Splunk Search

Splunk Search
Community Activity
Shakira1
I have all_ip filed that contains all my ips.now I want to split it to public ip and private ip:public_ip, private_ip...
by Shakira1 Explorer in Splunk Search 12-28-2022
0 2
0
2
villnooB
Hi guys, Can you please help me , I am trying to create a query in which it shows if a user is in  a different locati...
by villnooB Explorer in Splunk Search 12-28-2022
0 5
0
5
bosseres
Hello everyone,  I got several fields in search result (name, ip_src). Now I have lookup with 2 columns: namesubnetna...
by bosseres Contributor in Splunk Search 12-28-2022
0 2
0
2
boxmetal
Hi Splunk community, I have a lookup containing a list of allowed departments as the following vendorallowed_departme...
by boxmetal Path Finder in Splunk Search 12-27-2022
0 3
0
3
chetanN
Hi all, I am very new to Splunk and trying to learn it. Following is my JSON: {<!-- -->        TrainID&#61;AA11          TrainDat...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 2
0
2
chetanN
Hi all, I am trying to run a basic search where I am trying to print table based on where and like() condition. But i...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 5
0
5
yadavameeth
How to update a lookup file in splunk from Phantom?
by yadavameeth Engager in Splunk Search 12-27-2022
1 5
1
5
chetanN
Hi all, To give a problem background, I am trying to run a map command inside a search to get some values. THE JSON I...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 1
0
1
sekhar463
Good day,   how to group results of a same filed value into one fileld value from below table i have a field box-name...
by sekhar463 Path Finder in Splunk Search 12-27-2022
0 4
0
4
Aj01
i have been using this query but couldn't be able to remove null rows, please help me index&#61;Window_wash | rex field&#61;...
by Aj01 Path Finder in Splunk Search 12-26-2022
0 4
0
4
sasank
Hi,I need the JSON array in Splunk &#96;List&#96; view to be expanded by default instead of showing the Plus icon.I have a Sp...
by sasank Explorer in Splunk Search 12-25-2022
0 3
0
3
Dantuzzo
Hi,i'm struggling in calculating hourly or daily average and displaying the results if there's no events at all, whic...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-25-2022
0 2
0
2
sasank
Hi,I have a Splunk event "Application -&gt; start of the log".When I try to search for this log using the exact text the...
by sasank Explorer in Splunk Search 12-25-2022
0 2
0
2
informatika
Hello, new to using splunk across a domain and I am attempting to get a query that details any domain user account ch...
by informatika Loves-to-Learn in Splunk Search 12-24-2022
0 3
0
3
avadhutha
I have a requirement to pull 90% of max execution time. Ex: I have 10 requests for an hour and it's execution times a...
by avadhutha Explorer in Splunk Search 12-24-2022
0 1
0
1
st1
We currently have an report every morning that shows which users have been removed from a particular AD group from th...
by st1 Path Finder in Splunk Search 12-24-2022
0 3
0
3
zoebanning
Hi Splunk Community,I was wondering if it was possible to have a chart that was made up from 3 fields.... I have alre...
by zoebanning Path Finder in Splunk Search 12-24-2022
0 2
0
2
Dantuzzo
Hi,i'm trying to calculate the average events weekly by their severity and comparing the daily amount with the weekly...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-23-2022
0 1
0
1
user33
Hello, I am trying to extract the below 201 text highlighted in red below as one separate field from two separate eve...
by user33 Path Finder in Splunk Search 12-23-2022
0 4
0
4
sasank
After I perform a search and click the "Format" Icon above the search results, there is an option for "Wrap Results"....
by sasank Explorer in Splunk Search 12-23-2022
1 0
1
0
Anu189
Search query for including non-business hours and weekends ie exclude Monday to Friday 9am to 5pm 
by Anu189 New Member in Splunk Search 12-23-2022
0 1
0
1
abazgwa21cz
I want to set a Schedule for my search to find the data sent by user in our system . This is my search to catch each ...
by abazgwa21cz Explorer in Splunk Search 12-23-2022
0 3
0
3
avadhutha
mainsearch| stats count(_raw)  as Cou by hour|join hour [ subsearch| head -$Cou$ ]   Above mentioned command is not w...
by avadhutha Explorer in Splunk Search 12-23-2022
0 2
0
2
svarendorff
Having some issue with extraction.source:SESSION: Session closedClient address: 123.CCCCCCCClient name: CC222C22[123....
by svarendorff Explorer in Splunk Search 12-22-2022
0 5
0
5
bt149
I have a field called properties.requestbody.  I would like to have this field broken out based on the field and valu...
by bt149 Path Finder in Splunk Search 12-22-2022
0 9
0
9
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...