Splunk Search

Splunk Search
Community Activity
egonstep
Hello all, I have a report that searches for differents time range like Year to now, Month to now, Last 5 days and l...
by egonstep Path Finder in Splunk Search 08-31-2022
1 5
1
5
BenTreeser
Hello,what' the best way to compare averages between two non-adjacent time periods. I have bunch of api call events w...
by BenTreeser Explorer in Splunk Search 08-31-2022
0 2
0
2
user2023rd
Picking up my first project for SOAR detections. Asking if anyone knows groups or sites that helped them when they we...
by user2023rd Engager in Splunk Search 08-31-2022
1 1
1
1
fperalde
Hello I have a little problem with Splunk! I have a table that basically contains data in the following way number ...
by fperalde Engager in Splunk Search 08-31-2022
0 2
0
2
Akdollar
Hello One of my company's firewall ingest more logs every tuesday to splunk which makes us go over the 10G limit per ...
by Akdollar New Member in Splunk Search 08-31-2022
0 1
0
1
jalo23
Is there a more elegant way to do this? New to using rex & I can’t seem to strip out the multiple parentheses and sla...
by jalo23 Explorer in Splunk Search 08-31-2022
0 2
0
2
amanda_dg
Hi everyone,  When I search for multiple items from multiselect, it is not working. I can search for "ALL" or one ite...
by amanda_dg Engager in Splunk Search 08-31-2022
0 0
0
0
olbapito
Hi! I have a log like this eventtype=000111 msg=malicious srcip=11.11.22.22 eventtype=123 msg=traffic srcip=11.11.22....
by olbapito New Member in Splunk Search 08-30-2022
0 3
0
3
mdyunusraza
Hi,I want to create a table from the sample log file entry by computing the field names based on the entries defined ...
by mdyunusraza Observer in Splunk Search 08-30-2022
0 5
0
5
baljkastr
I have this event:(pool-4-thread-1 18a68b34-f4af-4940-9339-6201b5004bb8) (********): do_SMSGW (Request) : &from=TULBU...
by baljkastr Engager in Splunk Search 08-30-2022
0 1
0
1
SS1
My Query:  index=test sourcetype=true AND private AND beta |rex field=_raw "\[private]\s(?<category>\S+\s+\S+\s+\S+)"...
by SS1 Path Finder in Splunk Search 08-30-2022
0 3
0
3
toernerg
I have the following 2 logs DRT.log:  This consists of the following log lines:   {"date_time":"20220823-13:11:11.622...
by toernerg Observer in Splunk Search 08-30-2022
0 1
0
1
ichesla1111
I want to use the map command to add the total event times for each day during the time interval from 6am-6pm.For eac...
by ichesla1111 Path Finder in Splunk Search 08-30-2022
0 2
0
2
IndyJones1345
Hello all, I know this has been asked many different ways but, I cant seem to get the search correct. I am attempting...
by IndyJones1345 Loves-to-Learn in Splunk Search 08-30-2022
0 1
0
1
spl_unker
Hi Splunkers ,   Im trying to build a dashboard to capture all the triggered alerts with some custom actions to be ap...
by spl_unker Explorer in Splunk Search 08-30-2022
0 1
0
1
metylkinandrey
Good afternoon!I receive messages from systems on splunk, several messages from one system line up in a message chain...
by metylkinandrey Communicator in Splunk Search 08-30-2022
0 1
0
1
ShamGowda
I need the count and count % to be reflected in Available and Not Available line with the value. Appreciate if i get ...
by ShamGowda Loves-to-Learn Lots in Splunk Search 08-30-2022
0 1
0
1
SajarKumarPat
I have a message thread, these messages are coming on splunk.The chain consists of ten different messages: five messa...
by SajarKumarPat New Member in Splunk Search 08-30-2022
0 3
0
3
Edwin1471
Hi,How can I make both of these panels be the same height ? 
by Edwin1471 Path Finder in Splunk Search 08-30-2022
0 1
0
1
vamsi354
Hi Experts , i want to show Column1 timestamp selected as default in Date/Time Range From not sure what i am doing wr...
by vamsi354 Explorer in Splunk Search 08-30-2022
0 2
0
2
kimberlytrayson
My data looks as follows: host col2 ---- ---- A SUCCESS A ERROR B ERROR B SUCCESS B SUCCESS C ERROR Here ...
by kimberlytrayson Path Finder in Splunk Search 08-30-2022
0 1
0
1
m_khatibo88
Hi Community,   I have these alerts on EDR and I want to create a correlation search to show these alerts on the Splu...
by m_khatibo88 New Member in Splunk Search 08-30-2022
0 1
0
1
Khuzair81
status=Auto, Manual car= BMW, Honda, Audi index * | stats count(status) as Total by car Is there anyway I can get the...
by Khuzair81 Path Finder in Splunk Search 08-29-2022
0 2
0
2
mcristinzio
How do list multiple sources in a query: sourcetype=xml source="/wealthsuite/tti/current/*"?
by mcristinzio New Member in Splunk Search 08-29-2022
0 3
0
3
sh254087
I want to change the title text on the tabs from, for example, "Login|Splunk" or "Dashboards | Splunk 7.1.2" to a tex...
by sh254087 Communicator in Splunk Search 08-29-2022
0 4
0
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors