Splunk Search

Splunk Search
Community Activity
nilbak88
Hello Splunkers,I need help with Network Security Group flow logs where  each of the tuples should be a single event ...
by nilbak88 Explorer in Splunk Search 06-22-2022
0 6
0
6
boxmetal
Hi, I need to join data on my 2 source A and B on the fields "Workitems_URL" and "Work Item URL"  In source B, there ...
by boxmetal Path Finder in Splunk Search 06-22-2022
0 3
0
3
neerajs_81
Hi All,  Below are 2 sets of raw events from my DDOS appliance.  The sets are separated based on the eventID field.  ...
by neerajs_81 Builder in Splunk Search 06-22-2022
0 4
0
4
DEAD_BEEF
My search shows each website category and the number of times each category was visited. What I would like to create...
by DEAD_BEEF Builder in Splunk Search 06-22-2022
0 3
0
3
Michael_Scott
Hi everyone. I am a new user to Splunk. Recently, I have met some trouble with trying to extract a certain message ou...
by Michael_Scott Explorer in Splunk Search 06-21-2022
0 4
0
4
ashidhingra
How can i create an alarm when a location goes down?  index=internal sourcetype=abc| timechart span=5m count(linecoun...
by ashidhingra Path Finder in Splunk Search 06-21-2022
0 3
0
3
Callum_f
I am using the query below to gather all the request IDs of when an error occurs when calling an api. It provides a l...
by Callum_f Explorer in Splunk Search 06-21-2022
0 6
0
6
Callum_f
I have a sub query that gives the output example below  Sub Query [ search index=prod_diamond sourcetype=CloudWatch_...
by Callum_f Explorer in Splunk Search 06-21-2022
0 3
0
3
HansNL
Hi, am working on a lookup in a lookup. i have the following search: index=* source="*WinEventLog:Security" EventCode...
by HansNL Loves-to-Learn in Splunk Search 06-21-2022
0 5
0
5
bdunstan
Hi,Is there a way to target which application lookup you want to use?Lets say there are 3 applications, A, B and C,  ...
by bdunstan Path Finder in Splunk Search 06-21-2022
0 2
0
2
kc_prane
Hi Team -  Need your expertise in Regex. The below is the rawlog i need to extract the Date and time  the only unique...
by kc_prane Communicator in Splunk Search 06-21-2022
0 7
0
7
BLACKBEARCO
We are about to open up a Splunk ticket for this issue, but figured we'd check with the community first. Problem: The...
by BLACKBEARCO Explorer in Splunk Search 06-21-2022
0 3
0
3
mistydennis
When I add this case statement to my search, all results for Severity are "Other". What did I miss?| eval Severity=ca...
by mistydennis Communicator in Splunk Search 06-21-2022
0 10
0
10
jmrtm44
Hello, using Splunk version 8.1.3.Would you know why there’s a Server Error when we input the below search expression...
by jmrtm44 Observer in Splunk Search 06-21-2022
0 3
0
3
paritoshs24
My search is  like  this index = idx source = src data_stamp = A  field1 = *lol* | table Field2   --> This generates ...
by paritoshs24 Path Finder in Splunk Search 06-21-2022
0 6
0
6
kiran007
Need to pass the result of query1 to as a input string for the second query. For the First query i'm getting output(x...
by kiran007 Explorer in Splunk Search 06-21-2022
0 4
0
4
_pravin
Hi Community,   I have two separate Splunk installs: one is the 8.1.0 version and another one is 8.2.5 The older vers...
by _pravin Contributor in Splunk Search 06-21-2022
0 8
0
8
SCSC
I created this data table by "mvappend" command. dont have "_time" column and have only 3months records. MONTH itemA ...
by SCSC Explorer in Splunk Search 06-20-2022
0 4
0
4
hungln9
Hi Team,  I have query, result returned for "dateofBirth" filed is "yyyymmdd" like "19911021", can I format the value...
by hungln9 Explorer in Splunk Search 06-20-2022
0 1
0
1
jomon_ng
Hi, I tried to filter events on version 2.30.0 based on v1.110.0 configuration, but it failed to dropped events in ve...
by jomon_ng Observer in Splunk Search 06-20-2022
0 0
0
0
morgantay96
Hi All, I have a mv field with a bunch of different values. I want to learn how to pull specific values based on stri...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 2
0
2
morgantay96
Hello I am a bit confused here but I have a search that runs and creates a multivalue  field called "tags{}.name". Th...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 4
0
4
jpfrancetic
Hi Splunk Community, I am having a problem with saved searches not saving the full results. I have a saved search tha...
by jpfrancetic Path Finder in Splunk Search 06-20-2022
0 2
0
2
nikhilmalkari18
index = "abc" required_field = "xx" | table date - gives me a single string in the table. How can I store this string...
by nikhilmalkari18 New Member in Splunk Search 06-20-2022
0 4
0
4
ashidhingra
| where like(RouteCode, "50%") AND !like(RouteCode, "503%")I am trying to show Routecode 501,2, -- anyother not 503.
by ashidhingra Path Finder in Splunk Search 06-20-2022
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...