Splunk Search

Splunk Search
Community Activity
marco_massari11
Hi,I have similar authentication logs as below:LOG 1:03362 auth: ST1-CMDR: User 'my-global\admin' logged in from IP1 ...
by marco_massari11 Communicator in Splunk Search 09-09-2022
0 1
0
1
kgiri253
As we can see below the two events contain multiple results. But when I try to export it as csv all these events get ...
by kgiri253 Explorer in Splunk Search 09-09-2022
0 3
0
3
darphboubou
HI,   I would like to get the servers who use only ntlmv1.   So in a first search I using this command       index="w...
by darphboubou Explorer in Splunk Search 09-09-2022
0 8
0
8
abhishekbhasin
Need to extract P302 P1 P2 with a single regular ex I build (?<Par>P[1-9][0-9]*) but when I run this in splunk it onl...
by abhishekbhasin Explorer in Splunk Search 09-09-2022
0 5
0
5
Bobmc
Hello, I'm a bit new to Splunk and I'm trying to run a query that shows me users in Active directory that are still e...
by Bobmc Observer in Splunk Search 09-09-2022
0 6
0
6
SimonSchoppel
I want to display the number of sent data in certain time in the dashboard. I think the best way is with "Single Valu...
by SimonSchoppel Explorer in Splunk Search 09-09-2022
0 3
0
3
Toki
I'm using lookup but don't know how to do a partial match instead of an exact match Example: 10.20.30.40 is in the li...
by Toki Explorer in Splunk Search 09-09-2022
0 4
0
4
mahesh27
Hi all, I have few queries to be modified using tstats:I am new to splunk, please let me know whether these queries c...
by mahesh27 Communicator in Splunk Search 09-08-2022
0 15
0
15
zacksoft
How do I get the  job-execution start time and job execution endtime of my  query as output of the query.index = some...
by zacksoft Contributor in Splunk Search 09-08-2022
0 5
0
5
bro_coded101
My current search is: `index`| search source="Main Source" | fields identifier, status_label| chart count over identi...
by bro_coded101 Loves-to-Learn Lots in Splunk Search 09-08-2022
0 3
0
3
mark_cet
We have alert events coming into Splunk & Splunk ITSI that we open Service Now incidents for, but depending on the ev...
by mark_cet Path Finder in Splunk Search 09-08-2022
0 4
0
4
KH
I'm extremely new to Splunk and finding learning SPL very frustrating. I'm trying to look for windows log on events/ ...
by KH Engager in Splunk Search 09-08-2022
0 2
0
2
Finn
I have encountered an issue with the foreach command on mv-fields.When I execute my search, Splunk says: "Error in 'e...
by Finn Explorer in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
What is the difference between now() and _time?
by smanojkumar Contributor in Splunk Search 09-08-2022
0 2
0
2
Dharani
Hi, Below is the example for raw log: 20220906T23:43:58+03:00#0115dummyvalue.com#01110.111.169.11:51868#01110.45.38.1...
by Dharani Path Finder in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
Start_Time=092659Start_Date=20220908My requirement is to find the job amount many jobs that runs longer than a day, t...
by smanojkumar Contributor in Splunk Search 09-08-2022
0 3
0
3
responsys_cm
I'm trying to make the Linux audit daemon data play nice. One of the challenges is that a particular action can trig...
by responsys_cm Builder in Splunk Search 09-08-2022
0 2
0
2
mydog8it
I have a comma delimited multivalue field that contains text and a digit in each value pair that I am trying to find ...
by mydog8it Builder in Splunk Search 09-08-2022
1 14
1
14
CybSec1
Hello,I have logs like : samples={'xxxxxxx' : {'111' :{'222' :{'333'}}}}{'yyyyyyy'{'444'}}{'zzzzzzz'}I need to take a...
by CybSec1 New Member in Splunk Search 09-08-2022
0 2
0
2
FGAnders
Hi, Is there any way to exclude any events that has more than one value of a field  from end result.    index=X statu...
by FGAnders Explorer in Splunk Search 09-08-2022
0 2
0
2
PepposChris
Hello,   I've been using SPLUNK search REST API for a while now and just today i've run into the following issue.   W...
by PepposChris Observer in Splunk Search 09-07-2022
0 4
0
4
kpavan
Hi All, Am looking for query to have multiple earliest days  index=something sourcetype=something earliest=-7d@d late...
by kpavan Path Finder in Splunk Search 09-07-2022
0 3
0
3
jhcbazinga95
Hey all, Can someone help me out with a JSON related question! Many many thanks!  I have a JSON arrays field in this...
by jhcbazinga95 Loves-to-Learn Everything in Splunk Search 09-07-2022
0 3
0
3
SS1
Hi, I have 2 searches where the dedup strategy is different, i want to combine the 2 searches but need help with dedu...
by SS1 Path Finder in Splunk Search 09-07-2022
0 1
0
1
janderhungrige
Hi,I want to count the numbers of containers per company. Each data point has a container id, company id, and much mo...
by janderhungrige Observer in Splunk Search 09-07-2022
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors