| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Trying to get these UUID/GUIDs to extract from the message field. Hoping to create a rex to extract everything after ...
        
         
           by 
           
                
                    
                        judges88
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        I have read all the posts about "merging fields" and none of the options work for me. 
  I have events where the same...
        
         
           by 
           
                
                    
                        JohnnyMnemonic
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi All, 
  these are the logger info counts which are generated in splunk  
  Total numner where inds-a 20Total numne...
        
         
           by 
           
                
                    
                        Splunkstart
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        hi 
  I want to not display the week end in my chart 
  for example, if i use a time picler range of 7 days, I just w...
        
         
           by 
           
                
                    
                        jip31
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  11
	 | |||
| 
        I am having issue with "Status" values as below and screenshot, please find below json and search query. 
  Please ad...
        
         
           by 
           
                
                    
                        anu41
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi,
  Sometimes if we are doing base search, if not handled properly, you will see page loading, how do you handle it...
        
         
           by 
           
                
                    
                        SumanPalisetty
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Dears, 
    
  We need your support to convert below search to tstats search. 
  
   (index=os_windows OR index=works...
        
         
           by 
           
                
                    
                        Abdullah
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello,  We have been using this query to list out hosts that are not sending logs since past 24h.  It has been workin...
        
         
           by 
           
                
                    
                        neerajs_81
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  8
	 | |||
| 
        I have the following table of activities: 
  InternalExternalDirection1.1.1.12.2.2.2Outbound3.3.3.34.4.4.4Inbound5.5....
        
         
           by 
           
                
                    
                        KMoryson
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        sample event 
  "USR_LOGIN","USR_EMP_NO","USR_LAST_NAME","USR_FIRST_NAME","USR_DISPLAY_NAME","USR_STATUS","USR_EMAIL"...
        
         
           by 
           
                
                    
                        sivakumargik
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               11-18-2019
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        I want to add an annotation to a dashboard every time we switch from blue servers to green servers or green to blue. ...
        
         
           by 
           
                
                    
                        MScottFoley
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Hi, 
  What are the limitations on subsearch? Please give one or two, please? This is an interview question. 
  Regar...
        
         
           by 
           
                
                    
                        SumanPalisetty
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi all,
  I have a timestamp in a format I havn't dealt with before and I am struggling to get it converted to my tim...
        
         
           by 
           
                
                    
                        DGilbert91
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-26-2022
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi,
  How will search head know which index has data? It's an interview question. Kindly help me.
  Regards
  Suman P...
        
         
           by 
           
                
                    
                        SumanPalisetty
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        I have some Phantom playbooks performing tasks that I want to monitor on a Splunk dashboard - runs/day, distinct task...
        
         
           by 
           
                
                    
                        ben_r
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi all!
  I'm trying to create a table with case_number and session as the two columns. 
  Any event without a case_n...
        
         
           by 
           
                
                    
                        KyleMcDougall
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               05-11-2022
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi Team, 
  Thanks in advance, 
  Need a quick help in Regex query, 
  Input values:  
  KUL6LJBJ62YDBLR6LC7BLNJRHRI6...
        
         
           by 
           
                
                    
                        jerinvarghese
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               11-15-2022
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        sample data 
  _timesourcenameappIdstate10/8/207:53:27.090 AMxyzTransform-x-2020-10-081001success10/8/207:53:16.890 A...
        
         
           by 
           
                
                    
                        shivaguthi
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               10-08-2020
             
           
         
        | 
		
		0
   | 
	  
	  10
	 | |||
| 
        what is splunk search query to find the oldest ( first ) event generated on a index ?
        
         
           by 
           
                
                    
                        Mayurmpatil
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               07-10-2018
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi  
  I have index = A sourcetype = A and source = /tmp/A.app.log 
  I want to find the earliest event (date and tim...
        
         
           by 
           
                
                    
                        Log_wrangler
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               04-18-2018
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi, I have SPL which includes just using bunch of lookups and producting following data: 
  _timeturnaround_timediff_...
        
         
           by 
           
                
                    
                        k31453
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-14-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi peeps, 
  Need help to do some query. Basically I'm trying to group some of field value in the 'Category' field in...
        
         
           by 
           
                
                    
                        syazwani
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               11-14-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Good afternoon!I send a message like this: 
  curl --location --request POST 'http://test.test.org:8088/services/coll...
        
         
           by 
           
                
                    
                        metylkinandrey
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               11-07-2022
             
           
         
        | 
		
		0
   | 
	  
	  20
	 | |||
| 
        Hi, I am working with firewall logs in external IP's ,  I want to collect blocked IP's from the firewall, and blocked...
        
         
           by 
           
                
                    
                        k115
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               11-13-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hello,
  For the past week I've been working in a way to run some queries for a report about vulnerability findings.
...
        
         
           by 
           
                
                    
                        Berfomet96
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               11-14-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 |