Splunk Search

Splunk Search
Community Activity
cool_pbenjamin
I have a search along these lines     "duration: " | rex field=host "(?P<host_type>[my_magic_regex])" | rex "duration...
by cool_pbenjamin New Member in Splunk Search 02-02-2023
0 1
0
1
jamesjung01
| inputlookup suspicious_win_comm.csv lookup table contents has only keyword keyword <- field name tasklist ver i...
by jamesjung01 Explorer in Splunk Search 02-02-2023
0 2
0
2
power12
Hello SplunkersI am pretty new to splunk admin .I have the following config set up in indexes.conf where I set up one...
by power12 Communicator in Splunk Search 02-02-2023
0 8
0
8
poojithavasanth
Hello, I wanted a EVAL statement which manually adds a specified time may be "00:00:00" for the event containing only...
by poojithavasanth Explorer in Splunk Search 02-02-2023
0 2
0
2
tfujita_splunk
Numeral system macros for SplunkExamples of Single Value panel and Table.Hello,Just an announcement.I have created ma...
by tfujita_splunk Splunk Employee Splunk Employee in Splunk Search 02-02-2023
3 0
3
0
Neel88
I am working on the saved search not index/lookup.I tried this code - | eval date=strftime(strptime(<fieldname>,"%Y-%...
by Neel88 Explorer in Splunk Search 02-02-2023
0 5
0
5
naveenalagu
Basically I have a set of raw data with different time stamp in CCYYMMDDHHMMSS format. I want to list out the stats w...
by naveenalagu Explorer in Splunk Search 02-02-2023
0 6
0
6
erikschubert
Hello everyone,I have a search in the following format:(index="index1" group=a) OR (index="index2" group=a)....Later ...
by erikschubert Engager in Splunk Search 02-02-2023
0 1
0
1
syamaguchi3
Hi I'm implementing some searches provided by Splunk Threat Research Team to detect threats from AD logs. But I canno...
by syamaguchi3 Explorer in Splunk Search 02-02-2023
0 2
0
2
tomapatan
I have the following search which returns a table of all hostnames and operating systems. | inputlookup hosts.csv| se...
by tomapatan Contributor in Splunk Search 02-02-2023
0 4
0
4
AKBBB
Hi Guys, Less Event displayed while searching as * then search hostname while its showing if I search at the beginnin...
by AKBBB Explorer in Splunk Search 02-02-2023
0 11
0
11
arriel96
A have two tables anda i want to relation this two tables by nember of events in a hour, i  manage to make a SQL quer...
by arriel96 Explorer in Splunk Search 02-02-2023
0 4
0
4
super_edition
Hello Everyone, I have dashboard with token value as datacenter, which has 3 options from dropdown: Dublin ="*dbl_dc_...
by super_edition Path Finder in Splunk Search 02-02-2023
0 4
0
4
chongdong
Does anyone know why the time range picker here on the right side (set to Yesterday Jan 30) cannot affect my _time da...
by chongdong Explorer in Splunk Search 02-02-2023
0 3
0
3
NEHS
Hello Splunk's community, I got some difficulty for the fields extraction in crowdsec's logs which are format with JS...
by NEHS Loves-to-Learn in Splunk Search 02-01-2023
0 1
0
1
MSY
I've been working on a Dashboard/Query that takes two date/time values (UTC) from Zscaler ZPA logs and converts to lo...
by MSY Explorer in Splunk Search 02-01-2023
0 4
0
4
Vani_26
Query:|tstats count where index=afg-juhb-appl   host_ip=*     source=*     TERM(offer)i want to get the count of each...
by Vani_26 Path Finder in Splunk Search 02-01-2023
0 4
0
4
ilhwan
My boss asked me to generate a report of people connecting to our network from public VPN providers.  I'm using this ...
by ilhwan Path Finder in Splunk Search 02-01-2023
0 7
0
7
garrywilmeth
Hello, I am trying to get regex to work in ingest actions to match a list of event codes from Window Security Logs.  ...
by garrywilmeth Explorer in Splunk Search 02-01-2023
0 4
0
4
majeedk_nbg
I have a dashboard showing website user journey data by reading various elements from a  log message.  Now the struct...
by majeedk_nbg Engager in Splunk Search 02-01-2023
0 3
0
3
dmoberg
I am struggling to figure out how to get the Visualization that I want, if even possible.... Timechart works great fo...
by dmoberg Path Finder in Splunk Search 02-01-2023
0 2
0
2
brettgladys
I have two fields, application and servletName. I'd like to have them as column names in a chart. I'm currently try...
by brettgladys Explorer in Splunk Search 02-01-2023
9 8
9
8
dieguiariel
Hi! im trying to detect multiple user access from the same source (same mobile device). Im feeding splunk with logs f...
by dieguiariel Path Finder in Splunk Search 02-01-2023
0 4
0
4
Renunaren
Above is the title of my dashboard, need to add the present date along with the title   For the above one we need to...
by Renunaren Loves-to-Learn Everything in Splunk Search 02-01-2023
0 0
0
0
Austin_James
Hi I have a field(event_details) that contains a JSON array.Record 1:{<!-- -->"event_details":[{"product_id":"P002","price":1...
by Austin_James Engager in Splunk Search 02-01-2023
0 6
0
6
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...