Splunk Search

Splunk Search
Community Activity
wanda619
Hi community, I have to calculate previous week result, based on that, I calculate Percent difference with this weeks...
by wanda619 Path Finder in Splunk Search 08-17-2022
0 5
0
5
Mattjj
Hi all,I have a lookup instance_list, which I'm trying to use to filter my flow logs to only show the logs with the s...
by Mattjj Explorer in Splunk Search 08-17-2022
0 2
0
2
HarperWCurran
Hi, i am doing a search and noticing that i am getting 200% on the fields i troubleshooted and used this line at the ...
by HarperWCurran Engager in Splunk Search 08-17-2022
0 2
0
2
hyeongn
Hello, I'm a Korean beginner, Splunkerindex=my sourcetype=my2 sernder_ip=my3 | table _time | stats count by _time | s...
by hyeongn Engager in Splunk Search 08-17-2022
0 2
0
2
Siva04
Hi, This is my first time starting a discussion. Please pardon my mistakes. So I am trying to perform a search where ...
by Siva04 Engager in Splunk Search 08-17-2022
0 5
0
5
Woodpecker
Hi,Can someone please help me with a query to find Long DNS sessions?  
by Woodpecker Path Finder in Splunk Search 08-16-2022
0 1
0
1
phamxuantung
Hello, When I ran       index=_audit NOT user="splunk-system-user" |stats count by action       I find that accelerat...
by phamxuantung Communicator in Splunk Search 08-16-2022
0 1
0
1
djoobbani
Dear splunk community: So i am using the following chart command: <base search> | chart count by url_path, http_statu...
by djoobbani Path Finder in Splunk Search 08-16-2022
0 3
0
3
firstname
My search looks similar to the one below: index=mock_index source=mock_source.log param1 param2 param3 | rex field=_r...
by firstname Explorer in Splunk Search 08-16-2022
0 1
0
1
haiweichen
The values I need are located in the field "msg". Each msg contains 3 records. I run this query and get the result as...
by haiweichen Explorer in Splunk Search 08-16-2022
0 2
0
2
staymini
The special characters of the result of my question is converted to HTML Name and output like " and &lt.What are...
by staymini Explorer in Splunk Search 08-16-2022
0 3
0
3
Clecimar
Guys, can you help me ? I need to know the elapsed time between this two fields: CREATED_TS: 20220816182818.215CURREN...
by Clecimar Explorer in Splunk Search 08-16-2022
0 1
0
1
kalebh
Hi,I've run into an issue while working with the Splunk Rest API, specifically when trying to leverage extracted fiel...
by kalebh New Member in Splunk Search 08-16-2022
0 0
0
0
kymenope
New to Splunk.  Have been tasked with finding a query to audit access to specific files.  Any ideas?
by kymenope Explorer in Splunk Search 08-16-2022
0 1
0
1
wanda619
Hi community, I am stuck on a problem where i have to calculate percentage and Percent Difference.    I have 3 column...
by wanda619 Path Finder in Splunk Search 08-16-2022
0 4
0
4
Mick_OBrien
I have two REX strings that work independently... ^\S+\s(?<microService>\S+).* [supplied by previous SPLUNK answer] ....
by Mick_OBrien Path Finder in Splunk Search 08-16-2022
0 5
0
5
vivekbs
section for calculation_window_telemetry in /apps/SA-ITOA/default/savedsearches.conf:  """ search = | inputlookup cal...
by vivekbs Splunk Employee Splunk Employee in Splunk Search 08-16-2022
0 0
0
0
prithwirajbose
I have Splunk logs stored in this format (2 example dataset below):        {"org":"myorg","environment":"prod","proxy...
by prithwirajbose New Member in Splunk Search 08-16-2022
0 1
0
1
bosseres1
Hello everyone, asking your help with my subsearch query. I need to find events in index="1", take from it Logon_ID, ...
by bosseres1 Engager in Splunk Search 08-16-2022
0 7
0
7
splunkhadi_480
i have the following two entries   TimeEvent8/16/221:46:22.592 PM2022/08/16 13:46:22.592154:P_GUI_SERV06 :pbaho3 : 98...
by splunkhadi_480 Engager in Splunk Search 08-16-2022
0 2
0
2
rpecka
I would like to run a timechart query that ends with `| timechart span=1h distinct_count(thing) by other_thing` The p...
by rpecka Explorer in Splunk Search 08-16-2022
0 3
0
3
cybersej
H, I want to take rules on security essentials as a list.I m try to search in app but I cant get rule list.There r ma...
by cybersej Observer in Splunk Search 08-15-2022
0 3
0
3
mark_groenveld
I have a key:value for db names but need only the first part. Example CurrentDBNAME : db001_inst1:schemanamexyxOrDBNA...
by mark_groenveld Path Finder in Splunk Search 08-15-2022
0 4
0
4
rockzers
how to access splunk using python script when i run this code i get an error import splunklib.client as client servic...
by rockzers Path Finder in Splunk Search 08-15-2022
0 1
0
1
amey2407
We have output of 2 queries in terms of disk usage. One is from DELL and one is rom Huawei index. Dell Query:  |`clus...
by amey2407 Splunk Employee Splunk Employee in Splunk Search 08-15-2022
0 4
0
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors