Splunk Search

Splunk Search
Community Activity
kirangurram
Hello Folks , I have json data in below format. I am looking for a best solution to table list of Keys which can be e...
by kirangurram Explorer in Splunk Search 08-18-2022
0 2
0
2
Veeru
Hello Splunk team,I am trying for a logic to disable the alerts in the particular app while I disable maintenance mod...
by Veeru Path Finder in Splunk Search 08-18-2022
0 3
0
3
user_303_user
I'm having issues properly extracting all the fields I'm after from some json.  The logs are from a script that dumps...
by user_303_user Observer in Splunk Search 08-18-2022
0 4
0
4
neerajs_81
Hi All, Can someone pls assist me in extracting the different Recipients out this nested Json ?  This is from O365 lo...
by neerajs_81 Builder in Splunk Search 08-18-2022
0 13
0
13
SPLKwame28
Creating A dashboard to log any New Firewall rule that has been committed to Panorama. How do i go about this? Any as...
by SPLKwame28 Engager in Splunk Search 08-18-2022
0 6
0
6
majilan1
Hi Every one, Is it possible to modify a portion of CSV file in inputlookup? Cheers.
by majilan1 Path Finder in Splunk Search 08-17-2022
0 5
0
5
yk010123
I have the following queries      query 1 : index1 .... | table _time uniqueID query 2 : index2 .... | table _time...
by yk010123 Path Finder in Splunk Search 08-17-2022
0 7
0
7
hmohta
Hi all, I am new at Splunk and trying to evaluate this query.  I have some accounts, dates(week starting) and number ...
by hmohta Path Finder in Splunk Search 08-17-2022
0 6
0
6
firstname
Currently I have used a similar query to what is below to plot data on a 24 hour graph. index=mock_index source=mock_...
by firstname Explorer in Splunk Search 08-17-2022
0 1
0
1
Nickbshaw
Currently using a manual verification of non US logins:sourcetype="o365:management:activity"| iplocation ActorIpAddre...
by Nickbshaw Observer in Splunk Search 08-17-2022
0 1
0
1
kteng2024
From Documentation: To verify how often the forwarder is hitting this limit, check the forwarder's metrics.log. (Loo...
by kteng2024 Path Finder in Splunk Search 08-17-2022
0 3
0
3
wanda619
Hi community, I have to calculate previous week result, based on that, I calculate Percent difference with this weeks...
by wanda619 Path Finder in Splunk Search 08-17-2022
0 5
0
5
Mattjj
Hi all,I have a lookup instance_list, which I'm trying to use to filter my flow logs to only show the logs with the s...
by Mattjj Explorer in Splunk Search 08-17-2022
0 2
0
2
HarperWCurran
Hi, i am doing a search and noticing that i am getting 200% on the fields i troubleshooted and used this line at the ...
by HarperWCurran Engager in Splunk Search 08-17-2022
0 2
0
2
hyeongn
Hello, I'm a Korean beginner, Splunkerindex=my sourcetype=my2 sernder_ip=my3 | table _time | stats count by _time | s...
by hyeongn Engager in Splunk Search 08-17-2022
0 2
0
2
Siva04
Hi, This is my first time starting a discussion. Please pardon my mistakes. So I am trying to perform a search where ...
by Siva04 Engager in Splunk Search 08-17-2022
0 5
0
5
Woodpecker
Hi,Can someone please help me with a query to find Long DNS sessions?  
by Woodpecker Path Finder in Splunk Search 08-16-2022
0 1
0
1
phamxuantung
Hello, When I ran       index=_audit NOT user="splunk-system-user" |stats count by action       I find that accelerat...
by phamxuantung Communicator in Splunk Search 08-16-2022
0 1
0
1
djoobbani
Dear splunk community: So i am using the following chart command: <base search> | chart count by url_path, http_statu...
by djoobbani Path Finder in Splunk Search 08-16-2022
0 3
0
3
firstname
My search looks similar to the one below: index=mock_index source=mock_source.log param1 param2 param3 | rex field=_r...
by firstname Explorer in Splunk Search 08-16-2022
0 1
0
1
haiweichen
The values I need are located in the field "msg". Each msg contains 3 records. I run this query and get the result as...
by haiweichen Explorer in Splunk Search 08-16-2022
0 2
0
2
staymini
The special characters of the result of my question is converted to HTML Name and output like " and &lt.What are...
by staymini Explorer in Splunk Search 08-16-2022
0 3
0
3
Clecimar
Guys, can you help me ? I need to know the elapsed time between this two fields: CREATED_TS: 20220816182818.215CURREN...
by Clecimar Explorer in Splunk Search 08-16-2022
0 1
0
1
kalebh
Hi,I've run into an issue while working with the Splunk Rest API, specifically when trying to leverage extracted fiel...
by kalebh New Member in Splunk Search 08-16-2022
0 0
0
0
kymenope
New to Splunk.  Have been tasked with finding a query to audit access to specific files.  Any ideas?
by kymenope Explorer in Splunk Search 08-16-2022
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors