Splunk Search

Splunk Search
Community Activity
kteng2024
From Documentation: To verify how often the forwarder is hitting this limit, check the forwarder's metrics.log. (Loo...
by kteng2024 Path Finder in Splunk Search 08-17-2022
0 3
0
3
wanda619
Hi community, I have to calculate previous week result, based on that, I calculate Percent difference with this weeks...
by wanda619 Path Finder in Splunk Search 08-17-2022
0 5
0
5
Mattjj
Hi all,I have a lookup instance_list, which I'm trying to use to filter my flow logs to only show the logs with the s...
by Mattjj Explorer in Splunk Search 08-17-2022
0 2
0
2
HarperWCurran
Hi, i am doing a search and noticing that i am getting 200% on the fields i troubleshooted and used this line at the ...
by HarperWCurran Engager in Splunk Search 08-17-2022
0 2
0
2
hyeongn
Hello, I'm a Korean beginner, Splunkerindex=my sourcetype=my2 sernder_ip=my3 | table _time | stats count by _time | s...
by hyeongn Engager in Splunk Search 08-17-2022
0 2
0
2
Siva04
Hi, This is my first time starting a discussion. Please pardon my mistakes. So I am trying to perform a search where ...
by Siva04 Engager in Splunk Search 08-17-2022
0 5
0
5
Woodpecker
Hi,Can someone please help me with a query to find Long DNS sessions?  
by Woodpecker Path Finder in Splunk Search 08-16-2022
0 1
0
1
phamxuantung
Hello, When I ran       index=_audit NOT user="splunk-system-user" |stats count by action       I find that accelerat...
by phamxuantung Communicator in Splunk Search 08-16-2022
0 1
0
1
djoobbani
Dear splunk community: So i am using the following chart command: <base search> | chart count by url_path, http_statu...
by djoobbani Path Finder in Splunk Search 08-16-2022
0 3
0
3
firstname
My search looks similar to the one below: index=mock_index source=mock_source.log param1 param2 param3 | rex field=_r...
by firstname Explorer in Splunk Search 08-16-2022
0 1
0
1
haiweichen
The values I need are located in the field "msg". Each msg contains 3 records. I run this query and get the result as...
by haiweichen Explorer in Splunk Search 08-16-2022
0 2
0
2
staymini
The special characters of the result of my question is converted to HTML Name and output like " and &lt.What are...
by staymini Explorer in Splunk Search 08-16-2022
0 3
0
3
Clecimar
Guys, can you help me ? I need to know the elapsed time between this two fields: CREATED_TS: 20220816182818.215CURREN...
by Clecimar Explorer in Splunk Search 08-16-2022
0 1
0
1
kalebh
Hi,I've run into an issue while working with the Splunk Rest API, specifically when trying to leverage extracted fiel...
by kalebh New Member in Splunk Search 08-16-2022
0 0
0
0
kymenope
New to Splunk.  Have been tasked with finding a query to audit access to specific files.  Any ideas?
by kymenope Explorer in Splunk Search 08-16-2022
0 1
0
1
wanda619
Hi community, I am stuck on a problem where i have to calculate percentage and Percent Difference.    I have 3 column...
by wanda619 Path Finder in Splunk Search 08-16-2022
0 4
0
4
Mick_OBrien
I have two REX strings that work independently... ^\S+\s(?<microService>\S+).* [supplied by previous SPLUNK answer] ....
by Mick_OBrien Path Finder in Splunk Search 08-16-2022
0 5
0
5
vivekbs
section for calculation_window_telemetry in /apps/SA-ITOA/default/savedsearches.conf:  """ search = | inputlookup cal...
by vivekbs Splunk Employee Splunk Employee in Splunk Search 08-16-2022
0 0
0
0
prithwirajbose
I have Splunk logs stored in this format (2 example dataset below):        {"org":"myorg","environment":"prod","proxy...
by prithwirajbose New Member in Splunk Search 08-16-2022
0 1
0
1
bosseres1
Hello everyone, asking your help with my subsearch query. I need to find events in index="1", take from it Logon_ID, ...
by bosseres1 Engager in Splunk Search 08-16-2022
0 7
0
7
splunkhadi_480
i have the following two entries   TimeEvent8/16/221:46:22.592 PM2022/08/16 13:46:22.592154:P_GUI_SERV06 :pbaho3 : 98...
by splunkhadi_480 Engager in Splunk Search 08-16-2022
0 2
0
2
rpecka
I would like to run a timechart query that ends with `| timechart span=1h distinct_count(thing) by other_thing` The p...
by rpecka Explorer in Splunk Search 08-16-2022
0 3
0
3
cybersej
H, I want to take rules on security essentials as a list.I m try to search in app but I cant get rule list.There r ma...
by cybersej Observer in Splunk Search 08-15-2022
0 3
0
3
mark_groenveld
I have a key:value for db names but need only the first part. Example CurrentDBNAME : db001_inst1:schemanamexyxOrDBNA...
by mark_groenveld Path Finder in Splunk Search 08-15-2022
0 4
0
4
rockzers
how to access splunk using python script when i run this code i get an error import splunklib.client as client servic...
by rockzers Path Finder in Splunk Search 08-15-2022
0 1
0
1
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...