Splunk Search

Splunk Search
Community Activity
ghostrider
I have below format log messages. At the end I want to group the messages by BID. I tried using the below query but I...
by ghostrider Path Finder in Splunk Search 10-03-2022
0 3
0
3
charlottelimcl
Hi everyone, I am new to splunk. I am looking at windows event logs for the EventCode=4725 for all usernames within a...
by charlottelimcl Explorer in Splunk Search 10-03-2022
0 3
0
3
Roei_Rom
I have the following JSON object which contains certificates expreation date: {<!-- -->        "certificate-one.crt": 2022-11...
by Roei_Rom Engager in Splunk Search 10-02-2022
0 2
0
2
krim
is there any function works like group by grouping sets in Mysql?So that I can get a value from each group and a tota...
by krim Explorer in Splunk Search 10-02-2022
0 3
0
3
NizanCohen
Hi. I'm trying to get only failed login attempts but while I could find the correct field, it's not as accurate as th...
by NizanCohen Explorer in Splunk Search 10-02-2022
0 3
0
3
sarit_s
Hello,I have a rest query with a field that contain date and time Is it possible to limit the search by this field so...
by sarit_s Communicator in Splunk Search 10-02-2022
0 40
0
40
hank72
How to convert Windows lastLogonTimestamp from this format 07:17.45 PM, Fri 09/30/2022 to 09/30/2022 19:17:45Thank yo...
by hank72 Path Finder in Splunk Search 10-01-2022
0 5
0
5
youngso
youngsuh_0-1664595933183.png         index&#61;aws sourcetype&#61;"aws:metadata" InstanceId&#61;i-* | spath Tags{}.key.Name outp...
by SplunkTrust SplunkTrust in Splunk Search 10-01-2022
0 3
0
3
vikasg
ERROR HttpListener [97417 TcpChannelThread] - Exception while processing request from x.x.x.x:63596 for /en-US/splunk...
by vikasg Loves-to-Learn Lots in Splunk Search 10-01-2022
0 6
0
6
alexspunkshell
I have an SPL which gives a result. I want to get a trend of the result. So I tried using timechart command, but it i...
by alexspunkshell Contributor in Splunk Search 09-30-2022
0 2
0
2
spadler
The below search is intended to get status codes from two different sources and put them together in a table. It work...
by spadler Explorer in Splunk Search 09-30-2022
0 7
0
7
vp
I am trying to extract field from the "textPayload" value which is log message and it has "status" as key.  I want to...
by vp New Member in Splunk Search 09-30-2022
0 1
0
1
ddrillic
An internal customer got the following error on a dashboard when I running any search: Streamed search execute faile...
by ddrillic Ultra Champion in Splunk Search 09-30-2022
4 5
4
5
Tomb
Hi, I'm trying to update a KV store so that the only entries in it will be for consecutive returns from a search.   F...
by Tomb Engager in Splunk Search 09-30-2022
0 2
0
2
manojchacko78
Hi &#64;gcusello Need one more help, from the below log, i am able to remove all the wild characters using below script, ...
by manojchacko78 Path Finder in Splunk Search 09-30-2022
0 7
0
7
JykkeDaMan
I have the following fields, where some of them might be null, empty, whatnot values.I would like to split the Servic...
by JykkeDaMan Path Finder in Splunk Search 09-30-2022
0 3
0
3
Amol1300
Hi Team,   I wanted to count response time for each hours from application logs, wanted to create dashboard using lin...
by Amol1300 New Member in Splunk Search 09-30-2022
0 1
0
1
vishalduttauk
Hi there, I am new to this kind of analysis within Splunk but i've been asked to create a filter on events where the ...
by vishalduttauk Communicator in Splunk Search 09-30-2022
0 2
0
2
LogUx
Hello Splunkers!! I have two weeks events week 1 & week 2. Here I need to compare event of Week 1 & Week 2. The highl...
by LogUx Motivator in Splunk Search 09-30-2022
0 2
0
2
helge
Some of our data is logged in key value format separated by an equal sign (&#61;), e.g.: field1&#61;data1 field2&#61;data2 Spl...
by helge Builder in Splunk Search 09-29-2022
2 6
2
6
umesh
Hi ,   i want to find the license utilization of  firewall logs based on severity level. can anyone help me with the ...
by umesh Path Finder in Splunk Search 09-29-2022
0 2
0
2
phamxuantung
Hello, I have a log file that go like this     2022-09-30 09:43:41,038: INSTANCE&#61;34-bankgw1, REF&#61;237324562, MESSSAGE&#61;...
by phamxuantung Communicator in Splunk Search 09-29-2022
0 3
0
3
mistydennis
I need to create a field (30days) with a date 30 days from the date in a given field (pubdate). I believe I have that...
by mistydennis Communicator in Splunk Search 09-29-2022
0 4
0
4
mala_splunk_91
Hi, I  have a lookup file with the fields - biz_department, biz_unit, biz_owner, data_usageI have a query to generate...
by mala_splunk_91 Explorer in Splunk Search 09-29-2022
0 1
0
1
joomla
Hi Community Support, I have a lookup file with IP addresses where all the values are IP Addresses including the very...
by joomla Engager in Splunk Search 09-29-2022
0 4
0
4
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors