Splunk Search

Splunk Search
Community Activity
chetanN
Hi all, I am very new to Splunk and trying to learn it. Following is my JSON: {<!-- -->        TrainID&#61;AA11          TrainDat...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 2
0
2
chetanN
Hi all, I am trying to run a basic search where I am trying to print table based on where and like() condition. But i...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 5
0
5
yadavameeth
How to update a lookup file in splunk from Phantom?
by yadavameeth Engager in Splunk Search 12-27-2022
1 5
1
5
chetanN
Hi all, To give a problem background, I am trying to run a map command inside a search to get some values. THE JSON I...
by chetanN Loves-to-Learn Lots in Splunk Search 12-27-2022
0 1
0
1
sekhar463
Good day,   how to group results of a same filed value into one fileld value from below table i have a field box-name...
by sekhar463 Path Finder in Splunk Search 12-27-2022
0 4
0
4
Aj01
i have been using this query but couldn't be able to remove null rows, please help me index&#61;Window_wash | rex field&#61;...
by Aj01 Path Finder in Splunk Search 12-26-2022
0 4
0
4
sasank
Hi,I need the JSON array in Splunk &#96;List&#96; view to be expanded by default instead of showing the Plus icon.I have a Sp...
by sasank Explorer in Splunk Search 12-25-2022
0 3
0
3
Dantuzzo
Hi,i'm struggling in calculating hourly or daily average and displaying the results if there's no events at all, whic...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-25-2022
0 2
0
2
sasank
Hi,I have a Splunk event "Application -&gt; start of the log".When I try to search for this log using the exact text the...
by sasank Explorer in Splunk Search 12-25-2022
0 2
0
2
informatika
Hello, new to using splunk across a domain and I am attempting to get a query that details any domain user account ch...
by informatika Loves-to-Learn in Splunk Search 12-24-2022
0 3
0
3
avadhutha
I have a requirement to pull 90% of max execution time. Ex: I have 10 requests for an hour and it's execution times a...
by avadhutha Explorer in Splunk Search 12-24-2022
0 1
0
1
st1
We currently have an report every morning that shows which users have been removed from a particular AD group from th...
by st1 Path Finder in Splunk Search 12-24-2022
0 3
0
3
zoebanning
Hi Splunk Community,I was wondering if it was possible to have a chart that was made up from 3 fields.... I have alre...
by zoebanning Path Finder in Splunk Search 12-24-2022
0 2
0
2
Dantuzzo
Hi,i'm trying to calculate the average events weekly by their severity and comparing the daily amount with the weekly...
by Dantuzzo Loves-to-Learn Lots in Splunk Search 12-23-2022
0 1
0
1
user33
Hello, I am trying to extract the below 201 text highlighted in red below as one separate field from two separate eve...
by user33 Path Finder in Splunk Search 12-23-2022
0 4
0
4
sasank
After I perform a search and click the "Format" Icon above the search results, there is an option for "Wrap Results"....
by sasank Explorer in Splunk Search 12-23-2022
1 0
1
0
Anu189
Search query for including non-business hours and weekends ie exclude Monday to Friday 9am to 5pm 
by Anu189 New Member in Splunk Search 12-23-2022
0 1
0
1
abazgwa21cz
I want to set a Schedule for my search to find the data sent by user in our system . This is my search to catch each ...
by abazgwa21cz Explorer in Splunk Search 12-23-2022
0 3
0
3
avadhutha
mainsearch| stats count(_raw)  as Cou by hour|join hour [ subsearch| head -$Cou$ ]   Above mentioned command is not w...
by avadhutha Explorer in Splunk Search 12-23-2022
0 2
0
2
svarendorff
Having some issue with extraction.source:SESSION: Session closedClient address: 123.CCCCCCCClient name: CC222C22[123....
by svarendorff Explorer in Splunk Search 12-22-2022
0 5
0
5
bt149
I have a field called properties.requestbody.  I would like to have this field broken out based on the field and valu...
by bt149 Path Finder in Splunk Search 12-22-2022
0 9
0
9
leagawa
I want to convert this query to tstats for faster searching can you help me convert it index&#61;win-security host&#61;srv001...
by leagawa New Member in Splunk Search 12-22-2022
0 1
0
1
Taruchit
Hi All,I have enquired this problem earlier in older threads, however, could not get a working answer, thus, created ...
by Taruchit Contributor in Splunk Search 12-22-2022
0 5
0
5
Chaser
My task is format field "app" with relative fieldnameHow can I use format command to format as example: (app&#61;*app1* O...
by Chaser Explorer in Splunk Search 12-22-2022
0 8
0
8
langtuphidao
I have some log, and i want get top 20 with 2 conditions:  I user: index&#61;"fortinet" |top srcip srcname but in chart d...
by langtuphidao New Member in Splunk Search 12-22-2022
0 3
0
3
Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...