Splunk Search

Splunk Search
Community Activity
seekay
Greetings, I've been asked to provide log data for a specific form that has been accessed over a certain time period....
by seekay Engager in Splunk Search 09-01-2022
0 2
0
2
Edwin1471
Hi, REX command rex mode=sed to remove quotation marks and numbers inside of them   OUTPUT file "19214132.IKU" copied...
by Edwin1471 Path Finder in Splunk Search 09-01-2022
0 2
0
2
marceldera
I have 2 dates first_found: 2022-08-23T21:08:54.808Z last_fixed:2022-08-30T12:56:58.860Z I am trying to calculate the...
by marceldera Explorer in Splunk Search 09-01-2022
0 3
0
3
Anesthet1ze
Hello,    I need to create a single value panel that displays a countdown from today's date until a target date, how ...
by Anesthet1ze Explorer in Splunk Search 09-01-2022
0 4
0
4
djoobbani
Dear Splunk community: So i have the following SPL that has been running fine for the last week or so however, all of...
by djoobbani Path Finder in Splunk Search 09-01-2022
0 2
0
2
XOJ
I have some searches that do not appear to be enhancing properly using the asset_lookup_by_str lookup table. In this ...
by XOJ Path Finder in Splunk Search 09-01-2022
0 0
0
0
ZubairBMW
Hi All If I apply a limits.conf for subsearch - maxout and searchresults - maxresultsrow for an app im deploying, wil...
by ZubairBMW Engager in Splunk Search 09-01-2022
0 2
0
2
metylkinandrey
Good afternoon!I have six Heartbeat messages coming from the system. All messages from the chain are connected by one...
by metylkinandrey Communicator in Splunk Search 09-01-2022
0 1
0
1
time2200
Case Scenario: Dashboard A is clicked, thus sending a token whose value is hostname ($hostnameToken$) to Dashboard B....
by time2200 Explorer in Splunk Search 09-01-2022
0 6
0
6
dzyfer
Hi, I have a search that uses the chart command to split by 2 fields, such that the results are shown below. The data...
by dzyfer Path Finder in Splunk Search 09-01-2022
0 6
0
6
egonstep
Hello all, I have a report that searches for differents time range like Year to now, Month to now, Last 5 days and l...
by egonstep Path Finder in Splunk Search 08-31-2022
1 5
1
5
BenTreeser
Hello,what' the best way to compare averages between two non-adjacent time periods. I have bunch of api call events w...
by BenTreeser Explorer in Splunk Search 08-31-2022
0 2
0
2
user2023rd
Picking up my first project for SOAR detections. Asking if anyone knows groups or sites that helped them when they we...
by user2023rd Engager in Splunk Search 08-31-2022
1 1
1
1
fperalde
Hello I have a little problem with Splunk! I have a table that basically contains data in the following way number ...
by fperalde Engager in Splunk Search 08-31-2022
0 2
0
2
Akdollar
Hello One of my company's firewall ingest more logs every tuesday to splunk which makes us go over the 10G limit per ...
by Akdollar New Member in Splunk Search 08-31-2022
0 1
0
1
jalo23
Is there a more elegant way to do this? New to using rex & I can’t seem to strip out the multiple parentheses and sla...
by jalo23 Explorer in Splunk Search 08-31-2022
0 2
0
2
amanda_dg
Hi everyone,  When I search for multiple items from multiselect, it is not working. I can search for "ALL" or one ite...
by amanda_dg Engager in Splunk Search 08-31-2022
0 0
0
0
olbapito
Hi! I have a log like this eventtype=000111 msg=malicious srcip=11.11.22.22 eventtype=123 msg=traffic srcip=11.11.22....
by olbapito New Member in Splunk Search 08-30-2022
0 3
0
3
mdyunusraza
Hi,I want to create a table from the sample log file entry by computing the field names based on the entries defined ...
by mdyunusraza Observer in Splunk Search 08-30-2022
0 5
0
5
baljkastr
I have this event:(pool-4-thread-1 18a68b34-f4af-4940-9339-6201b5004bb8) (********): do_SMSGW (Request) : &from=TULBU...
by baljkastr Engager in Splunk Search 08-30-2022
0 1
0
1
SS1
My Query:  index=test sourcetype=true AND private AND beta |rex field=_raw "\[private]\s(?<category>\S+\s+\S+\s+\S+)"...
by SS1 Path Finder in Splunk Search 08-30-2022
0 3
0
3
toernerg
I have the following 2 logs DRT.log:  This consists of the following log lines:   {"date_time":"20220823-13:11:11.622...
by toernerg Observer in Splunk Search 08-30-2022
0 1
0
1
ichesla1111
I want to use the map command to add the total event times for each day during the time interval from 6am-6pm.For eac...
by ichesla1111 Path Finder in Splunk Search 08-30-2022
0 2
0
2
IndyJones1345
Hello all, I know this has been asked many different ways but, I cant seem to get the search correct. I am attempting...
by IndyJones1345 Loves-to-Learn in Splunk Search 08-30-2022
0 1
0
1
spl_unker
Hi Splunkers ,   Im trying to build a dashboard to capture all the triggered alerts with some custom actions to be ap...
by spl_unker Explorer in Splunk Search 08-30-2022
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors