Splunk Search

Splunk Search
Community Activity
kgiri253
As we can see below the two events contain multiple results. But when I try to export it as csv all these events get ...
by kgiri253 Explorer in Splunk Search 09-09-2022
0 3
0
3
darphboubou
HI,   I would like to get the servers who use only ntlmv1.   So in a first search I using this command       index="w...
by darphboubou Explorer in Splunk Search 09-09-2022
0 8
0
8
abhishekbhasin
Need to extract P302 P1 P2 with a single regular ex I build (?<Par>P[1-9][0-9]*) but when I run this in splunk it onl...
by abhishekbhasin Explorer in Splunk Search 09-09-2022
0 5
0
5
Bobmc
Hello, I'm a bit new to Splunk and I'm trying to run a query that shows me users in Active directory that are still e...
by Bobmc Observer in Splunk Search 09-09-2022
0 6
0
6
SimonSchoppel
I want to display the number of sent data in certain time in the dashboard. I think the best way is with "Single Valu...
by SimonSchoppel Explorer in Splunk Search 09-09-2022
0 3
0
3
Toki
I'm using lookup but don't know how to do a partial match instead of an exact match Example: 10.20.30.40 is in the li...
by Toki Explorer in Splunk Search 09-09-2022
0 4
0
4
mahesh27
Hi all, I have few queries to be modified using tstats:I am new to splunk, please let me know whether these queries c...
by mahesh27 Communicator in Splunk Search 09-08-2022
0 15
0
15
zacksoft
How do I get the  job-execution start time and job execution endtime of my  query as output of the query.index = some...
by zacksoft Contributor in Splunk Search 09-08-2022
0 5
0
5
bro_coded101
My current search is: `index`| search source="Main Source" | fields identifier, status_label| chart count over identi...
by bro_coded101 Loves-to-Learn Lots in Splunk Search 09-08-2022
0 3
0
3
mark_cet
We have alert events coming into Splunk & Splunk ITSI that we open Service Now incidents for, but depending on the ev...
by mark_cet Path Finder in Splunk Search 09-08-2022
0 4
0
4
KH
I'm extremely new to Splunk and finding learning SPL very frustrating. I'm trying to look for windows log on events/ ...
by KH Engager in Splunk Search 09-08-2022
0 2
0
2
Finn
I have encountered an issue with the foreach command on mv-fields.When I execute my search, Splunk says: "Error in 'e...
by Finn Explorer in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
What is the difference between now() and _time?
by smanojkumar Contributor in Splunk Search 09-08-2022
0 2
0
2
Dharani
Hi, Below is the example for raw log: 20220906T23:43:58+03:00#0115dummyvalue.com#01110.111.169.11:51868#01110.45.38.1...
by Dharani Path Finder in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
Start_Time=092659Start_Date=20220908My requirement is to find the job amount many jobs that runs longer than a day, t...
by smanojkumar Contributor in Splunk Search 09-08-2022
0 3
0
3
responsys_cm
I'm trying to make the Linux audit daemon data play nice. One of the challenges is that a particular action can trig...
by responsys_cm Builder in Splunk Search 09-08-2022
0 2
0
2
mydog8it
I have a comma delimited multivalue field that contains text and a digit in each value pair that I am trying to find ...
by mydog8it Builder in Splunk Search 09-08-2022
1 14
1
14
CybSec1
Hello,I have logs like : samples={'xxxxxxx' : {'111' :{'222' :{'333'}}}}{'yyyyyyy'{'444'}}{'zzzzzzz'}I need to take a...
by CybSec1 New Member in Splunk Search 09-08-2022
0 2
0
2
FGAnders
Hi, Is there any way to exclude any events that has more than one value of a field  from end result.    index=X statu...
by FGAnders Explorer in Splunk Search 09-08-2022
0 2
0
2
PepposChris
Hello,   I've been using SPLUNK search REST API for a while now and just today i've run into the following issue.   W...
by PepposChris Observer in Splunk Search 09-07-2022
0 4
0
4
kpavan
Hi All, Am looking for query to have multiple earliest days  index=something sourcetype=something earliest=-7d@d late...
by kpavan Path Finder in Splunk Search 09-07-2022
0 3
0
3
jhcbazinga95
Hey all, Can someone help me out with a JSON related question! Many many thanks!  I have a JSON arrays field in this...
by jhcbazinga95 Loves-to-Learn Everything in Splunk Search 09-07-2022
0 3
0
3
SS1
Hi, I have 2 searches where the dedup strategy is different, i want to combine the 2 searches but need help with dedu...
by SS1 Path Finder in Splunk Search 09-07-2022
0 1
0
1
janderhungrige
Hi,I want to count the numbers of containers per company. Each data point has a container id, company id, and much mo...
by janderhungrige Observer in Splunk Search 09-07-2022
0 1
0
1
Kislac
Greetings. Is it possible merge 2 search? If there is any common value than connect it. If there is no match keep the...
by Kislac Engager in Splunk Search 09-07-2022
0 4
0
4
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors