Splunk Search

Splunk Search
Community Activity
brennson90
Hi, i'm currently working on a props.conf and have different values from _time and the timestamp in my logs. What did...
by brennson90 Path Finder in Splunk Search 02-02-2023
0 3
0
3
harryhcg
I have 2 index, abc and bcz index abc data is in raw format like below. <random ip address>|-NA\CAPITA|5xxhxh545|jljd...
by harryhcg Explorer in Splunk Search 02-02-2023
0 5
0
5
Neel88
Hello,I am using 2 multi select dropdown. When its on  the default value  'ALL' then it doesn't show any value in the...
by Neel88 Explorer in Splunk Search 02-02-2023
0 1
0
1
interrobang
 (index="external*" Feedback* "Text") | transaction channel startswith=POST endswith=received maxspan=1m maxevents=2 ...
by interrobang Explorer in Splunk Search 02-02-2023
0 3
0
3
cool_pbenjamin
I have a search along these lines     "duration: " | rex field=host "(?P<host_type>[my_magic_regex])" | rex "duration...
by cool_pbenjamin New Member in Splunk Search 02-02-2023
0 1
0
1
jamesjung01
| inputlookup suspicious_win_comm.csv lookup table contents has only keyword keyword <- field name tasklist ver i...
by jamesjung01 Explorer in Splunk Search 02-02-2023
0 2
0
2
power12
Hello SplunkersI am pretty new to splunk admin .I have the following config set up in indexes.conf where I set up one...
by power12 Communicator in Splunk Search 02-02-2023
0 8
0
8
poojithavasanth
Hello, I wanted a EVAL statement which manually adds a specified time may be "00:00:00" for the event containing only...
by poojithavasanth Explorer in Splunk Search 02-02-2023
0 2
0
2
tfujita_splunk
Numeral system macros for SplunkExamples of Single Value panel and Table.Hello,Just an announcement.I have created ma...
by tfujita_splunk Splunk Employee Splunk Employee in Splunk Search 02-02-2023
3 0
3
0
Neel88
I am working on the saved search not index/lookup.I tried this code - | eval date=strftime(strptime(<fieldname>,"%Y-%...
by Neel88 Explorer in Splunk Search 02-02-2023
0 5
0
5
naveenalagu
Basically I have a set of raw data with different time stamp in CCYYMMDDHHMMSS format. I want to list out the stats w...
by naveenalagu Explorer in Splunk Search 02-02-2023
0 6
0
6
erikschubert
Hello everyone,I have a search in the following format:(index="index1" group=a) OR (index="index2" group=a)....Later ...
by erikschubert Engager in Splunk Search 02-02-2023
0 1
0
1
syamaguchi3
Hi I'm implementing some searches provided by Splunk Threat Research Team to detect threats from AD logs. But I canno...
by syamaguchi3 Explorer in Splunk Search 02-02-2023
0 2
0
2
tomapatan
I have the following search which returns a table of all hostnames and operating systems. | inputlookup hosts.csv| se...
by tomapatan Contributor in Splunk Search 02-02-2023
0 4
0
4
AKBBB
Hi Guys, Less Event displayed while searching as * then search hostname while its showing if I search at the beginnin...
by AKBBB Explorer in Splunk Search 02-02-2023
0 11
0
11
arriel96
A have two tables anda i want to relation this two tables by nember of events in a hour, i  manage to make a SQL quer...
by arriel96 Explorer in Splunk Search 02-02-2023
0 4
0
4
super_edition
Hello Everyone, I have dashboard with token value as datacenter, which has 3 options from dropdown: Dublin ="*dbl_dc_...
by super_edition Path Finder in Splunk Search 02-02-2023
0 4
0
4
chongdong
Does anyone know why the time range picker here on the right side (set to Yesterday Jan 30) cannot affect my _time da...
by chongdong Explorer in Splunk Search 02-02-2023
0 3
0
3
NEHS
Hello Splunk's community, I got some difficulty for the fields extraction in crowdsec's logs which are format with JS...
by NEHS Loves-to-Learn in Splunk Search 02-01-2023
0 1
0
1
MSY
I've been working on a Dashboard/Query that takes two date/time values (UTC) from Zscaler ZPA logs and converts to lo...
by MSY Explorer in Splunk Search 02-01-2023
0 4
0
4
Vani_26
Query:|tstats count where index=afg-juhb-appl   host_ip=*     source=*     TERM(offer)i want to get the count of each...
by Vani_26 Path Finder in Splunk Search 02-01-2023
0 4
0
4
ilhwan
My boss asked me to generate a report of people connecting to our network from public VPN providers.  I'm using this ...
by ilhwan Path Finder in Splunk Search 02-01-2023
0 7
0
7
garrywilmeth
Hello, I am trying to get regex to work in ingest actions to match a list of event codes from Window Security Logs.  ...
by garrywilmeth Explorer in Splunk Search 02-01-2023
0 4
0
4
majeedk_nbg
I have a dashboard showing website user journey data by reading various elements from a  log message.  Now the struct...
by majeedk_nbg Engager in Splunk Search 02-01-2023
0 3
0
3
dmoberg
I am struggling to figure out how to get the Visualization that I want, if even possible.... Timechart works great fo...
by dmoberg Path Finder in Splunk Search 02-01-2023
0 2
0
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors