Splunk Search

Splunk Search
Community Activity
chandankr
i want to make a dashboard of last 3 month of avg cpu load and max cpu load For example:dec= 320dec=10dec=40dec=90nov...
by chandankr Path Finder in Splunk Search 12-12-2022
0 1
0
1
indeed_2000
Hi I have 3 servers that generate log file daily with size about 12GB (12*3=36GB) How can I gather these files on cen...
by indeed_2000 Motivator in Splunk Search 12-12-2022
0 7
0
7
sekhar463
hi All, can someone help on the splunk search eval condition based on below scenario using fields  Actualstarttime an...
by sekhar463 Path Finder in Splunk Search 12-12-2022
0 1
0
1
minpd0309
HI, I want to make the log below in the form of the table below. What should I do with the spl?   [log ex]  14:39:19....
by minpd0309 Explorer in Splunk Search 12-12-2022
0 1
0
1
splunk_enjoyer
Hello Splunk Lovers! i have date format 202211131614220000 and i want convert this format to readble for Splunk i sho...
by splunk_enjoyer Explorer in Splunk Search 12-11-2022
0 3
0
3
tminicoz
My objective is to make a search that compares the dest_ip field value of outbound traffic with the ip values in a lo...
by tminicoz Engager in Splunk Search 12-11-2022
0 2
0
2
batham
Hi Folks , I am new to splunk and trying to get dynamic source value from the response, here is my query:   index="it...
by batham Explorer in Splunk Search 12-11-2022
0 2
0
2
a212830
Hi, Just upgraded to Splunk 6.1.1 and I noticed a new process running (introspection) and a new index (which, btw, is...
by a212830 Champion in Splunk Search 12-11-2022
6 3
6
3
NapalmYourMom
I have the following main search:  index=utm sys=SecureNet action=drop | eval protocol=case(proto==1, "ICMP", proto==...
by NapalmYourMom Observer in Splunk Search 12-11-2022
0 2
0
2
moayadalghamdi
Dears    I need your help in extracting the domain and top level domain from dns queries where:   Query Field        ...
by moayadalghamdi Path Finder in Splunk Search 12-11-2022
0 2
0
2
sanggonlee
My logs have a JSON field, like this: {<!-- -->  "foo": 5,  "bar": {}} I'd like to filter out logs that have an empty JSON fo...
by sanggonlee New Member in Splunk Search 12-10-2022
0 2
0
2
SentinelPrime01
Im trying to get the following into a table and have a count of the successful attempts. I have tried a few ways, but...
by SentinelPrime01 Explorer in Splunk Search 12-10-2022
0 5
0
5
dkingsland967
Hi all, I'm currently working on creating an alert for any time a user mounts an ISO. My core search works exactly as...
by dkingsland967 Observer in Splunk Search 12-09-2022
0 1
0
1
md
I have a KV store based lookup for Port Address Translation. Given the first 3 octets of a public facing IP and a por...
by md Explorer in Splunk Search 12-09-2022
0 2
0
2
bt149
I have a subsearch that is used to pull user, and start and expiration time fields.  I want to use the two time field...
by bt149 Path Finder in Splunk Search 12-09-2022
0 3
0
3
rajababu
I looking for someone help on this I am struggling with parsing the logs when pool was down and and send alert 5 minu...
by rajababu Observer in Splunk Search 12-09-2022
0 1
0
1
jaydiare
Hello Splunk community, I need some help with the following:    I have a .csv file that is being created at a Pacific...
by jaydiare Explorer in Splunk Search 12-09-2022
0 1
0
1
neilsmith2
Hi, looking for guidance please on how to alert on recurring auth events over multiple time spans, but I can't get my...
by neilsmith2 Explorer in Splunk Search 12-09-2022
0 1
0
1
hamishcross
Hi All I am trying to extract the values that trail context, userid, username, groupid Sample partial event   { "type...
by hamishcross Engager in Splunk Search 12-09-2022
0 4
0
4
greekleo89
Hi Guys,   I am comparing the values from a csv with those returned in a json format on a splunk search.   At the mom...
by greekleo89 Loves-to-Learn Everything in Splunk Search 12-09-2022
0 3
0
3
Veeru
HelloGreetings!i have data in the following wayDevice   Processor  status01             Splunkd        Running01     ...
by Veeru Path Finder in Splunk Search 12-09-2022
0 4
0
4
nehamvinchankar
0
1
Woodpecker
HI,I have a multivalued field with values asABCI want it to be replaced as 'A','B','C' . I tried to do it with eval m...
by Woodpecker Path Finder in Splunk Search 12-08-2022
0 5
0
5
iammax
Hi Community,I have 2 mvfields, how can I search for all the values in the first mvfield to all the values in the sec...
by iammax Explorer in Splunk Search 12-08-2022
0 4
0
4
Peru123
  Hi , I need to extract the value FISOBPIT10101 from the below lines.   message:PSUS7|8897|FISOBPIT10101|OWA|8897|88...
by Peru123 Loves-to-Learn in Splunk Search 12-08-2022
0 5
0
5
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors