Splunk Search

Splunk Search
Community Activity
kpavan
Hi All, Greetings! Need help on splunk query, I have 2 indexes assets and vulns, am trying to build report to analyze...
by kpavan Path Finder in Splunk Search 01-10-2023
0 3
0
3
robertisimos
Currently we are ingesting a big amount of AWS VPC FlowLogs in to the Splunk and I am wondering if there is any usage...
by robertisimos Observer in Splunk Search 01-10-2023
0 2
0
2
finnpalm
Hello. I'm fairly new to Splunk and SPL so bear with me here. I have the following scenario: I have an existing looku...
by finnpalm Explorer in Splunk Search 01-10-2023
0 4
0
4
Erilope
Hello everyone, I have a search for after hour logins between 6pm and 6am. Right now I have event codes 4625 and 4624...
by Erilope Explorer in Splunk Search 01-10-2023
0 3
0
3
MrIncredible
In few logs I can see escape character is also printed. My rex is working fine when i am testing it on regex101.com b...
by MrIncredible Explorer in Splunk Search 01-10-2023
0 4
0
4
ramanan
Hi All, I need to collect "Thread Dump" and "Heap Dump" of the application into Splunk.  What are all the possibiliti...
by ramanan Engager in Splunk Search 01-10-2023
0 1
0
1
jmr44
I have Splunk UF 7.0.3 that I want to send logs from to Splunk Cloud.  However, the UF doesn't support httpout so I a...
by jmr44 Explorer in Splunk Search 01-09-2023
0 1
0
1
Jackiifilwhh
I want to get the last index of my target value for a multi-value field. For example, idchain1SendMessageCheckMessage...
by Jackiifilwhh Path Finder in Splunk Search 01-09-2023
0 12
0
12
siksaw33
please help extract adsId,offerName, currentProductDescription, offerAccountToken, offerType, offerIdentifiermessage=...
by siksaw33 Path Finder in Splunk Search 01-09-2023
0 7
0
7
satish
Hi Experts,   I would like to compare values in same field (vlan_ids) for equality based on a machine serial (hyp_ser...
by satish Explorer in Splunk Search 01-09-2023
0 4
0
4
evallja
Hello, I have created and imported a lookup file ex. "hashes.csv" and I have pasted there a list of 500+ hashes. I wa...
by evallja Path Finder in Splunk Search 01-09-2023
0 2
0
2
aa0
Hi all,I want to extract the following word with rex expression:ABC\qq1234 expected result: qq1234Please note that th...
by aa0 Path Finder in Splunk Search 01-09-2023
0 2
0
2
niks987
Happy New Year to all of you. So I have syslog in which we have details of the devices and switches. The requirement ...
by niks987 Explorer in Splunk Search 01-09-2023
0 0
0
0
vineela
i need to extract fields which are in json format i have been trying using spath command for extracting the following...
by vineela Path Finder in Splunk Search 01-09-2023
0 8
0
8
Rakzskull
I'd want to merge two regex strings into a single one; any suggestions would be greatly appreciated.Reference Search ...
by Rakzskull Path Finder in Splunk Search 01-09-2023
0 2
0
2
Jagadeesh2022
Hi Friends, My requirement: I want to trigger SNOW ticket from Splunk alert. Before trigger I want to check any open ...
by Jagadeesh2022 Path Finder in Splunk Search 01-09-2023
0 5
0
5
martinhelgegren
Hi! I have various syslog clients sending me logs about their current state (a certain process). Eg. [timestamp] host...
by martinhelgegren Explorer in Splunk Search 01-08-2023
0 8
0
8
x3ncrypt
There is a lookup table with a row called 'ip' containing multiple ip address values which I would like to correlate ...
by x3ncrypt Loves-to-Learn Everything in Splunk Search 01-08-2023
0 6
0
6
sc_admin11
I have uploaded the screenshots of logs of same time but in one log stack and task field is empty and in one it is fi...
by sc_admin11 Explorer in Splunk Search 01-08-2023
0 6
0
6
shruti14
index=mysql sourcetype=audit_log earliest=1| rex field=source "\/home\/mysqld\/(?<Database1>.*)\/audit\/"| rex ...
by shruti14 Explorer in Splunk Search 01-08-2023
0 6
0
6
SplunkDash
Hello, I have a few use cases to send data from SPLUNK to consumers in real time, and consumers have both Linux/Windo...
by SplunkDash Motivator in Splunk Search 01-07-2023
0 9
0
9
sekhar463
Hai All, from the below search  how to convert secs to HH:MM format  age fields is getting time in secs   index=_inte...
by sekhar463 Path Finder in Splunk Search 01-07-2023
0 3
0
3
scootsblue48
Hi, I have been looking to see if splunk has the capability of searching for loggins outside of a specified set time ...
by scootsblue48 New Member in Splunk Search 01-06-2023
0 2
0
2
DesertSocBum
I am trying to match results to ONLY the names in a list I have using a lookup.  I cant figure out for the life of me...
by DesertSocBum Explorer in Splunk Search 01-06-2023
0 6
0
6
dtarnaine920
Hi, I'm trying to come up with a query to generate the count of strings in a json field in a log, across all events. ...
by dtarnaine920 Explorer in Splunk Search 01-06-2023
0 5
0
5
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors