Splunk Search

Splunk Search
Community Activity
user_303_user
I'm having issues properly extracting all the fields I'm after from some json.  The logs are from a script that dumps...
by user_303_user Observer in Splunk Search 08-18-2022
0 4
0
4
neerajs_81
Hi All, Can someone pls assist me in extracting the different Recipients out this nested Json ?  This is from O365 lo...
by neerajs_81 Builder in Splunk Search 08-18-2022
0 13
0
13
SPLKwame28
Creating A dashboard to log any New Firewall rule that has been committed to Panorama. How do i go about this? Any as...
by SPLKwame28 Engager in Splunk Search 08-18-2022
0 6
0
6
majilan1
Hi Every one, Is it possible to modify a portion of CSV file in inputlookup? Cheers.
by majilan1 Path Finder in Splunk Search 08-17-2022
0 5
0
5
yk010123
I have the following queries      query 1 : index1 .... | table _time uniqueID query 2 : index2 .... | table _time...
by yk010123 Path Finder in Splunk Search 08-17-2022
0 7
0
7
hmohta
Hi all, I am new at Splunk and trying to evaluate this query.  I have some accounts, dates(week starting) and number ...
by hmohta Path Finder in Splunk Search 08-17-2022
0 6
0
6
firstname
Currently I have used a similar query to what is below to plot data on a 24 hour graph. index=mock_index source=mock_...
by firstname Explorer in Splunk Search 08-17-2022
0 1
0
1
Nickbshaw
Currently using a manual verification of non US logins:sourcetype="o365:management:activity"| iplocation ActorIpAddre...
by Nickbshaw Observer in Splunk Search 08-17-2022
0 1
0
1
kteng2024
From Documentation: To verify how often the forwarder is hitting this limit, check the forwarder's metrics.log. (Loo...
by kteng2024 Path Finder in Splunk Search 08-17-2022
0 3
0
3
wanda619
Hi community, I have to calculate previous week result, based on that, I calculate Percent difference with this weeks...
by wanda619 Path Finder in Splunk Search 08-17-2022
0 5
0
5
Mattjj
Hi all,I have a lookup instance_list, which I'm trying to use to filter my flow logs to only show the logs with the s...
by Mattjj Explorer in Splunk Search 08-17-2022
0 2
0
2
HarperWCurran
Hi, i am doing a search and noticing that i am getting 200% on the fields i troubleshooted and used this line at the ...
by HarperWCurran Engager in Splunk Search 08-17-2022
0 2
0
2
hyeongn
Hello, I'm a Korean beginner, Splunkerindex=my sourcetype=my2 sernder_ip=my3 | table _time | stats count by _time | s...
by hyeongn Engager in Splunk Search 08-17-2022
0 2
0
2
Siva04
Hi, This is my first time starting a discussion. Please pardon my mistakes. So I am trying to perform a search where ...
by Siva04 Engager in Splunk Search 08-17-2022
0 5
0
5
Woodpecker
Hi,Can someone please help me with a query to find Long DNS sessions?  
by Woodpecker Path Finder in Splunk Search 08-16-2022
0 1
0
1
phamxuantung
Hello, When I ran       index=_audit NOT user="splunk-system-user" |stats count by action       I find that accelerat...
by phamxuantung Communicator in Splunk Search 08-16-2022
0 1
0
1
djoobbani
Dear splunk community: So i am using the following chart command: <base search> | chart count by url_path, http_statu...
by djoobbani Path Finder in Splunk Search 08-16-2022
0 3
0
3
firstname
My search looks similar to the one below: index=mock_index source=mock_source.log param1 param2 param3 | rex field=_r...
by firstname Explorer in Splunk Search 08-16-2022
0 1
0
1
haiweichen
The values I need are located in the field "msg". Each msg contains 3 records. I run this query and get the result as...
by haiweichen Explorer in Splunk Search 08-16-2022
0 2
0
2
staymini
The special characters of the result of my question is converted to HTML Name and output like " and &lt.What are...
by staymini Explorer in Splunk Search 08-16-2022
0 3
0
3
Clecimar
Guys, can you help me ? I need to know the elapsed time between this two fields: CREATED_TS: 20220816182818.215CURREN...
by Clecimar Explorer in Splunk Search 08-16-2022
0 1
0
1
kalebh
Hi,I've run into an issue while working with the Splunk Rest API, specifically when trying to leverage extracted fiel...
by kalebh New Member in Splunk Search 08-16-2022
0 0
0
0
kymenope
New to Splunk.  Have been tasked with finding a query to audit access to specific files.  Any ideas?
by kymenope Explorer in Splunk Search 08-16-2022
0 1
0
1
wanda619
Hi community, I am stuck on a problem where i have to calculate percentage and Percent Difference.    I have 3 column...
by wanda619 Path Finder in Splunk Search 08-16-2022
0 4
0
4
Mick_OBrien
I have two REX strings that work independently... ^\S+\s(?<microService>\S+).* [supplied by previous SPLUNK answer] ....
by Mick_OBrien Path Finder in Splunk Search 08-16-2022
0 5
0
5
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors