Splunk Search

Splunk Search
Community Activity
jbanAtSplunk
Hi, Just curios if this is possible as I have interesting challenge. So, I have extracted fields, key=value id0=0000,...
by jbanAtSplunk Communicator in Splunk Search 09-12-2022
0 4
0
4
abdullah_osail
What are the steps to retrieve frozen data and make it searchable again? Can I specify specific data (date) to be ret...
by abdullah_osail New Member in Splunk Search 09-12-2022
0 3
0
3
Skysurfer
Can someone please help me with this.  I have looking for a query so that if count is less than 0 change it to 0, oth...
by Skysurfer Explorer in Splunk Search 09-11-2022
0 3
0
3
Taruchit
Hi All,I have a lookup table table1.csv with following fields: -indexsourcetypehostlast_seenI have a custom index: id...
by Taruchit Contributor in Splunk Search 09-11-2022
0 13
0
13
jbanAtSplunk
Hi, I have a log that will dynamically add "fields" to log record based on some logic. It's syslog begging + payload ...
by jbanAtSplunk Communicator in Splunk Search 09-11-2022
0 2
0
2
richnavis88
I believe there is no report Splunk cannot produce, but I'm having trouble with this one. I'd like to generate a repo...
by richnavis88 Explorer in Splunk Search 09-10-2022
0 3
0
3
HathMH
I am not sure how to word this so I'm going to bring it as an example. We have 3 firewalls that send logs for ingesti...
by HathMH Path Finder in Splunk Search 09-09-2022
0 1
0
1
amit2312
Hi, I am new to splunk, this might have asked and answered but didn't get the answer when i searched it. here is my q...
by amit2312 Explorer in Splunk Search 09-09-2022
0 3
0
3
jwhughes58
I'm working with the "Jira Issue Input Add-on" and in Jira we have created custom fields.  Splunk ingests issues and ...
by jwhughes58 Contributor in Splunk Search 09-09-2022
0 1
0
1
marco_massari11
Hi,I have similar authentication logs as below:LOG 1:03362 auth: ST1-CMDR: User 'my-global\admin' logged in from IP1 ...
by marco_massari11 Communicator in Splunk Search 09-09-2022
0 1
0
1
kgiri253
As we can see below the two events contain multiple results. But when I try to export it as csv all these events get ...
by kgiri253 Explorer in Splunk Search 09-09-2022
0 3
0
3
darphboubou
HI,   I would like to get the servers who use only ntlmv1.   So in a first search I using this command       index="w...
by darphboubou Explorer in Splunk Search 09-09-2022
0 8
0
8
abhishekbhasin
Need to extract P302 P1 P2 with a single regular ex I build (?<Par>P[1-9][0-9]*) but when I run this in splunk it onl...
by abhishekbhasin Explorer in Splunk Search 09-09-2022
0 5
0
5
Bobmc
Hello, I'm a bit new to Splunk and I'm trying to run a query that shows me users in Active directory that are still e...
by Bobmc Observer in Splunk Search 09-09-2022
0 6
0
6
SimonSchoppel
I want to display the number of sent data in certain time in the dashboard. I think the best way is with "Single Valu...
by SimonSchoppel Explorer in Splunk Search 09-09-2022
0 3
0
3
Toki
I'm using lookup but don't know how to do a partial match instead of an exact match Example: 10.20.30.40 is in the li...
by Toki Explorer in Splunk Search 09-09-2022
0 4
0
4
mahesh27
Hi all, I have few queries to be modified using tstats:I am new to splunk, please let me know whether these queries c...
by mahesh27 Communicator in Splunk Search 09-08-2022
0 15
0
15
zacksoft
How do I get the  job-execution start time and job execution endtime of my  query as output of the query.index = some...
by zacksoft Contributor in Splunk Search 09-08-2022
0 5
0
5
bro_coded101
My current search is: `index`| search source="Main Source" | fields identifier, status_label| chart count over identi...
by bro_coded101 Loves-to-Learn Lots in Splunk Search 09-08-2022
0 3
0
3
mark_cet
We have alert events coming into Splunk & Splunk ITSI that we open Service Now incidents for, but depending on the ev...
by mark_cet Path Finder in Splunk Search 09-08-2022
0 4
0
4
KH
I'm extremely new to Splunk and finding learning SPL very frustrating. I'm trying to look for windows log on events/ ...
by KH Engager in Splunk Search 09-08-2022
0 2
0
2
Finn
I have encountered an issue with the foreach command on mv-fields.When I execute my search, Splunk says: "Error in 'e...
by Finn Explorer in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
What is the difference between now() and _time?
by smanojkumar Contributor in Splunk Search 09-08-2022
0 2
0
2
Dharani
Hi, Below is the example for raw log: 20220906T23:43:58+03:00#0115dummyvalue.com#01110.111.169.11:51868#01110.45.38.1...
by Dharani Path Finder in Splunk Search 09-08-2022
0 2
0
2
smanojkumar
Start_Time=092659Start_Date=20220908My requirement is to find the job amount many jobs that runs longer than a day, t...
by smanojkumar Contributor in Splunk Search 09-08-2022
0 3
0
3
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...