Splunk Search

Splunk Search
Community Activity
Derson
When I use walklex on my indexes, it doesn't appear to be following the time specifications very well. Does anybody k...
by Derson Explorer in Splunk Search 01-29-2023
0 0
0
0
andyfromoz
We have a particular file of the format: Field1, Field2, Timestamp field, Field4, Field5, Number of records, Field7 ...
by andyfromoz Explorer in Splunk Search 01-28-2023
1 4
1
4
Vani_26
Hi allwhen i run my original query i am getting one result and when i execute the same query using tstats i am gettin...
by Vani_26 Path Finder in Splunk Search 01-28-2023
0 3
0
3
axelmunoz
Hey all! I have a saved search that runs on a schedule and generates those "artifacts", I know I can access a specifi...
by axelmunoz New Member in Splunk Search 01-28-2023
0 3
0
3
mohdmikhael
Hi,I recently came across this warning on Splunk web and was just wondering if anyone else has encountered this befor...
by mohdmikhael Explorer in Splunk Search 01-27-2023
0 3
0
3
batham
Hi, My Strptime function is not working for the below format. date format: 1/13/23 11:44:11.543 AM eval  time_epoc= s...
by batham Explorer in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
Currently I have an inputlookup csv that contains a list of IP addresses and lookup csv that has a list of subnets. I...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
I'm doing a search for server names and will eventually extract to to a csv. However, each result comes out as one of...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 4
0
4
pjanssen007
I'm trying to filter out events like the ones below using the regex expression regex _raw!="^[A-Za-z0-9]{4}:.*$"   bu...
by pjanssen007 Explorer in Splunk Search 01-27-2023
0 6
0
6
qcjacobo2577
Currently running Splunk Universal Forwarder version 9.0.3. Looking to ignore Windows event logs (EventCode = 4103) u...
by qcjacobo2577 Path Finder in Splunk Search 01-27-2023
0 14
0
14
finchy
Hi Is there a way to search across multiple Lookup files to find text within them ?  I know that you can use | inputl...
by finchy Explorer in Splunk Search 01-27-2023
0 4
0
4
bapun18
I want to disable the feature of save as, user can able to search but shouldn't be able to save it as a dashboard or ...
by bapun18 Communicator in Splunk Search 01-27-2023
0 2
0
2
jip12048
Hi all, I am new to Spluntk and have problem with my search. I have a Lookup table: Error.csv Filter*Error1**Error2**...
by jip12048 Engager in Splunk Search 01-27-2023
0 1
0
1
kalaiyarasi
|eval TotalApps=if(match('Total',"NTB"),"1","0") |eval In-Progress=if('Total'="NTB" AND isnull('APPL_SUB-DATE'),"1","...
by kalaiyarasi Loves-to-Learn Lots in Splunk Search 01-27-2023
0 5
0
5
amitrinx
I have 2 events having fields1. id_cse_event: sqsmessageid,timestamp2. Scim: sqs_message_id, timestamp.I want to sear...
by amitrinx Explorer in Splunk Search 01-27-2023
0 3
0
3
sdhiaeddine
Hi,Please could you help with parsing this json data to table       { "list_element": [ { "element": "{\"var1\"...
by sdhiaeddine Explorer in Splunk Search 01-26-2023
0 5
0
5
Macky_29
Dear experts , I am searching on my bot index, which contain conve-id and rest of the fields are stored as payload. U...
by Macky_29 Explorer in Splunk Search 01-26-2023
0 5
0
5
prasant
I have sample.csv file with about 30000 rows with columns: sample data data  value1   value25600012345   abc xxx7890...
by prasant Path Finder in Splunk Search 01-26-2023
0 5
0
5
michaeler
I feel like I'm dancing circles around the solution to this problem. I created a field named "Duration" with rex that...
by michaeler Communicator in Splunk Search 01-26-2023
0 1
0
1
Skeer-Jamf
So after searching here it seems like a lot of people have trouble parsing/handling WinEventLogs. I want to ask if th...
by Skeer-Jamf Path Finder in Splunk Search 01-26-2023
0 6
0
6
cdieringerwm
Greetings. My Splunk instance parses messages which has a JSON array type: ```{ tags: ["info", "foo", "bar"] }```Let'...
by cdieringerwm Observer in Splunk Search 01-26-2023
0 1
0
1
security_mike
Hi All, I'm pretty new to Splunk so forgive me if this is an easy question. I'm trying to figure out how to a) search...
by security_mike Explorer in Splunk Search 01-26-2023
0 4
0
4
jason_hotchkiss
I have a horizontal bar chart usingthe following post processing search:| stats count by urgency| eval urgency = if(u...
by jason_hotchkiss Communicator in Splunk Search 01-26-2023
0 3
0
3
michaeler
I am trying to determine the average time for a set of issues to get resolved. I already created a field named "Durat...
by michaeler Communicator in Splunk Search 01-26-2023
0 3
0
3
Cyberguru
Query doesnt bring up anything. Try to pull RDP connections in my environment:      event_simpleName=UserLogon LogonT...
by Cyberguru Engager in Splunk Search 01-26-2023
0 2
0
2
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors