Splunk Search

Splunk Search
Community Activity
Cyberguru
Query doesnt bring up anything. Try to pull RDP connections in my environment:      event_simpleName=UserLogon LogonT...
by Cyberguru Engager in Splunk Search 01-26-2023
0 2
0
2
fariapm1
Hi, I have a csv that is imported to splunk and one of those fields has a space for the thousands and ends with  ",00...
by fariapm1 Explorer in Splunk Search 01-26-2023
0 6
0
6
ze271021
Hello,  I need a search query to detect http outboun irect traffic. Thank  you.
by ze271021 Loves-to-Learn Everything in Splunk Search 01-26-2023
0 1
0
1
neerajs_81
Hi All,  When using stats  to display values() of  fields , how can we have the values to align between the field nam...
by neerajs_81 Builder in Splunk Search 01-26-2023
0 3
0
3
halu
Hello Splunker!   Sometimes my searches on Splunk Enterprise Security Search Head ran into following error (mostly) w...
by halu Loves-to-Learn Lots in Splunk Search 01-26-2023
0 7
0
7
daveywfii
I have a list of chrome extensions that are installed that is returned in a multivalue field. One of the results look...
by daveywfii Explorer in Splunk Search 01-25-2023
0 2
0
2
anissabnk
Hello everyone,  I have a question for you, and I need your help please  I have some logs, but the parsing isn't don...
by anissabnk Path Finder in Splunk Search 01-25-2023
0 1
0
1
Jamie
Hello,My events contain strings such as:notification that user "mydomain\bob" hasnotification that user "fred" has no...
by Jamie Path Finder in Splunk Search 01-25-2023
0 7
0
7
Khuzair81
Please help with the query on how to compare CSV data with Splunk event and get those data in result which is not ava...
by Khuzair81 Path Finder in Splunk Search 01-25-2023
0 4
0
4
vinothkumark
< query > ... | stats count by return_code fetches me the below output.I have to create an alert where the sum of any...
by vinothkumark Path Finder in Splunk Search 01-24-2023
0 5
0
5
hank72
Hi community. Some searches have:index="my_index"index=my_indexI want to extract a new field named user_index but can...
by hank72 Path Finder in Splunk Search 01-24-2023
0 1
0
1
svm157
Hi, I am very new to splunk and need help for the below situation. I am having two columns as below Row        Column...
by svm157 Loves-to-Learn Lots in Splunk Search 01-24-2023
0 5
0
5
sjaitly
I'm trying to create a dashboard to find the old version and new version of splunk from the logs but unable to find i...
by sjaitly Engager in Splunk Search 01-24-2023
0 2
0
2
Virpee
We have a use case where we need to have an alert emailed if a user (under the field User) does not have an event of ...
by Virpee Engager in Splunk Search 01-24-2023
0 2
0
2
power12
Hello SplunkersI have the following raw events 2023-01-20 18:45:59.000, mod_time="1674240490", job_id="79" , time_sub...
by power12 Communicator in Splunk Search 01-24-2023
0 8
0
8
harryhcg
Can someone help with query?I have 2 index abc and bczFrom abc index I want to show stats for field1where field2 from...
by harryhcg Explorer in Splunk Search 01-24-2023
0 2
0
2
mikefoti
Given web access log data with following fields: _time,  http_status, src_ip, dest_ip After a bruteforce attack on a ...
by mikefoti Communicator in Splunk Search 01-24-2023
0 1
0
1
user33
Hello, apologies if this was stated previously. I have multiple calls - each RequestID with a RequestReceive and Resp...
by user33 Path Finder in Splunk Search 01-24-2023
0 5
0
5
bam22
In the below search I am looking for rules hit by count, but how or where would I add a NOT or !, if I wanted to know...
by bam22 Engager in Splunk Search 01-24-2023
0 1
0
1
rprior
I have six eventtype's that each check Juniper router logs for an Interface bounce (an up/down event). These are work...
by rprior Explorer in Splunk Search 01-24-2023
0 3
0
3
munang
I'm trying to get data by registering it as a Splunk script using Python code. But the problem only occurs when I run...
by munang Path Finder in Splunk Search 01-24-2023
0 2
0
2
ipteam
Hello Guys, I'd like to create a search based on business hours, and like to use a field with value like this: "2023/...
by ipteam Engager in Splunk Search 01-23-2023
0 5
0
5
anrak33
My data looks like the following  student_idbrowser_idguiddatetimex_id12_aChrome_211221/9/23 14:45788a13_aChrome_4121...
by anrak33 Explorer in Splunk Search 01-23-2023
0 7
0
7
spl_1991
Given the below scenario: base search| table service_name,status,count Service_name Status Count serviceA 500_IN...
by spl_1991 Engager in Splunk Search 01-23-2023
0 2
0
2
villnooB
Is it possible to assign a value to a different fields. I am trying to combine two different events but the same inde...
by villnooB Explorer in Splunk Search 01-23-2023
0 4
0
4
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...
Top Solution Authors