Splunk Search

Splunk Search
Community Activity
guywood13
I have the following data:     { "remote_addr": "1.2.3.4", "remote_user": "-", "time_local": "24/Nov/2022:09:55...
by guywood13 Path Finder in Splunk Search 11-25-2022
0 3
0
3
innoce
Hi,My datasets are much larger but these represent the crux of my hurdle...     Sourcetype= transaction fields= trans...
by innoce Path Finder in Splunk Search 11-24-2022
0 1
0
1
matcad81
HI All, I would like to visualize all the search fields/content I mentioned using the command search: index=*  | sear...
by matcad81 New Member in Splunk Search 11-24-2022
0 2
0
2
Ash
I want to implement this correlation search:   `sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* O...
by Ash Engager in Splunk Search 11-24-2022
0 1
0
1
ayu2375
Hello,I am looking for the equivalent of performing SQL like such:SELECT transaction_id, vendorFROM ordersWHERE trans...
by ayu2375 Engager in Splunk Search 11-24-2022
0 2
0
2
singlinet
We have api requests that I want to create statistics by the request but to do this I need to remove variable identif...
by singlinet Engager in Splunk Search 11-24-2022
0 2
0
2
stong2351
I have an eval query. The details object returned looks like this: {<!-- --> status: 404, code: ERROR } "details...
by stong2351 New Member in Splunk Search 11-24-2022
0 2
0
2
indeed_2000
Hi need to generate current date like this "20201123" and use as a search filter on metadata. AFAIK there is no "_tim...
by indeed_2000 Motivator in Splunk Search 11-24-2022
0 6
0
6
dougburdan
I have a saved search running every few minutes to append data to a 15 day csv log file within Splunk.  I'm trying to...
by dougburdan Explorer in Splunk Search 11-24-2022
0 2
0
2
xiaoming
Hi all,  I am attempting to convert data extracted as a field containing combination of hex and ascii data. Was wonde...
by xiaoming New Member in Splunk Search 11-23-2022
0 3
0
3
ansif
Is there a way to achieve this?   I have  a lookup table with 2 columns alert_type and short_description.   alert_typ...
by ansif Motivator in Splunk Search 11-23-2022
0 5
0
5
MikeyD100
Hi, I want to display the error details in the last 30 mins, so they can be investigated, when the amount of errors h...
by MikeyD100 Explorer in Splunk Search 11-23-2022
0 4
0
4
PrisonMike
0
10
simo
Hi, I have a lookup as follow ipidname111.111.111.111111simone*222marco in the index I have  ipid 111.111.111.1111112...
by simo Path Finder in Splunk Search 11-23-2022
0 2
0
2
splunkuser320
I have a job that runs multiple times if it failed. I need to create a dashboard with a table that shows all the atte...
by splunkuser320 Path Finder in Splunk Search 11-23-2022
0 3
0
3
sphiwee
i have below result, how can I do a regex to extract the fields, first being DateTime, username, Action, Entity2022-1...
by sphiwee Contributor in Splunk Search 11-22-2022
0 2
0
2
renangomes
How do I check which major destinations generate the most logs on a specific firewall host &#61; 10.22.44.254? I would li...
by renangomes New Member in Splunk Search 11-22-2022
0 1
0
1
itsmevic70
Is it possible to create a Pie Chart from three fields? If so, how?   Thanks a million in advance! 
by itsmevic70 Explorer in Splunk Search 11-22-2022
0 2
0
2
Praveenrocky
Hi All,   i have events like below and i want to extract the fields as TotalRecords, SuccessRecords, FailedRecords, B...
by Praveenrocky New Member in Splunk Search 11-22-2022
0 2
0
2
Marinus
I'm calculating the sum of spending over a month period. * | timechart sum(value) span&#61;1mon This will produce the ...
by Marinus Communicator in Splunk Search 11-22-2022
4 8
4
8
Julia1231
Hi community, I have 2 data sources, 1 from a csv to get the list of district (include number of population according...
by Julia1231 Communicator in Splunk Search 11-22-2022
0 1
0
1
userQ
Hello, I put them in context before showing the query. I have a splunk that I test on it to see the query results bec...
by userQ Loves-to-Learn in Splunk Search 11-22-2022
0 3
0
3
PrisonMike
       
by PrisonMike Explorer in Splunk Search 11-22-2022
0 1
0
1
venky1544
Time door Fruit Count11/11/2022 04:36:07 112 APPLE 1411/11/2022 04:10:00 111 PEAR 811/11/2022 03:01:02 111 PEAR 11911...
by venky1544 Builder in Splunk Search 11-22-2022
0 2
0
2
metylkinandrey
I get strange errors when searching messages by old dates. If I put a search for more than two hours, I immediately g...
by metylkinandrey Communicator in Splunk Search 11-22-2022
0 4
0
4
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors