Splunk Search

Splunk Search
Community Activity
Mayurmpatil
what is splunk search query to find the oldest ( first ) event generated on a index ?
by Mayurmpatil Path Finder in Splunk Search 11-15-2022
0 6
0
6
Log_wrangler
Hi I have index = A sourcetype = A and source = /tmp/A.app.log I want to find the earliest event (date and time...
by Log_wrangler Builder in Splunk Search 11-15-2022
0 6
0
6
k31453
Hi, I have SPL which includes just using bunch of lookups and producting following data: _timeturnaround_timediff_tim...
by k31453 Explorer in Splunk Search 11-15-2022
0 2
0
2
syazwani
Hi peeps, Need help to do some query. Basically I'm trying to group some of field value in the 'Category' field into ...
by syazwani Path Finder in Splunk Search 11-14-2022
0 2
0
2
metylkinandrey
Good afternoon!I send a message like this: curl --location --request POST 'http://test.test.org:8088/services/collect...
by metylkinandrey Communicator in Splunk Search 11-14-2022
0 20
0
20
k115
Hi, I am working with firewall logs in external IP's ,  I want to collect blocked IP's from the firewall, and blocked...
by k115 Engager in Splunk Search 11-14-2022
0 3
0
3
Berfomet96
Hello,For the past week I've been working in a way to run some queries for a report about vulnerability findings.I ha...
by Berfomet96 Explorer in Splunk Search 11-14-2022
0 3
0
3
Ansab
I am trying to correlate authentication attempts [ index_A (username, role) vs index_B (username, authentication_time...
by Ansab Engager in Splunk Search 11-14-2022
0 1
0
1
lbonnes
These two cells are examples of results I see in IIs logs.  If the field is just a / (backslash) ( as in the first ex...
by lbonnes Observer in Splunk Search 11-14-2022
0 1
0
1
pc1234
is there a REST command to delete rows from the dmc_forwarder_assets.csv? For example, to remove rows where the statu...
by pc1234 Explorer in Splunk Search 11-14-2022
0 1
0
1
fedejko
Hi, I have a general question about which commands do you usually avoid in order to make search faster? For example I...
by fedejko Explorer in Splunk Search 11-14-2022
0 3
0
3
coreyCLI
I recently migrated a clustered index.  We wanted to rename the index.  I created the new index as your normally woul...
by coreyCLI Communicator in Splunk Search 11-14-2022
0 0
0
0
adam_reber
I have a use case that uses an indexed field that is configured at input time: [monitor:///my/input/file1] _meta = n...
by adam_reber Path Finder in Splunk Search 11-13-2022
0 3
0
3
jbrenner
Let's say I have data in an event that looks like this:       NAME: John NAME: Mary NAME: Sue       Assuming I have ...
by jbrenner Path Finder in Splunk Search 11-13-2022
0 3
0
3
JLopez
Hi Guys,I'm trying to create a table with the count emails sent and emails received from a given emails addressesColu...
by JLopez Explorer in Splunk Search 11-13-2022
0 6
0
6
joe06031990
Hi, on our Splunk instance I have set a report using a time chart with a span of 1h and time frame of a day and the r...
by joe06031990 Communicator in Splunk Search 11-13-2022
0 5
0
5
Paul
Hello: I am trying to get fields from different events in the same table. I have two different events, and let's say ...
by Paul Explorer in Splunk Search 11-12-2022
0 3
0
3
indeed_2000
Hi I have challenge that need to know how with splunk, math, statistics, ... able to solve it. Here is the log: sampl...
by indeed_2000 Motivator in Splunk Search 11-11-2022
0 5
0
5
SumanPalisetty
Hi, I am facing an issue with the eval if condition. Please help.   index=main, source=ls.csv | eval new_field = if(e...
by SumanPalisetty Path Finder in Splunk Search 11-11-2022
0 1
0
1
brcox9090
I am trying to get a wildcard to work with a where clause. Not sure if I'm doing something wrong altogether or just m...
by brcox9090 New Member in Splunk Search 11-11-2022
0 2
0
2
manojchacko78
Hi, I am using the following script in Splunk query. Here i am trying having multiple values in field AdditionalData ...
by manojchacko78 Path Finder in Splunk Search 11-11-2022
0 3
0
3
Splunk_321
I have data something like below.  msg: {<!-- -->      application: test-app     correlationid: 0.59680117.1667864418.7d2b8d5...
by Splunk_321 Path Finder in Splunk Search 11-11-2022
0 1
0
1
thoma1
Can't seem to get this lookup(KVstore) to function.The dataset is from active directory in some cases in the same eve...
by thoma1 Explorer in Splunk Search 11-11-2022
0 11
0
11
Fleety
Hello,I have a collection of logs (same source type) but some of them have different or additional fields. In order t...
by Fleety Loves-to-Learn Lots in Splunk Search 11-11-2022
0 1
0
1
Berfomet96
Hello everybody, I'm trying to join two different sourcetypes from the same index that both have a field with the sam...
by Berfomet96 Explorer in Splunk Search 11-11-2022
0 2
0
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors