Splunk Search

Splunk Search
Community Activity
TBH0
Hey all, I'm attempting to compare a variable (we'll call it cDOW), which is set to (strftime(now(), "%A")),  to a DO...
by TBH0 Explorer in Splunk Search 01-11-2023
0 5
0
5
pm771
HelloI have a Splunk query that looks like following: index=something "*abc*" OR "*def*" OR "*hig*"  These substrings...
by pm771 Communicator in Splunk Search 01-11-2023
0 2
0
2
dionrivera
Some of my events are displaying UTC time while others display PST time, as they should since I have my preferences s...
by dionrivera Communicator in Splunk Search 01-11-2023
0 3
0
3
mv10
I have read the documentation about breaker characters, but within our organization there is disagreement about when ...
by mv10 Path Finder in Splunk Search 01-11-2023
0 3
0
3
yuanliu
I have two different sources with different fields.  Let's call them sourcetypeA and sourcetypeB.  Some fields that I...
by SplunkTrust SplunkTrust in Splunk Search 01-11-2023
0 1
0
1
Evgenii
The event has a field:  { ... some_field: { key1: value1 key2: value2 } ... }  How to iterate over the values of "s...
by Evgenii Engager in Splunk Search 01-11-2023
0 3
0
3
sabari80
This is my sample eventonlinequoteinguser 2023-01-11T10:27:13,843 INFO DigitalPortal.xxxeSubmissionUtil{"hostName": "...
by sabari80 Explorer in Splunk Search 01-11-2023
0 2
0
2
kumar497
Hi All,  I am trying to tabulate the error ratio based on the following scenarios from the unique log event but furth...
by kumar497 Path Finder in Splunk Search 01-11-2023
0 13
0
13
Splunkadmin1876
Hi All, I have a search with a subsearch that references a lookup file test.csv with a single field. "Account_Name". ...
by Splunkadmin1876 Engager in Splunk Search 01-11-2023
0 2
0
2
TalNiv
Hi, suppose I have a multi-value field which represents names, which can have different values in each event. for exa...
by TalNiv New Member in Splunk Search 01-11-2023
0 3
0
3
jwalzerpitt
I have a JSON file I am trying to search for a specific value - EventType=GoodMail - and then pull the values from an...
by jwalzerpitt Influencer in Splunk Search 01-11-2023
0 10
0
10
sasank
Hi, I have below splunk command: | makeresults | eval _raw="The first value is 0.00 and The second value is 0\",\"ori...
by sasank Explorer in Splunk Search 01-11-2023
0 3
0
3
zen1tsu
Good morning\afternoon\evening community! I've met an issue with detecting vpn tunnel interface statuses which is ide...
by zen1tsu Loves-to-Learn Lots in Splunk Search 01-11-2023
0 3
0
3
wjz
Hi, I'd like to count the number of responses by the following status codes: 2xx, 4xx and 5xx. I'm basically countin...
by wjz New Member in Splunk Search 01-11-2023
0 3
0
3
amitrinx
I have two lookupsRLQuotas: Endpoint, Endpoint Name, filter, quota, WindowRLFilters: Attribute, filterI want to loop ...
by amitrinx Explorer in Splunk Search 01-10-2023
0 1
0
1
sjs
My data looks something like this The status can be either SUCCESS or FAILED, I want to count the total number of ev...
by sjs Path Finder in Splunk Search 01-10-2023
0 2
0
2
sharsmail
I'm trying to implement a search query in splunk to get anomalous values around a particular field in the service eve...
by sharsmail Engager in Splunk Search 01-10-2023
0 3
0
3
nikhil29
could someone please let me know where I'm going wrong in my query ?| spath service_roles{} output=service_role| stat...
by nikhil29 Loves-to-Learn Everything in Splunk Search 01-10-2023
0 2
0
2
Rapidz
I am setting up an alert to notify when a message is received more than a 100 times in a week. I figured it out for t...
by Rapidz Explorer in Splunk Search 01-10-2023
0 5
0
5
Vivekmishra01
I am trying to find few strings in my search query and count occurrences of them and I want to put them in a two colu...
by Vivekmishra01 Explorer in Splunk Search 01-10-2023
0 2
0
2
Ker_splunk
Hi Splunk Community,   I wondered if there was any way to match a keyword against a string in a lookup.  For example:...
by Ker_splunk Engager in Splunk Search 01-10-2023
0 2
0
2
evallja
Hello everyone, I have the following results when running my search: _time                                        use...
by evallja Path Finder in Splunk Search 01-10-2023
0 1
0
1
anjuliwyles
When I place event.code into an if statement, it will not evaluate as true   Currently I have this code: index = wind...
by anjuliwyles Engager in Splunk Search 01-10-2023
0 2
0
2
neilmac64
My current project polls a device every 15 minutes to pull a counter which is then charted. Thanks to members here, I...
by neilmac64 Path Finder in Splunk Search 01-10-2023
0 16
0
16
kpavan
Hi All, Greetings! Need help on splunk query, I have 2 indexes assets and vulns, am trying to build report to analyze...
by kpavan Path Finder in Splunk Search 01-10-2023
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors