Splunk Search

Splunk Search
Community Activity
KMoryson
I have the following table of activities: InternalExternalDirection1.1.1.12.2.2.2Outbound3.3.3.34.4.4.4Inbound5.5.5.5...
by KMoryson Explorer in Splunk Search 11-16-2022
0 2
0
2
sivakumargik
sample event "USR_LOGIN","USR_EMP_NO","USR_LAST_NAME","USR_FIRST_NAME","USR_DISPLAY_NAME","USR_STATUS","USR_EMAIL","...
by sivakumargik New Member in Splunk Search 11-16-2022
0 6
0
6
MScottFoley
I want to add an annotation to a dashboard every time we switch from blue servers to green servers or green to blue. ...
by MScottFoley Path Finder in Splunk Search 11-15-2022
0 1
0
1
SumanPalisetty
Hi, What are the limitations on subsearch? Please give one or two, please? This is an interview question. Regards Sum...
by SumanPalisetty Path Finder in Splunk Search 11-15-2022
0 3
0
3
DGilbert91
Hi all,I have a timestamp in a format I havn't dealt with before and I am struggling to get it converted to my timezo...
by DGilbert91 Explorer in Splunk Search 11-15-2022
0 4
0
4
SumanPalisetty
Hi,How will search head know which index has data? It's an interview question. Kindly help me.RegardsSuman P.
by SumanPalisetty Path Finder in Splunk Search 11-15-2022
0 2
0
2
ben_r
I have some Phantom playbooks performing tasks that I want to monitor on a Splunk dashboard - runs/day, distinct task...
by ben_r Engager in Splunk Search 11-15-2022
0 0
0
0
KyleMcDougall
Hi all!I'm trying to create a table with case_number and session as the two columns. Any event without a case_number ...
by KyleMcDougall Path Finder in Splunk Search 11-15-2022
0 5
0
5
jerinvarghese
Hi Team, Thanks in advance, Need a quick help in Regex query, Input values:  KUL6LJBJ62YDBLR6LC7BLNJRHRI6M5G6KKPHKUL6...
by jerinvarghese Communicator in Splunk Search 11-15-2022
0 5
0
5
shivaguthi
sample data _timesourcenameappIdstate10/8/207:53:27.090 AMxyzTransform-x-2020-10-081001success10/8/207:53:16.890 AMxy...
by shivaguthi Explorer in Splunk Search 11-15-2022
0 10
0
10
Mayurmpatil
what is splunk search query to find the oldest ( first ) event generated on a index ?
by Mayurmpatil Path Finder in Splunk Search 11-15-2022
0 6
0
6
Log_wrangler
Hi I have index = A sourcetype = A and source = /tmp/A.app.log I want to find the earliest event (date and time...
by Log_wrangler Builder in Splunk Search 11-15-2022
0 6
0
6
k31453
Hi, I have SPL which includes just using bunch of lookups and producting following data: _timeturnaround_timediff_tim...
by k31453 Explorer in Splunk Search 11-15-2022
0 2
0
2
syazwani
Hi peeps, Need help to do some query. Basically I'm trying to group some of field value in the 'Category' field into ...
by syazwani Path Finder in Splunk Search 11-14-2022
0 2
0
2
metylkinandrey
Good afternoon!I send a message like this: curl --location --request POST 'http://test.test.org:8088/services/collect...
by metylkinandrey Communicator in Splunk Search 11-14-2022
0 20
0
20
k115
Hi, I am working with firewall logs in external IP's ,  I want to collect blocked IP's from the firewall, and blocked...
by k115 Engager in Splunk Search 11-14-2022
0 3
0
3
Berfomet96
Hello,For the past week I've been working in a way to run some queries for a report about vulnerability findings.I ha...
by Berfomet96 Explorer in Splunk Search 11-14-2022
0 3
0
3
Ansab
I am trying to correlate authentication attempts [ index_A (username, role) vs index_B (username, authentication_time...
by Ansab Engager in Splunk Search 11-14-2022
0 1
0
1
lbonnes
These two cells are examples of results I see in IIs logs.  If the field is just a / (backslash) ( as in the first ex...
by lbonnes Observer in Splunk Search 11-14-2022
0 1
0
1
pc1234
is there a REST command to delete rows from the dmc_forwarder_assets.csv? For example, to remove rows where the statu...
by pc1234 Explorer in Splunk Search 11-14-2022
0 1
0
1
fedejko
Hi, I have a general question about which commands do you usually avoid in order to make search faster? For example I...
by fedejko Explorer in Splunk Search 11-14-2022
0 3
0
3
coreyCLI
I recently migrated a clustered index.  We wanted to rename the index.  I created the new index as your normally woul...
by coreyCLI Communicator in Splunk Search 11-14-2022
0 0
0
0
adam_reber
I have a use case that uses an indexed field that is configured at input time: [monitor:///my/input/file1] _meta = n...
by adam_reber Path Finder in Splunk Search 11-13-2022
0 3
0
3
jbrenner
Let's say I have data in an event that looks like this:       NAME: John NAME: Mary NAME: Sue       Assuming I have ...
by jbrenner Path Finder in Splunk Search 11-13-2022
0 3
0
3
JLopez
Hi Guys,I'm trying to create a table with the count emails sent and emails received from a given emails addressesColu...
by JLopez Explorer in Splunk Search 11-13-2022
0 6
0
6
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors