02-21-2023
0 3
0
3
lostcauz3
Hi,I have an index= random_index which contains JSON data of a URL HTTP status code like {'availability':200,applicat...
by lostcauz3 Path Finder in Splunk Search 02-21-2023
0 1
0
1
joe06031990
Hi, For field extractions in a clustered environment do you have to use the props.conf method or can you use the fiel...
by joe06031990 Communicator in Splunk Search 02-21-2023
0 1
0
1
sergimola
I am sending some traces from my service to Splunk using the OpenTelemetry Collector and the Splunk HEC exporter. My ...
by sergimola Explorer in Splunk Search 02-21-2023
0 5
0
5
zakirhere
Hi, I have an unusual scenario for the data I am working with and would like to see if it's even possible to extract ...
by zakirhere New Member in Splunk Search 02-21-2023
0 2
0
2
AKBBB
Hi All, After splunk upgrade from 8.0 to 9.0.2 , i am facing the slowness in alerting to create ticket . Can anyone h...
by AKBBB Explorer in Splunk Search 02-21-2023
0 0
0
0
ravikumar_sri20
Hi Experts,I have below eventsEvent 1 : TRANEND TRANS ABENDS TRN1 ABN1 blah blahEvent 2 : TRANEND CICS_TRAN_Abends CI...
by ravikumar_sri20 Engager in Splunk Search 02-21-2023
0 3
0
3
anissabnk
Hello  I need your help for a subject.  I want to combine two search results and I need you help beacause I have a p...
by anissabnk Path Finder in Splunk Search 02-21-2023
0 7
0
7
willspk
Hey all, Our raw syslogs are showing IP addresses of sourced events, but the results in Splunk is changing the IP add...
by willspk Engager in Splunk Search 02-21-2023
0 3
0
3
Raymond2T
I decided to make a search with following situation.  However, I would like to enhance the performance that when user...
by Raymond2T Path Finder in Splunk Search 02-21-2023
0 7
0
7
aaa2324
I am looking to get the data in year, month, day, hour, minute and second basissearch criteria is index="abc" rex fie...
by aaa2324 Explorer in Splunk Search 02-21-2023
0 2
0
2
splunkcol
Hi, I hope that asking this question will not cause controversy. I currently manage a hybrid between Splunk and ELK, ...
by splunkcol Builder in Splunk Search 02-21-2023
0 1
0
1
jnhth
Hi, This work when I use it at search time: | spath path=messageParts{} output=message | mvexpand message | rex field...
by jnhth Explorer in Splunk Search 02-21-2023
0 0
0
0
11v
Hi Team,working on how to log individual rows in my search result table as individual events in Splunk. Below is a pi...
by 11v New Member in Splunk Search 02-20-2023
0 1
0
1
michaelnorup
So i am trying to get a list of inactive splunk users. I have first tried just grabbing a list of all the users with ...
by michaelnorup Communicator in Splunk Search 02-20-2023
0 2
0
2
LRathinakumar
Hello Splunkers,I have two lookups which are need to join. In lookup1.csv its containing the Rule name and the techni...
by LRathinakumar Explorer in Splunk Search 02-20-2023
0 3
0
3
chimell1
I cannot find data in field named version in my request. Please help me.See request belong   |mstats min(cpu_metric.p...
by chimell1 Explorer in Splunk Search 02-20-2023
0 3
0
3
smith_
Hi, Could you help me in editing the below search  index=test sourcetype="centino" | stats count, values(change_asset...
by smith_ Builder in Splunk Search 02-20-2023
0 7
0
7
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors