Splunk Search

Splunk Search
Community Activity
yadavameeth
How to update a lookup file in splunk from Phantom?
by yadavameeth Engager in Splunk Search 12-27-2022
1 5
1
5
chetanN
Hi all, To give a problem background, I am trying to run a map command inside a search to get some values. THE JSON I...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 1
0
1
sekhar463
Good day,   how to group results of a same filed value into one fileld value from below table i have a field box-name...
by sekhar463 Path Finder in Splunk Search 12-27-2022
0 4
0
4
Aj01
i have been using this query but couldn't be able to remove null rows, please help me index=Window_wash | rex field=...
by Aj01 Path Finder in Splunk Search 12-26-2022
0 4
0
4
sasank
Hi,I need the JSON array in Splunk `List` view to be expanded by default instead of showing the Plus icon.I have a Sp...
by sasank Explorer in Splunk Search 12-25-2022
0 3
0
3
Dantuzzo
Hi,i'm struggling in calculating hourly or daily average and displaying the results if there's no events at all, whic...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-25-2022
0 2
0
2
sasank
Hi,I have a Splunk event "Application -> start of the log".When I try to search for this log using the exact text the...
by sasank Explorer in Splunk Search 12-25-2022
0 2
0
2
informatika
Hello, new to using splunk across a domain and I am attempting to get a query that details any domain user account ch...
by informatika Loves-to-Learn in Splunk Search 12-24-2022
0 3
0
3
avadhutha
I have a requirement to pull 90% of max execution time. Ex: I have 10 requests for an hour and it's execution times a...
by avadhutha Explorer in Splunk Search 12-24-2022
0 1
0
1
st1
We currently have an report every morning that shows which users have been removed from a particular AD group from th...
by st1 Path Finder in Splunk Search 12-24-2022
0 3
0
3
zoebanning
Hi Splunk Community,I was wondering if it was possible to have a chart that was made up from 3 fields.... I have alre...
by zoebanning Path Finder in Splunk Search 12-24-2022
0 2
0
2
Dantuzzo
Hi,i'm trying to calculate the average events weekly by their severity and comparing the daily amount with the weekly...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-23-2022
0 1
0
1
user33
Hello, I am trying to extract the below 201 text highlighted in red below as one separate field from two separate eve...
by user33 Path Finder in Splunk Search 12-23-2022
0 4
0
4
sasank
After I perform a search and click the "Format" Icon above the search results, there is an option for "Wrap Results"....
by sasank Explorer in Splunk Search 12-23-2022
1 0
1
0
Anu189
Search query for including non-business hours and weekends ie exclude Monday to Friday 9am to 5pm 
by Anu189 New Member in Splunk Search 12-23-2022
0 1
0
1
abazgwa21cz
I want to set a Schedule for my search to find the data sent by user in our system . This is my search to catch each ...
by abazgwa21cz Explorer in Splunk Search 12-23-2022
0 3
0
3
avadhutha
mainsearch| stats count(_raw)  as Cou by hour|join hour [ subsearch| head -$Cou$ ]   Above mentioned command is not w...
by avadhutha Explorer in Splunk Search 12-23-2022
0 2
0
2
svarendorff
Having some issue with extraction.source:SESSION: Session closedClient address: 123.CCCCCCCClient name: CC222C22[123....
by svarendorff Explorer in Splunk Search 12-22-2022
0 5
0
5
bt149
I have a field called properties.requestbody.  I would like to have this field broken out based on the field and valu...
by bt149 Path Finder in Splunk Search 12-22-2022
0 9
0
9
leagawa
I want to convert this query to tstats for faster searching can you help me convert it index=win-security host=srv001...
by leagawa New Member in Splunk Search 12-22-2022
0 1
0
1
Taruchit
Hi All,I have enquired this problem earlier in older threads, however, could not get a working answer, thus, created ...
by Taruchit Contributor in Splunk Search 12-22-2022
0 5
0
5
Chaser
My task is format field "app" with relative fieldnameHow can I use format command to format as example: (app=*app1* O...
by Chaser Explorer in Splunk Search 12-22-2022
0 8
0
8
langtuphidao
I have some log, and i want get top 20 with 2 conditions:  I user: index="fortinet" |top srcip srcname but in chart d...
by langtuphidao New Member in Splunk Search 12-22-2022
0 3
0
3
Cuicuo
I found that I am the only user who has this situation. My role is admin. I thought it was a performance problem, but...
by Cuicuo Engager in Splunk Search 12-22-2022
0 3
0
3
Deeksha
I need a query for basic malware outbreak   Need query with server IP and server name from this raw logs.
by Deeksha New Member in Splunk Search 12-22-2022
0 2
0
2
Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...