Splunk Search

Splunk Search
Community Activity
Krishna_Sridhar
I have a URL field and need to find the last word (split by "/") Ex: URL 1: xxx/yyy/ServiceNameURL 2 : aaa/bbb/ccc/dd...
by Krishna_Sridhar New Member in Splunk Search 01-30-2023
0 4
0
4
neerajs_81
Hi All, I have a very simple use case and that is to display the time difference between 2 fields that already have t...
by neerajs_81 Builder in Splunk Search 01-30-2023
0 5
0
5
riposan
please help,i used _time from date log, and i using time from windowstime, but i tried substraction bot of them not r...
by riposan Explorer in Splunk Search 01-30-2023
0 3
0
3
mailwimp
The sender and recipient information  I need from Unix/Linux "sendmail" logs is contained in separate lines in the se...
by mailwimp Engager in Splunk Search 01-29-2023
0 4
0
4
kiran331
Hi, How to use regex to send all events related to fw_rule=0 and from a sensor sensor=abcd-f01 to null queue? samp...
by kiran331 Builder in Splunk Search 01-29-2023
0 10
0
10
neelpatel02
I was trying to send data through Splunk HEC (Http event Collector).curl http://ip:8088/services/collector -H "Author...
by neelpatel02 New Member in Splunk Search 01-29-2023
0 1
0
1
Harish2
Hi My sources:1.  /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC.log2.  /app/splunkser/ShiftNonMinJMC/ShiftNonMinJMC-sh...
by Harish2 Path Finder in Splunk Search 01-29-2023
0 5
0
5
phularah
Hi, I would like to add value in two fields based on their name.  I want the output as sum of traffic_in#fw1+traffic_...
by phularah Communicator in Splunk Search 01-29-2023
0 5
0
5
Derson
When I use walklex on my indexes, it doesn't appear to be following the time specifications very well. Does anybody k...
by Derson Explorer in Splunk Search 01-29-2023
0 0
0
0
andyfromoz
We have a particular file of the format: Field1, Field2, Timestamp field, Field4, Field5, Number of records, Field7 ...
by andyfromoz Explorer in Splunk Search 01-28-2023
1 4
1
4
Vani_26
Hi allwhen i run my original query i am getting one result and when i execute the same query using tstats i am gettin...
by Vani_26 Path Finder in Splunk Search 01-28-2023
0 3
0
3
axelmunoz
Hey all! I have a saved search that runs on a schedule and generates those "artifacts", I know I can access a specifi...
by axelmunoz New Member in Splunk Search 01-28-2023
0 3
0
3
mohdmikhael
Hi,I recently came across this warning on Splunk web and was just wondering if anyone else has encountered this befor...
by mohdmikhael Explorer in Splunk Search 01-27-2023
0 3
0
3
batham
Hi, My Strptime function is not working for the below format. date format: 1/13/23 11:44:11.543 AM eval  time_epoc= s...
by batham Explorer in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
Currently I have an inputlookup csv that contains a list of IP addresses and lookup csv that has a list of subnets. I...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 1
0
1
atebysandwich
I'm doing a search for server names and will eventually extract to to a csv. However, each result comes out as one of...
by atebysandwich Path Finder in Splunk Search 01-27-2023
0 4
0
4
pjanssen007
I'm trying to filter out events like the ones below using the regex expression regex _raw!="^[A-Za-z0-9]{4}:.*$"   bu...
by pjanssen007 Explorer in Splunk Search 01-27-2023
0 6
0
6
qcjacobo2577
Currently running Splunk Universal Forwarder version 9.0.3. Looking to ignore Windows event logs (EventCode = 4103) u...
by qcjacobo2577 Path Finder in Splunk Search 01-27-2023
0 14
0
14
finchy
Hi Is there a way to search across multiple Lookup files to find text within them ?  I know that you can use | inputl...
by finchy Explorer in Splunk Search 01-27-2023
0 4
0
4
bapun18
I want to disable the feature of save as, user can able to search but shouldn't be able to save it as a dashboard or ...
by bapun18 Communicator in Splunk Search 01-27-2023
0 2
0
2
jip12048
Hi all, I am new to Spluntk and have problem with my search. I have a Lookup table: Error.csv Filter*Error1**Error2**...
by jip12048 Engager in Splunk Search 01-27-2023
0 1
0
1
kalaiyarasi
|eval TotalApps=if(match('Total',"NTB"),"1","0") |eval In-Progress=if('Total'="NTB" AND isnull('APPL_SUB-DATE'),"1","...
by kalaiyarasi Loves-to-Learn Lots in Splunk Search 01-27-2023
0 5
0
5
amitrinx
I have 2 events having fields1. id_cse_event: sqsmessageid,timestamp2. Scim: sqs_message_id, timestamp.I want to sear...
by amitrinx Explorer in Splunk Search 01-27-2023
0 3
0
3
sdhiaeddine
Hi,Please could you help with parsing this json data to table       { "list_element": [ { "element": "{\"var1\"...
by sdhiaeddine Explorer in Splunk Search 01-26-2023
0 5
0
5
Macky_29
Dear experts , I am searching on my bot index, which contain conve-id and rest of the fields are stored as payload. U...
by Macky_29 Explorer in Splunk Search 01-26-2023
0 5
0
5
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors