Splunk Search

Splunk Search
Community Activity
mv10
We have alerts for high Windows Server CPU usage, and we have automated vulnerability scanners which can trip these a...
by mv10 Path Finder in Splunk Search 10-21-2022
0 12
0
12
mnj1809
Hello, I need your help to find a way to achieve the following use case:in main search:I've to categories: Windows an...
by mnj1809 Path Finder in Splunk Search 10-21-2022
0 8
0
8
ChrisG
Beyond what's in the Search Reference and the Search Manual, are there other sites that have SPL examples available t...
by ChrisG Splunk Employee Splunk Employee in Splunk Search 10-21-2022
1 11
1
11
codeJesus
Hello,  please can someone assist with creating syntax to 1. know the numbers of desktop, laptops, servers and networ...
by codeJesus Engager in Splunk Search 10-21-2022
0 4
0
4
uagraw01
To provide further from yesterday's SPL query. I am facing huge events in multivalues. I want to break in a single ev...
by uagraw01 Motivator in Splunk Search 10-20-2022
0 1
0
1
klim
Is it possible to restrict a role to run a certain search or only be able to run saved searches?Ie a user can only ru...
by klim Path Finder in Splunk Search 10-20-2022
0 0
0
0
leeyounsoo
hello I have a question I have a data that access_log data and json data is mixed and my need is to extract field fr...
by leeyounsoo Path Finder in Splunk Search 10-20-2022
0 10
0
10
PawelKozy
Add "A" field from another index if "B" and ""C" are equal across indexesI have search that returns events with field...
by PawelKozy Loves-to-Learn Lots in Splunk Search 10-20-2022
0 5
0
5
napoleon182
Hello Splunk Ninjas! I will require your assistance with designing my regex expression. I need to filter for the valu...
by napoleon182 Explorer in Splunk Search 10-20-2022
0 2
0
2
mcaulsc
Hi, Any thoughts appreciated. I have some connection data captured at connection termination, it has connection start...
by mcaulsc Path Finder in Splunk Search 10-20-2022
0 6
0
6
usarios
The goal is to take all eventIds with "operation failed" and exclude events with "Duplicate key" and "Event processed...
by usarios Engager in Splunk Search 10-20-2022
0 2
0
2
uagraw01
Hello Splunkers !!   Last weekCurrent weekNew Error "enableEnhancedCheckout" "enableEnhancedCheckout" "error_in_pytho...
by uagraw01 Motivator in Splunk Search 10-20-2022
0 9
0
9
metylkinandrey
Good afternoon! I figured out how to set up alerts. Understood with the parameter: Cron Expression. Currently I am us...
by metylkinandrey Communicator in Splunk Search 10-20-2022
0 3
0
3
Manth
I have splunk logs as given below. However, I wanted display fields in between square brackets "[ ]" in a table as gi...
by Manth Explorer in Splunk Search 10-19-2022
0 3
0
3
restinlinux
i want to pass the input token to my base search. In the panel its shows no results found, but when try click on "ope...
by restinlinux Explorer in Splunk Search 10-19-2022
0 1
0
1
mnowaczy
Hi,I am struggling with the configuration pxGrid on Splunk for Rapid Threat Containment with ISE.I just installed a n...
by mnowaczy New Member in Splunk Search 10-19-2022
0 1
0
1
RichieH
Hi All, When running a search the following error will appear in the job inspector. Users get this message intermitte...
by RichieH Explorer in Splunk Search 10-19-2022
0 4
0
4
dj56
Hello, Assuming i have numbers, let's say 1-2-3-4-5-6. And each of those represent Ip adressnumber of requestmethod1....
by dj56 Explorer in Splunk Search 10-19-2022
0 9
0
9
wanda619
how to set an alert running every day hourly? ex - if new transactions /events occur alert the user
by wanda619 Path Finder in Splunk Search 10-19-2022
0 3
0
3
danutmatei
Hi, I have an inputlookup with wSender, wSubject and wRecipient. I want to whitelist some of the emails sent by an us...
by danutmatei Explorer in Splunk Search 10-19-2022
0 2
0
2
tomapatan
Hi, I`ve got the following search that I would like to amend as follows: 1. swipe_in and swipe_out times to show on t...
by tomapatan Contributor in Splunk Search 10-19-2022
0 6
0
6
agupta13
I have an ```index=xyz data.id=1```which gives me list of unique id's [1,2,3,4,5]Not sure how to store the above resu...
by agupta13 Engager in Splunk Search 10-18-2022
0 2
0
2
SplunkDash
Hello, How I would assign one source type to two different indexes, one after another. As an example: I assigned sour...
by SplunkDash Motivator in Splunk Search 10-18-2022
0 16
0
16
SplunkDash
Hello, I need to install ARUBA TA; do you have any recommendations on how to proceed.  Your recommendations will be h...
by SplunkDash Motivator in Splunk Search 10-18-2022
0 0
0
0
splunkcol
Hello,When I run a query I get the results as I need them in a table from Splunk but when I download the .csv file, t...
by splunkcol Builder in Splunk Search 10-18-2022
0 3
0
3
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...