Splunk Search

Splunk Search
Community Activity
retro-bloke
in the raw event there is a line that goes Brand\="xyz"   What's the rex command I can use to extract this in my sear...
by retro-bloke Explorer in Splunk Search 12-08-2022
0 4
0
4
splunkuser320
I want to store the Splunk dashboard code in Gitlab or Bitbucket so I do not lose the dashboard. Any ideal if its pos...
by splunkuser320 Path Finder in Splunk Search 12-08-2022
0 1
0
1
MPJ44
I have a .csv with this format (this is a mock, just to give you an idea of the pattern)code, message,1, "Not found",...
by MPJ44 Loves-to-Learn Everything in Splunk Search 12-08-2022
0 3
0
3
SplunkMiester
Would someone know how to find out who is logged into a specific computer. Thanks in advance!
by SplunkMiester New Member in Splunk Search 12-08-2022
0 2
0
2
vrmandadi
Hello Experts ,I am trying to delete the fishbucket but I want to delete only one index=syslog..Is there a command I ...
by vrmandadi Builder in Splunk Search 12-08-2022
0 5
0
5
LAcioffi
Hello! In any event i have two fields, something like: User - BobHobbies - Singing, Dancing, Eating The "Hobbies" fie...
by LAcioffi Explorer in Splunk Search 12-08-2022
0 7
0
7
mxh7777
Hi, I'm looking for how to make conditional stats aggregation query according to a form input "With users" (value : Y...
by mxh7777 Path Finder in Splunk Search 12-08-2022
0 4
0
4
MG
The result should look like the table given below.Need to find the matching product number within customers and the r...
by MG Engager in Splunk Search 12-08-2022
0 3
0
3
csahoo
i am working on splunk cloud , i don't have access to server and i am using dashboard studio . This is my table code ...
by csahoo Explorer in Splunk Search 12-08-2022
0 0
0
0
AbilashSe
Could anyone please help to find out unused indexes in Splunk DMC
by AbilashSe Explorer in Splunk Search 12-07-2022
0 6
0
6
auzark
Can someone please give me an explanation as to what the below rex command is doing. I do not understand the w+ s+ d+...
by auzark Communicator in Splunk Search 12-07-2022
0 2
0
2
splunkreal
Hello, we found useful trick to have field values as new fields, for example :       | eval {status}=status | timecha...
by splunkreal Influencer in Splunk Search 12-07-2022
0 1
0
1
djoobbani
Dear Splunk Community: I have the following search query: <Basic_Search> | chart count by path_template, http_status_...
by djoobbani Path Finder in Splunk Search 12-07-2022
0 3
0
3
djoobbani
Dear Splunk Community :   I have the following search query: <Basic_search> duration | stats count, avg(duration), pe...
by djoobbani Path Finder in Splunk Search 12-07-2022
0 4
0
4
splunkuser320
I need to show only the results of the job. Job try multiple times in case of failure. So if the job passed on 3rd at...
by splunkuser320 Path Finder in Splunk Search 12-07-2022
0 3
0
3
bt149
I have a log file that is coming into splunk in json format.  There appear to be two fields of interest, "key" and "v...
by bt149 Path Finder in Splunk Search 12-07-2022
0 8
0
8
AssureSec
Hello all, I am trying to figure out the following: 1. If an alert for rule_id1 occurs at the same time on the same h...
by AssureSec Loves-to-Learn in Splunk Search 12-07-2022
0 3
0
3
Jagadeesh2022
Hi Friends, My current query: index = pg_idx_whse_prod_events host="*" sourcetype= PG_ST_PROBE_DATA source="/opt/redp...
by Jagadeesh2022 Path Finder in Splunk Search 12-07-2022
0 5
0
5
avoelk
Hello, the following search      index=index1 message_type=query NOT ([|inputlookup lookup1 | fields ip_address |re...
by avoelk Communicator in Splunk Search 12-07-2022
0 2
0
2
Splunk_321
I have two savedsearches savedsearch1: | basesearch | stats count by _time, LocationId savedsearch2: | basesearch | c...
by Splunk_321 Path Finder in Splunk Search 12-07-2022
0 6
0
6
ajayrathore
Hi, I have a field in the logs like below       2022-12-07T08:40:14.253180536       How can I convert it to splunk ti...
by ajayrathore Loves-to-Learn in Splunk Search 12-07-2022
0 1
0
1
jacknguyen
I get troubleshoot following splunk.doc  but it s not working.  Anyone have any solutions.Screenshot_20221207_055907....
by jacknguyen Path Finder in Splunk Search 12-07-2022
0 0
0
0
balu1211
Hi, Could you help in extracting the fields from this json events. sample json event1 {"type":"akamai_siem","format":...
by balu1211 Path Finder in Splunk Search 12-06-2022
0 1
0
1
LogUx
Hello Splunkers!! I need the results as per the below format. I have tried some SPL but not achieved with the expecte...
by LogUx Motivator in Splunk Search 12-06-2022
0 0
0
0
balu1211
Hi extract the field sample data : "tag":AKAMAI/WAF/ Thanks..
by balu1211 Path Finder in Splunk Search 12-06-2022
0 18
0
18
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors