Splunk Search

Splunk Search
Community Activity
nord_nikon
Hi everyone,   basically I am trying to count how many unique customers I had in a period and that worked well with d...
by nord_nikon Engager in Splunk Search 07-12-2022
0 2
0
2
vjsplunk
Is there any reason why syntax highlighting is not working by default for splunk logs?. While clicking on the Syntax ...
by vjsplunk Loves-to-Learn Everything in Splunk Search 07-11-2022
0 1
0
1
bsanjeeva
Hi, When I run a search against an index in smart/verbose mode, I am getting the below error with zero results, "Some...
by bsanjeeva Explorer in Splunk Search 07-11-2022
0 0
0
0
bharath999
I have a URL as below 1.aa/bb/cc/dd 2.nbcn/hbd/hvhd/hbxn   Need to regular expression to get the below output 1.aa/bb...
by bharath999 Observer in Splunk Search 07-11-2022
0 3
0
3
NizanCohen
Hi all.I want to create an alert for hosts file modification.Found the build in one here on the forums but I would li...
by NizanCohen Explorer in Splunk Search 07-11-2022
0 4
0
4
mcscjlf
I don't have a ton of experience with Splunk yet but I've been asked to find API endpoints (which appear to be in our...
by mcscjlf Explorer in Splunk Search 07-11-2022
0 3
0
3
tlmayes
I have a query that must search 9 weeks of data, and then applies a filter against a single field (dv_opened_at) look...
by tlmayes Contributor in Splunk Search 07-11-2022
0 5
0
5
elmadi_fares
index=idx_rdap source="*f5*" "*member*" "RO1B4-0JLSM4000S" "/Common/pool_d2i_*gkrgkl" | rex field=member "\/Common\/(...
by elmadi_fares Loves-to-Learn Everything in Splunk Search 07-11-2022
0 3
0
3
morgantay96
I have read a lot of different threads and docs but still having trouble pulling what I need out of the below JSON. E...
by morgantay96 Path Finder in Splunk Search 07-10-2022
0 9
0
9
Yadukrishnan
Hi all, I am currently configuring Splunk Enterprise Security for Alerts. I have a doubt in the implementation of thi...
by Yadukrishnan Explorer in Splunk Search 07-09-2022
0 1
0
1
rodolfotva
Hi, I know this is a hot topic and there is answers everywhere, but i couldn't figure out by my self what to do. Sudd...
by rodolfotva Engager in Splunk Search 07-09-2022
0 2
0
2
splunkcol
I need to get the list of the IPs that have generated the most outgoing traffic. When the query is generated I find t...
by splunkcol Builder in Splunk Search 07-09-2022
0 2
0
2
reverse
How can i find difference b/w each MV Item? So far i was able to do only one difference ...
by reverse Contributor in Splunk Search 07-08-2022
1 9
1
9
mebra1
Hello all, I have an event that looks similar to the following: field_A="US", field_B="true", field_C="AB/CD,XYZ, <>D...
by mebra1 Loves-to-Learn in Splunk Search 07-08-2022
0 8
0
8
user33
Hi,  I have two event fields with the same name "timestamp". I just want to display (in stats) the "timestamp" field ...
by user33 Path Finder in Splunk Search 07-08-2022
0 2
0
2
jimish
In logs there are multiple lines printed like below  and I want to print all of them in a table but my search query o...
by jimish Explorer in Splunk Search 07-08-2022
0 2
0
2
Rithekakan
Hi All,I have this report    My requirement is only show in table those event that do not have the Plugin Name = "TL...
by Rithekakan Path Finder in Splunk Search 07-08-2022
0 1
0
1
meliaolsen
Hello folks, I'm trying to write a drill-down search for a correlation search in Enterprise Security, and I'm having ...
by meliaolsen Loves-to-Learn Lots in Splunk Search 07-08-2022
0 2
0
2
Abhineet
Base query: index=jenkins* teamcenter |search event_tag=job_event |search build_url=*TC_Active* |where isnotnull(job_...
by Abhineet Loves-to-Learn Everything in Splunk Search 07-08-2022
0 7
0
7
Rithekakan
host="SPL-SH-DC" sourcetype="ABCSW"......| search "Plugin Name" != "TLS Version 1.1 Protocol Deprecated" AND Port != ...
by Rithekakan Path Finder in Splunk Search 07-08-2022
0 8
0
8
splunk219783
I can't wrap my head around how to do this search.  It's like I need an array or variable.Example Data:HostnameStorag...
by splunk219783 Path Finder in Splunk Search 07-08-2022
0 8
0
8
ashidhingra
| eval RouteLatency = if (Name="ABC" AND HTTP="*https://.net.*.com*" , bckLatency ,RouteLatency )
by ashidhingra Path Finder in Splunk Search 07-08-2022
0 2
0
2
Veeru
I have the raw data where i need to convert the time in raw data to particular time zoneexample:if the time contains ...
by Veeru Path Finder in Splunk Search 07-08-2022
0 10
0
10
jhilton90
So I'm trying to extract a field called "secureToken=tokenvalue" from our akamai logs. However when I try to extract ...
by jhilton90 Path Finder in Splunk Search 07-08-2022
0 9
0
9
cwheeler33
How do I list machines that do not match my search?"if" my script runs, a message is sent to splunk. The script runs ...
by cwheeler33 Explorer in Splunk Search 07-07-2022
0 2
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors