Splunk Search

Splunk Search
Community Activity
harryhcg
I have 2 index, abc and bcz index abc data is in raw format like below. <random ip address>|-NA\CAPITA|5xxhxh545|jljd...
by harryhcg Explorer in Splunk Search 02-02-2023
0 5
0
5
Neel88
Hello,I am using 2 multi select dropdown. When its on  the default value  'ALL' then it doesn't show any value in the...
by Neel88 Explorer in Splunk Search 02-02-2023
0 1
0
1
interrobang
 (index="external*" Feedback* "Text") | transaction channel startswith=POST endswith=received maxspan=1m maxevents=2 ...
by interrobang Explorer in Splunk Search 02-02-2023
0 3
0
3
cool_pbenjamin
I have a search along these lines     "duration: " | rex field=host "(?P<host_type>[my_magic_regex])" | rex "duration...
by cool_pbenjamin New Member in Splunk Search 02-02-2023
0 1
0
1
jamesjung01
| inputlookup suspicious_win_comm.csv lookup table contents has only keyword keyword <- field name tasklist ver i...
by jamesjung01 Explorer in Splunk Search 02-02-2023
0 2
0
2
power12
Hello SplunkersI am pretty new to splunk admin .I have the following config set up in indexes.conf where I set up one...
by power12 Communicator in Splunk Search 02-02-2023
0 8
0
8
poojithavasanth
Hello, I wanted a EVAL statement which manually adds a specified time may be "00:00:00" for the event containing only...
by poojithavasanth Explorer in Splunk Search 02-02-2023
0 2
0
2
tfujita_splunk
Numeral system macros for SplunkExamples of Single Value panel and Table.Hello,Just an announcement.I have created ma...
by tfujita_splunk Splunk Employee Splunk Employee in Splunk Search 02-02-2023
3 0
3
0
Neel88
I am working on the saved search not index/lookup.I tried this code - | eval date=strftime(strptime(<fieldname>,"%Y-%...
by Neel88 Explorer in Splunk Search 02-02-2023
0 5
0
5
naveenalagu
Basically I have a set of raw data with different time stamp in CCYYMMDDHHMMSS format. I want to list out the stats w...
by naveenalagu Explorer in Splunk Search 02-02-2023
0 6
0
6
erikschubert
Hello everyone,I have a search in the following format:(index="index1" group=a) OR (index="index2" group=a)....Later ...
by erikschubert Engager in Splunk Search 02-02-2023
0 1
0
1
syamaguchi3
Hi I'm implementing some searches provided by Splunk Threat Research Team to detect threats from AD logs. But I canno...
by syamaguchi3 Explorer in Splunk Search 02-02-2023
0 2
0
2
tomapatan
I have the following search which returns a table of all hostnames and operating systems. | inputlookup hosts.csv| se...
by tomapatan Contributor in Splunk Search 02-02-2023
0 4
0
4
AKBBB
Hi Guys, Less Event displayed while searching as * then search hostname while its showing if I search at the beginnin...
by AKBBB Explorer in Splunk Search 02-02-2023
0 11
0
11
arriel96
A have two tables anda i want to relation this two tables by nember of events in a hour, i  manage to make a SQL quer...
by arriel96 Explorer in Splunk Search 02-02-2023
0 4
0
4
super_edition
Hello Everyone, I have dashboard with token value as datacenter, which has 3 options from dropdown: Dublin ="*dbl_dc_...
by super_edition Path Finder in Splunk Search 02-02-2023
0 4
0
4
chongdong
Does anyone know why the time range picker here on the right side (set to Yesterday Jan 30) cannot affect my _time da...
by chongdong Explorer in Splunk Search 02-02-2023
0 3
0
3
NEHS
Hello Splunk's community, I got some difficulty for the fields extraction in crowdsec's logs which are format with JS...
by NEHS Loves-to-Learn in Splunk Search 02-01-2023
0 1
0
1
MSY
I've been working on a Dashboard/Query that takes two date/time values (UTC) from Zscaler ZPA logs and converts to lo...
by MSY Explorer in Splunk Search 02-01-2023
0 4
0
4
Vani_26
Query:|tstats count where index=afg-juhb-appl   host_ip=*     source=*     TERM(offer)i want to get the count of each...
by Vani_26 Path Finder in Splunk Search 02-01-2023
0 4
0
4
ilhwan
My boss asked me to generate a report of people connecting to our network from public VPN providers.  I'm using this ...
by ilhwan Path Finder in Splunk Search 02-01-2023
0 7
0
7
garrywilmeth
Hello, I am trying to get regex to work in ingest actions to match a list of event codes from Window Security Logs.  ...
by garrywilmeth Explorer in Splunk Search 02-01-2023
0 4
0
4
majeedk_nbg
I have a dashboard showing website user journey data by reading various elements from a  log message.  Now the struct...
by majeedk_nbg Engager in Splunk Search 02-01-2023
0 3
0
3
dmoberg
I am struggling to figure out how to get the Visualization that I want, if even possible.... Timechart works great fo...
by dmoberg Path Finder in Splunk Search 02-01-2023
0 2
0
2
brettgladys
I have two fields, application and servletName. I'd like to have them as column names in a chart. I'm currently try...
by brettgladys Explorer in Splunk Search 02-01-2023
9 8
9
8
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors