Splunk Search

Splunk Search
Community Activity
ft_kd02
Hi all,I'm working on a dashboard in which I populate a panel with summary data. The summary data runs once per hour ...
by ft_kd02 Path Finder in Splunk Search 02-16-2023
0 3
0
3
fredclown
I'm logged into my system as an admin, so I have access to all the indexes. I've also verified this by looking at the...
by fredclown Builder in Splunk Search 02-16-2023
0 1
0
1
GhanaRusk
I've a couple of queries - index="main"app="student-api" "tags.studentId"=3B70E5 message="Id and pwd entered correctl...
by GhanaRusk Engager in Splunk Search 02-16-2023
0 11
0
11
sabari80
Following query is printing 'pp_user_action_name','Total_Calls','Avg_User_Action_Response' not getting 'pp_user_actio...
by sabari80 Explorer in Splunk Search 02-16-2023
0 3
0
3
gut1kor
Hi Team,I have events being pushed to HTTP event collector 24/7. In my dashboard I query and format the events using ...
by gut1kor Explorer in Splunk Search 02-16-2023
0 0
0
0
Shobhitha1
Hello Everyone, I have a requirement where I have to generate a query.  event 1 : <l:event dateTime="2023-02-10 11:28...
by Shobhitha1 New Member in Splunk Search 02-16-2023
0 3
0
3
Stijn
source=PR1 sourcetype="sap:abap" EVENT_TYPE=STAD EVENT_SUBTYPE=MAIN (TCODE="ZORF_BOX_CLOSING") SYUCOMM="SICH_T" ACCOU...
by Stijn Loves-to-Learn in Splunk Search 02-16-2023
0 3
0
3
midcoffessplunk
メインサーチのイベントの_timeをサブサーチに渡したいのですが、上手くいきません。何か方法はありますでしょうか。 index=event_data|eval earlytime=_time-60 latesttime=_time+6...
by midcoffessplunk Engager in Splunk Search 02-15-2023
0 1
0
1
dickersons
Hi, I am using a regex to search for a field "statusCode" which could have multiple values, i.e. "200", "400", "500",...
by dickersons Explorer in Splunk Search 02-15-2023
0 5
0
5
LeeMoe
I have a dataset which has a column "Port" that contains (limited) numerical values.  I want to make these values dis...
by LeeMoe Path Finder in Splunk Search 02-15-2023
0 8
0
8
solaced
I have a lookup which I want to compare search results against and find duplicate values.   How do I ignore duplicate...
by solaced Explorer in Splunk Search 02-15-2023
0 5
0
5
carl_landry
Hi, I have a problem finding answers about the failure of a universal forwarder to re-ingest an XML file. 02-08-2023 ...
by carl_landry New Member in Splunk Search 02-15-2023
0 0
0
0
splunkuser320
I am trying to create a query to get the sum of multiple fields by a field.    index="*****"|stats sum(field_A) as  A...
by splunkuser320 Path Finder in Splunk Search 02-15-2023
0 2
0
2
MDSplunkNinja
I have a table of data with values like this:String         NumericClient 1      99.9Client 2      99.2Client 3      ...
by MDSplunkNinja Explorer in Splunk Search 02-15-2023
0 2
0
2
Woodpecker
Hi,I have search which has S_host name values of different DB instances say MSSQL and Oracle in a single field.eg: S_...
by Woodpecker Path Finder in Splunk Search 02-14-2023
0 2
0
2
smith_
Hi,I want to create a search out of the below event, to raise an alert if the particular system having the label lost...
by smith_ Builder in Splunk Search 02-14-2023
0 10
0
10
sahilmits
Here is the query i have and need to extract the "sts:ExternalId"   requestParameters: { [-]policyDocument: {<!-- -->"Version...
by sahilmits Engager in Splunk Search 02-14-2023
0 7
0
7
sjringo
If I am starting with this query:index&#61;anIndex sourcetype&#61;aSourcetype ( aJobName AND "COMPLETED OK" )The job im inter...
by sjringo Contributor in Splunk Search 02-14-2023
0 1
0
1
queriousGeorge
I have two searches that will return orderNumbers 1.index&#61;main "Failed insert" | table orderNumber//returns small lis...
by queriousGeorge Engager in Splunk Search 02-14-2023
0 3
0
3
power12
Hello Splunkers,I have a field called state_sinfo which have values like (up,up*,up$,up^,continue,continue$,continued...
by power12 Communicator in Splunk Search 02-14-2023
0 1
0
1
akpuvvada
I am trying to find entries between a date-time range based on a field in the event 'Date'. It date-time value of the...
by akpuvvada Engager in Splunk Search 02-14-2023
0 1
0
1
nomad1981
Hi, I'm trying to build a line graph that would show me the completion time of an event on a daily basis. The complet...
by nomad1981 Explorer in Splunk Search 02-14-2023
0 3
0
3
erikschubert
Hey everyone,I want to create a search that gives me the following information in a structured way: Which type of hos...
by erikschubert Engager in Splunk Search 02-14-2023
0 3
0
3
gazoscreek
I need to provide audit details on our ES Content Library. Using rest, I can identify searches that have been updated...
by gazoscreek Path Finder in Splunk Search 02-14-2023
0 1
0
1
joock3r
Hi, I have a lookup definition that look like that: joock3r_2-1676389169438.png When I'm running this search with loo...
by joock3r Explorer in Splunk Search 02-14-2023
0 1
0
1
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...