Splunk Search

Splunk Search
Community Activity
smaran06
Hi Team, I have time in below two  formats and I want to convert them to minutes. How can I do this Format 1 1 Hour10...
by smaran06 Path Finder in Splunk Search 07-18-2022
0 4
0
4
robertlynch2020
Hi In a MultiSelect is there any way to us a wild character? My Data XYC_123 EOD_1234 EOD_23232 EOD_343434 aassss_...
by robertlynch2020 Influencer in Splunk Search 07-18-2022
0 3
0
3
AlanMoen
I've got a JSON array I ingest that I want to extract certain fields from to save into a lookup table. Here's an exam...
by AlanMoen Explorer in Splunk Search 07-18-2022
0 6
0
6
waldenwang9966
Is there a way to show currency symbol after the value? Like $393.26
by waldenwang9966 Loves-to-Learn in Splunk Search 07-18-2022
0 5
0
5
jhamot23
I'm trying to run a query to figure out the top 10 src_ip's along with their top 10 urls visited. When I try the belo...
by jhamot23 Engager in Splunk Search 07-18-2022
0 4
0
4
tayvionp
I'm currently building a query that reports the top 10 urls of the top 10 users. Although my current query works, I w...
by tayvionp Explorer in Splunk Search 07-18-2022
0 4
0
4
Minasdad
Within the tenable:sc:vuln sourcetype there is a particular field "PluginText" that has a value for hardware serial n...
by Minasdad Path Finder in Splunk Search 07-18-2022
0 3
0
3
Edwin1471
Hi, how can I modify x-axis in order to display date only for each column.  query | eval finish_time_epoch = strftim...
by Edwin1471 Path Finder in Splunk Search 07-18-2022
0 1
0
1
darphboubou
Hello, I have a lookup on which we have two columns, one with the computer name and the other with the OS version. Wh...
by darphboubou Explorer in Splunk Search 07-18-2022
0 10
0
10
sambitmahantaes
I am not able to find the host field information for the events coming from a particular machine.  This is related to...
by sambitmahantaes Explorer in Splunk Search 07-18-2022
0 7
0
7
wealot
Hi all, I have events coming in that have multivalue fields, but not always the same fields are multivalue. I want al...
by wealot Explorer in Splunk Search 07-18-2022
0 2
0
2
registration9
We have a FIG (fluentD/InfluxDB/Grafana) setup in which we want to change the IG part to Splunk. We have several das...
by registration9 New Member in Splunk Search 07-17-2022
0 2
0
2
cxm0u4e
Let's say I have a multivalue fieldA and a fieldB. I know you can do something like "| where field=value" in a search...
by cxm0u4e Engager in Splunk Search 07-17-2022
0 2
0
2
Ashwin3
Hi team, As per my requirement, on changing a particular form element [Token 1] , a set of other tokens [Token2,Token...
by Ashwin3 Engager in Splunk Search 07-17-2022
0 2
0
2
JR_Akaviri
I'm trying to find any new MFA factors(DUO) used by any user in the past X days in order to create an alert.  As an e...
by JR_Akaviri Engager in Splunk Search 07-17-2022
0 1
0
1
Minasdad
file1.csv and file2.csv with a common field of "Tests". Wanting to compare File2 field "Tests" against file1.csv fiel...
by Minasdad Path Finder in Splunk Search 07-17-2022
0 2
0
2
Gzee
Hi, Novice splunker here. My search only extracts 1st 10-digit number and my data contains atleast 4 or more  10-digi...
by Gzee Engager in Splunk Search 07-17-2022
0 1
0
1
DPOIRE
Good Day,I need help to calculate the time difference for field "@timestamp" containing time format 2022-07-14T09:05:...
by DPOIRE Path Finder in Splunk Search 07-15-2022
0 16
0
16
yshen
I need to first issue an alert for overheat temperature 24 hours in advance for the affected locations, for their for...
by yshen Communicator in Splunk Search 07-15-2022
1 3
1
3
Veeru
index=a host="b" source="0*_R_S_C_ajf" OWNER=dw*|eval ODate=strptime(ODATE,"%Y%m%d")|eval ODATE=strftime(ODate,"%Y-%m...
by Veeru Path Finder in Splunk Search 07-15-2022
0 6
0
6
ggilmore1
I have been trying to extract a field to list domain admins from AD logs. The logs have all the admins starting with ...
by ggilmore1 Explorer in Splunk Search 07-14-2022
0 8
0
8
csahoo
index="*dockerlogs*" source="*gps-request-processor-dev*" OR source="*gps-external-processor-dev*" OR source="*gps-ar...
by csahoo Explorer in Splunk Search 07-14-2022
0 1
0
1
mjones414
I have a scenario where I am analyzing the format of a given string to determine what the name of the format is (e.g....
by mjones414 Contributor in Splunk Search 07-14-2022
0 3
0
3
florianhh
Hi Splunkers, I try to get a new internal field "_application" added to certain events. So i added a new field via th...
by florianhh Explorer in Splunk Search 07-14-2022
0 3
0
3
willspk
Hey everyone, I've got all our firewall logs going into separate index. When I perform a search just using the index ...
by willspk Engager in Splunk Search 07-14-2022
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors