Splunk Search

Splunk Search
Community Activity
stuwoodward
Hi All, I am new to splunk and not a developer so first up apologies for any poor syntax or coding practices. What am...
by stuwoodward Engager in Splunk Search 06-23-2022
0 2
0
2
raffaelecervino
Hi, I'm doing a project and I've installed Splunk Trial Enterprise on a server and Universal Forwarder on other three...
by raffaelecervino Engager in Splunk Search 06-23-2022
0 4
0
4
Ishan
I have the below query, I need the scatter point visualization for this. time on the x axis and the build duration  o...
by Ishan Loves-to-Learn in Splunk Search 06-23-2022
0 0
0
0
Splunk4
Hi Everyone, I have a field called as TriggeredMessage coming in an event in Splunk and I want to extract the short d...
by Splunk4 Explorer in Splunk Search 06-23-2022
1 14
1
14
rebecalopes241
I have this query and I want to count how many logins were made by id, like if a person logged in 3 times I just want...
by rebecalopes241 New Member in Splunk Search 06-22-2022
0 1
0
1
hantaliu
I have an event which is constructed like the following:   { name: string, time: string, duration: string, ...
by hantaliu Loves-to-Learn Lots in Splunk Search 06-22-2022
0 1
0
1
Seawheels51
Hello gurus I'm trying to return a percentage from the results of sub searches. The value User_count and Device_count...
by Seawheels51 Path Finder in Splunk Search 06-22-2022
0 2
0
2
corti77
Hi, I went to the search of my own app I created a extracted field using the wizard.  Once created, I go to Settings-...
by corti77 Contributor in Splunk Search 06-22-2022
0 5
0
5
deepakgarg1373
this is my query  earliest=-15m latest=now index=** host="*" LOG_LEVEL=ERROR OR LOG_LEVEL=FATAL OR logLevel=ERROR OR ...
by deepakgarg1373 Loves-to-Learn Lots in Splunk Search 06-22-2022
0 15
0
15
nilbak88
Hello Splunkers,I need help with Network Security Group flow logs where  each of the tuples should be a single event ...
by nilbak88 Explorer in Splunk Search 06-22-2022
0 6
0
6
boxmetal
Hi, I need to join data on my 2 source A and B on the fields "Workitems_URL" and "Work Item URL"  In source B, there ...
by boxmetal Path Finder in Splunk Search 06-22-2022
0 3
0
3
neerajs_81
Hi All,  Below are 2 sets of raw events from my DDOS appliance.  The sets are separated based on the eventID field.  ...
by neerajs_81 Builder in Splunk Search 06-22-2022
0 4
0
4
DEAD_BEEF
My search shows each website category and the number of times each category was visited. What I would like to create...
by DEAD_BEEF Builder in Splunk Search 06-22-2022
0 3
0
3
Michael_Scott
Hi everyone. I am a new user to Splunk. Recently, I have met some trouble with trying to extract a certain message ou...
by Michael_Scott Explorer in Splunk Search 06-21-2022
0 4
0
4
ashidhingra
How can i create an alarm when a location goes down?  index=internal sourcetype=abc| timechart span=5m count(linecoun...
by ashidhingra Path Finder in Splunk Search 06-21-2022
0 3
0
3
Callum_f
I am using the query below to gather all the request IDs of when an error occurs when calling an api. It provides a l...
by Callum_f Explorer in Splunk Search 06-21-2022
0 6
0
6
Callum_f
I have a sub query that gives the output example below  Sub Query [ search index=prod_diamond sourcetype=CloudWatch_...
by Callum_f Explorer in Splunk Search 06-21-2022
0 3
0
3
HansNL
Hi, am working on a lookup in a lookup. i have the following search: index=* source="*WinEventLog:Security" EventCode...
by HansNL Loves-to-Learn in Splunk Search 06-21-2022
0 5
0
5
bdunstan
Hi,Is there a way to target which application lookup you want to use?Lets say there are 3 applications, A, B and C,  ...
by bdunstan Path Finder in Splunk Search 06-21-2022
0 2
0
2
kc_prane
Hi Team -  Need your expertise in Regex. The below is the rawlog i need to extract the Date and time  the only unique...
by kc_prane Communicator in Splunk Search 06-21-2022
0 7
0
7
BLACKBEARCO
We are about to open up a Splunk ticket for this issue, but figured we'd check with the community first. Problem: The...
by BLACKBEARCO Explorer in Splunk Search 06-21-2022
0 3
0
3
mistydennis
When I add this case statement to my search, all results for Severity are "Other". What did I miss?| eval Severity=ca...
by mistydennis Communicator in Splunk Search 06-21-2022
0 10
0
10
jmrtm44
Hello, using Splunk version 8.1.3.Would you know why there’s a Server Error when we input the below search expression...
by jmrtm44 Observer in Splunk Search 06-21-2022
0 3
0
3
paritoshs24
My search is  like  this index = idx source = src data_stamp = A  field1 = *lol* | table Field2   --> This generates ...
by paritoshs24 Path Finder in Splunk Search 06-21-2022
0 6
0
6
kiran007
Need to pass the result of query1 to as a input string for the second query. For the First query i'm getting output(x...
by kiran007 Explorer in Splunk Search 06-21-2022
0 4
0
4
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors