Splunk Search

Splunk Search
Community Activity
jwalzerpitt
I am trying to an eval with like to assign priority to certain IPs/hosts and running into an issue where the priority...
by jwalzerpitt Influencer in Splunk Search 09-16-2022
0 8
0
8
allan_newton
Hello Splunkers, I have a situation where I have to replace the first cell in each row in a statistics table with a ...
by allan_newton Path Finder in Splunk Search 09-16-2022
1 10
1
10
Julia1231
Hi everyone, From dbxquery, I retrieve this table: idstart_time1end_time1start_time2end_time2123413/09/2022 21:46:43....
by Julia1231 Communicator in Splunk Search 09-16-2022
0 1
0
1
neerajs_81
Hi,   Fundamentals question but one of those brain teasers.  How do i get a total count of distinct values of a field...
by neerajs_81 Builder in Splunk Search 09-16-2022
0 4
0
4
LogUx
Hello Splunkers !! As per the below screenshot I want to capitalise the first letter of every filed column.So for the...
by LogUx Motivator in Splunk Search 09-15-2022
0 6
0
6
Manideep
scenario : - I had a log file. I am able to extract the fields from the log event and also see the data in the extrac...
by Manideep Loves-to-Learn Lots in Splunk Search 09-15-2022
0 3
0
3
zoe
Hi,  I have data like A-001, A-002, A-003..... I would like to know how to extract the numbers from these strings: 00...
by zoe Path Finder in Splunk Search 09-15-2022
0 3
0
3
cramasta
Can I run a CLI search that will output the results to a file in json format? Thanks, Joe
by cramasta Builder in Splunk Search 09-15-2022
1 3
1
3
ichesla1111
Hello,
by ichesla1111 Path Finder in Splunk Search 09-15-2022
0 1
0
1
marco_massari11
Hi All, I have the following saved search: | tstats summariesonly=true fillnull_value="N/D" count from datamodel=Chan...
by marco_massari11 Communicator in Splunk Search 09-15-2022
0 5
0
5
comcordriro
Hi there after much searching and testing i feel i'm stuck. Or even unsure what i want is possible. What i wantI have...
by comcordriro Explorer in Splunk Search 09-15-2022
0 2
0
2
weddi_eddy
I currently have a lookup that contains two columns. Hostnames and Location.  I can use the following formula to sear...
by weddi_eddy Explorer in Splunk Search 09-15-2022
0 2
0
2
kimsej
I am running a query where I'm trying to calculate the difference between the start and end times a request travels t...
by kimsej Explorer in Splunk Search 09-15-2022
0 1
0
1
kimsej
I have a query that does a group by, which allows the sum(diff) column to be calculated. [search] | stats sum(diff) b...
by kimsej Explorer in Splunk Search 09-15-2022
0 1
0
1
splunkzilla
Hello all!  Newbie here so please forgive the ignorance in advance! I have a search: index="zscaler" reason="Reputati...
by splunkzilla Explorer in Splunk Search 09-15-2022
0 3
0
3
ABSplunker93
I have a stats table with output in the below format: Device                          Timestamp        Action some va...
by ABSplunker93 Engager in Splunk Search 09-15-2022
0 1
0
1
KyleMcDougall
Hello, How do I combine two searches in an eval command? In the example below, I'm trying to create a value for "foll...
by KyleMcDougall Path Finder in Splunk Search 09-15-2022
0 1
0
1
LogUx
Hello Splunker !! XBY-123-UTB SVV-123-TBU I want extract to trim the value according Condition  :  for XBY-123-UTB I ...
by LogUx Motivator in Splunk Search 09-15-2022
0 5
0
5
trentsnowbarger
a customer reports intermittent connectivity issues to the internet, a website, what have you. Our instance of Splunk...
by trentsnowbarger New Member in Splunk Search 09-15-2022
0 1
0
1
nathanluke1986
Hello, I am trying to list fields I have selected into a single field to display in a dashboard. Currently trying   |...
by nathanluke1986 Engager in Splunk Search 09-15-2022
0 1
0
1
lou_sierra
I have looked at the join documentation, but I am getting a little lost in translation.What I am trying to accomplish...
by lou_sierra New Member in Splunk Search 09-15-2022
0 1
0
1
Basavaraj
Reference : https://zpettry.com/cybersecurity/splunk-queries-data-exfiltration/ | bucket _time span=1d | stats sum(by...
by Basavaraj Engager in Splunk Search 09-15-2022
0 1
0
1
evallja
Hello everyone, Please, I need to extract a field named product (with its value in bold) from the below Message field...
by evallja Path Finder in Splunk Search 09-15-2022
0 1
0
1
Phil_S
Hi All, I have a search which parses key/value pairs out of a strangely-formatted XML field.         rex field=xml "<...
by Phil_S Engager in Splunk Search 09-15-2022
0 4
0
4
Sanjana
Hello , I have data like below. I need to frame a query such that I can calculate number of desync for each rate-pari...
by Sanjana Explorer in Splunk Search 09-14-2022
0 7
0
7
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...