Splunk Search

Splunk Search
Community Activity
renanxavier
Dear allI have a search that returns the description of the windows event and I would like to extract the IP address ...
by renanxavier Explorer in Splunk Search 08-24-2022
0 5
0
5
Russ
Disclaimer - Fairly New to SplunkI'm stuck on building a table for a dashboard.I would like to list a table of Comput...
by Russ Explorer in Splunk Search 08-24-2022
0 4
0
4
avneet26
I have a table in which one of the columns has logs like below 2022-08-21 23:00:00.877 Warning: PooledThread::run: N4...
by avneet26 Engager in Splunk Search 08-24-2022
0 4
0
4
risingflight143
Hi All i have an exchange onprem distribution list, lets say dl@mydomain.com i want to know how many emails are trigg...
by risingflight143 Explorer in Splunk Search 08-23-2022
0 1
0
1
dzyfer
 Hi, how do I display my Status Indicator with dynamic colors and icons in a Trellis layout? | eval status=case(statu...
by dzyfer Path Finder in Splunk Search 08-23-2022
0 0
0
0
jwalthour
I'm wanting to do something like this: index=main sourcetype=access_combined [ search index=myidx sourcetype=oncall ...
by jwalthour Communicator in Splunk Search 08-23-2022
0 8
0
8
jcaron9999a
I have a lookup file called ipaddress.csv.  The column title in the file is ipaddress.  I want to search my logs for ...
by jcaron9999a Explorer in Splunk Search 08-23-2022
0 2
0
2
Fields29
How do I fix low disk space in enterprise indexer. Please comment back on how to fix.
by Fields29 New Member in Splunk Search 08-23-2022
0 1
0
1
marceldera
Filed name = pluginText<plugin_output>Information about this scan : Nessus version : 10.3.0 Nessus build : 20080 Plug...
by marceldera Explorer in Splunk Search 08-23-2022
0 2
0
2
TBH0
I have a situation where I'm attempting to display a count on a dashboard of the amount of items in a lookup file who...
by TBH0 Explorer in Splunk Search 08-23-2022
0 6
0
6
yangadounb
I have the record like this:     _time  id status  1        x     yes 1         x     no 2          x      yes 1     ...
by yangadounb Explorer in Splunk Search 08-23-2022
0 4
0
4
siemengr
I'm trying to exclude specific src_ip addresses from the results of a firewall query (example below). The query compl...
by siemengr Engager in Splunk Search 08-23-2022
0 3
0
3
jalo23
I can't figure out the correct syntax for the second eval statement or what else I should use instead of eval. I know...
by jalo23 Explorer in Splunk Search 08-23-2022
0 2
0
2
fperalde
Hello, Here is my data! Basically everything is in the same table, however I separated to better explain my problem! ...
by fperalde Engager in Splunk Search 08-23-2022
0 1
0
1
mistydennis
Hi all - I am trying to take one lookup and limit its results with another lookup.  I can kinda get it to work with m...
by mistydennis Communicator in Splunk Search 08-23-2022
0 3
0
3
xiyangyang
I found follow logs in _audit logs.  The user who run this search cannot access internal logs, so I assume the underl...
by xiyangyang Path Finder in Splunk Search 08-23-2022
0 1
0
1
brad_
Hello, the request below works perfectly thanks to the help found on this forum.Now I would like to automate this req...
by brad_ Engager in Splunk Search 08-23-2022
0 14
0
14
Veeru
index=A host="bd*" OR host="p*" source="/apps/logs/*" | bin _time span="30m" | stats values(point) as point values(pr...
by Veeru Path Finder in Splunk Search 08-23-2022
0 6
0
6
FoxMike
Hi all, Is there a possibility that when you've made a query with the hits you want, that also the next x amounts of ...
by FoxMike Engager in Splunk Search 08-23-2022
0 2
0
2
SplunkDash
Hello, is there any way we can extract fields from this sample data, any help will be highly appreciated. Thank you! ...
by SplunkDash Motivator in Splunk Search 08-23-2022
0 6
0
6
masoud
It is sort of like multiplying the set with itself and getting a subset in mathematical term.   my data is sth like t...
by masoud Explorer in Splunk Search 08-23-2022
0 6
0
6
tushki6391
Hi everyone,   StateIDAPP_timeINFOABCCar19/08/22 19:51INFOABCCar19/08/22 19:52INFODEFCar20/08/22 19:53INFOZZZBook30/0...
by tushki6391 New Member in Splunk Search 08-22-2022
0 3
0
3
firstname
Given the below example events: Initial event: [stuff] apple.bean.carrot2donut.57.egg.fish(10) max:311 min 15 avg 101...
by firstname Explorer in Splunk Search 08-22-2022
0 4
0
4
Sanz
Hi All,I am trying to view a lookup file that has the sharing set on this app only from another app than it is define...
by Sanz Explorer in Splunk Search 08-22-2022
0 3
0
3
sgtlongwell
I have a kvstore like below populated with about 1mil rows.  _keynamecount1count2calculated_number1calculated_number2...
by sgtlongwell New Member in Splunk Search 08-22-2022
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...