Splunk Search

Splunk Search
Community Activity
NEHS
Hello Splunk's community, I got some difficulty for the fields extraction in crowdsec's logs which are format with JS...
by NEHS Loves-to-Learn in Splunk Search 02-01-2023
0 1
0
1
MSY
I've been working on a Dashboard/Query that takes two date/time values (UTC) from Zscaler ZPA logs and converts to lo...
by MSY Explorer in Splunk Search 02-01-2023
0 4
0
4
Vani_26
Query:|tstats count where index=afg-juhb-appl   host_ip=*     source=*     TERM(offer)i want to get the count of each...
by Vani_26 Path Finder in Splunk Search 02-01-2023
0 4
0
4
ilhwan
My boss asked me to generate a report of people connecting to our network from public VPN providers.  I'm using this ...
by ilhwan Path Finder in Splunk Search 02-01-2023
0 7
0
7
garrywilmeth
Hello, I am trying to get regex to work in ingest actions to match a list of event codes from Window Security Logs.  ...
by garrywilmeth Explorer in Splunk Search 02-01-2023
0 4
0
4
majeedk_nbg
I have a dashboard showing website user journey data by reading various elements from a  log message.  Now the struct...
by majeedk_nbg Engager in Splunk Search 02-01-2023
0 3
0
3
dmoberg
I am struggling to figure out how to get the Visualization that I want, if even possible.... Timechart works great fo...
by dmoberg Path Finder in Splunk Search 02-01-2023
0 2
0
2
brettgladys
I have two fields, application and servletName. I'd like to have them as column names in a chart. I'm currently try...
by brettgladys Explorer in Splunk Search 02-01-2023
9 8
9
8
dieguiariel
Hi! im trying to detect multiple user access from the same source (same mobile device). Im feeding splunk with logs f...
by dieguiariel Path Finder in Splunk Search 02-01-2023
0 4
0
4
Renunaren
Above is the title of my dashboard, need to add the present date along with the title   For the above one we need to...
by Renunaren Loves-to-Learn Everything in Splunk Search 02-01-2023
0 0
0
0
Austin_James
Hi I have a field(event_details) that contains a JSON array.Record 1:{<!-- -->"event_details":[{"product_id":"P002","price":1...
by Austin_James Engager in Splunk Search 02-01-2023
0 6
0
6
mohdmikhael
Hi, My client has encountered the following issue below and I was just wondering if anyone has encountered something ...
by mohdmikhael Explorer in Splunk Search 01-31-2023
0 7
0
7
jpsheridan
I have 5 separate endpoints for our Okta environment that I'm pulling into Splunk. The data is all event driven so if...
by jpsheridan Engager in Splunk Search 01-31-2023
0 1
0
1
mistydennis
Hi all - I'm attempting to write a query using earliest/latest based off a date field in the event, not _time. I've t...
by mistydennis Communicator in Splunk Search 01-31-2023
0 1
0
1
michaeler
I feel like there's a simple solution to this that I just can't remember. I have a field named Domain that has 13 val...
by michaeler Communicator in Splunk Search 01-31-2023
0 2
0
2
satyaallaparthi
How can I combine multiple fields results in to single column with common name for example Test1, Test2, Test3 and so...
by satyaallaparthi Communicator in Splunk Search 01-31-2023
0 1
0
1
briancronrath
I have a datasource that passes the time as a string like the following: "2018-08-07T17:38:16.352" This string is ...
by briancronrath Contributor in Splunk Search 01-31-2023
0 9
0
9
rohitmaheshwari
I have a search that gives me a column with hostnames host A B C I am trying to use the network toolkit application...
by rohitmaheshwari Explorer in Splunk Search 01-31-2023
0 3
0
3
NizanCohen
Hi guys. I'm currently working to fix all "real-time" jobs running on my company and I came across one job that I can...
by NizanCohen Explorer in Splunk Search 01-31-2023
0 2
0
2
ewanbrown967
Hello I've been looking at the new _configtracker index and I would like to know how I could get the User details ass...
by ewanbrown967 Engager in Splunk Search 01-31-2023
0 3
0
3
bosseres
Hello everyone, I have next one task: I want to collect (with collect command) information which I got after stats. P...
by bosseres Contributor in Splunk Search 01-31-2023
0 1
0
1
Renunaren
I have a message in my events like below "Main function executed successfully." I need to change status of the above ...
by Renunaren Loves-to-Learn Everything in Splunk Search 01-31-2023
0 2
0
2
akankshayadav
When I am click on my data summary, it is not displaying anything just showing Any suggestions?Thanks.
by akankshayadav Path Finder in Splunk Search 01-30-2023
0 4
0
4
erikschubert
Hi everyone, I'm kinda new to splunk. I have two indizes: Stores events (relevant fields: hostname, destPort)    ...
by erikschubert Engager in Splunk Search 01-30-2023
0 3
0
3
batham
Hi, I am using inner join to form a table between 2 search, search is working fine but i want to subtract 2 fields in...
by batham Explorer in Splunk Search 01-30-2023
0 2
0
2
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...