Splunk Search

Splunk Search
Community Activity
joey19154
Hello everyone,   I'm looking to make a simple search form with a few text inputs and a drop-down box to search for f...
by joey19154 New Member in Splunk Search 06-12-2022
0 1
0
1
Gauri001
Q): How to detect ransomware using Splunk?,  please give query also to create alert in ransomware, 
by Gauri001 Engager in Splunk Search 06-11-2022
0 2
0
2
Mayukh
Hello, I have a HEC with events like the following:   { "Log": { "Status": "Ordered", "Platform":...
by Mayukh Engager in Splunk Search 06-10-2022
0 2
0
2
cbcadmin
Hello! I just set up Splunk Enterprise on-prem this morning and I was able to connect our Cisco Meraki firewall to Sp...
by cbcadmin Loves-to-Learn Lots in Splunk Search 06-10-2022
0 6
0
6
Steve_A200
Hi, I am struggling with an SPL.  I am trying to create a report which lists the Online status of specific Site/locat...
by Steve_A200 Path Finder in Splunk Search 06-10-2022
0 4
0
4
aa0
Hi,I am a newbie in Splunk. I have to write a splunk query to get the status_code count for error(status range 300 an...
by aa0 Path Finder in Splunk Search 06-10-2022
0 6
0
6
rajs115
Hi,   I need help with below query search. Below is the sample logs. Logs: Conatainer: dev_test_clusterCountRequired:...
by rajs115 Path Finder in Splunk Search 06-10-2022
0 2
0
2
denissotoacc
I have the following json event: { "tags": [ {"key":"Name","value":"Damian"}, {"key":"Age","value":34}, ...
by denissotoacc Path Finder in Splunk Search 06-10-2022
0 1
0
1
thebankitgui
Good Afternoon! I have a search (code example #1) that looks for the EventData_Xml field looking at programs installe...
by thebankitgui Path Finder in Splunk Search 06-10-2022
0 5
0
5
splunkfriend123
Hi Team,   Is there any way to pull last 1000 searches performed on a particular index along with the user who perfor...
by splunkfriend123 Engager in Splunk Search 06-10-2022
0 1
0
1
actionabledata
Do the resulting files from a "dump" command have a TTL? I think they must since the files I created on Friday no lon...
by actionabledata Path Finder in Splunk Search 06-10-2022
0 2
0
2
aikn061
Hi Guys, I already have a query below that gives me a table similar to the one on bottom.  I was wondering if there i...
by aikn061 Explorer in Splunk Search 06-09-2022
0 2
0
2
spitchika
Hi,I want to store earliest and latest times of my search in variables to use them in further operations. But I am un...
by spitchika Path Finder in Splunk Search 06-09-2022
0 1
0
1
xoamanda12xo
Basically my data is formatted as a message and then info in parentheses on the right. Example:" LL - VPN Activity (l...
by xoamanda12xo Explorer in Splunk Search 06-09-2022
0 1
0
1
ashidhingra
| eval hours= if (day="Monday", hours=(a+b), hours) So basically if day=monday, i wants hours to add up a+b
by ashidhingra Path Finder in Splunk Search 06-09-2022
0 3
0
3
trent6
I have a collection of log files that I am trying to parse. Quick summary:From Apache/Tomcat using logback I don't ha...
by trent6 Explorer in Splunk Search 06-09-2022
0 1
0
1
ositaumeozulu
hello team please i need solution to these question i have three column fields, startDate,endDate, ARTstartDate. i wa...
by ositaumeozulu Explorer in Splunk Search 06-09-2022
0 4
0
4
Julia1231
Hi,  I have several model id: 12310, 12320, 12330. If the suffixes = "10", "20", "30", I define the typemachine accor...
by Julia1231 Communicator in Splunk Search 06-09-2022
0 2
0
2
KyleMcDougall
Hi all, I've been working on this query for the last few days and still can't seem to crack it. (Appreciate the perso...
by KyleMcDougall Path Finder in Splunk Search 06-09-2022
0 1
0
1
rstankus
Our IIS logs contain a "time_taken" field which indicates the number of milliseconds each event took. I'd like to use...
by rstankus Explorer in Splunk Search 06-09-2022
0 12
0
12
bolopez
I want to create an alert that pops up when the events match at least 500 times the same source IP address, same dest...
by bolopez Explorer in Splunk Search 06-09-2022
0 2
0
2
mihir_hardas
  I need a list of only those jobName which start with letter a though m - anycase. The below does not work index=log...
by mihir_hardas Explorer in Splunk Search 06-09-2022
0 2
0
2
CarbonCriterium
What is the is the best approach to creating a field that shows the number of incomplete requests in a given period o...
by CarbonCriterium Path Finder in Splunk Search 06-09-2022
0 3
0
3
kpavan
Hi All, I have logs which is from db_inputs/custom_script where owner not indexing custom time field as _time and the...
by kpavan Path Finder in Splunk Search 06-09-2022
0 2
0
2
johanhakim
Hi, I have a custom Python script developed in Splunk where it will translate Chinese characters to English. The cust...
by johanhakim Explorer in Splunk Search 06-09-2022
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...