Splunk Search

Splunk Search
Community Activity
aamirulh
Hi, im currently facing problem where splunk can detect all my files in directory but when doing searching, splunk ca...
by aamirulh New Member in Splunk Search 06-06-2022
0 1
0
1
nikolaevnz
Hello Team, Splunkers,  I am working on a correlation search and need to use a regex expression to strip all text bef...
by nikolaevnz Engager in Splunk Search 06-06-2022
0 2
0
2
biju_babu
Could you please let me know how to use an evaluated field in search command index=main sourcetype="access_combined" ...
by biju_babu Explorer in Splunk Search 06-06-2022
0 6
0
6
mjones414
I'm in a situation where by sourcetype, I'm already having a nested JSON array broken into 2 fields: DeviceProperties...
by mjones414 Contributor in Splunk Search 06-06-2022
0 2
0
2
biju_babu
Hi  I have a dropdown in my dashboard studio which has some static values like TokenName: appName Display NameValueAp...
by biju_babu Explorer in Splunk Search 06-06-2022
0 4
0
4
mldavis195
I have some data that's coming in as follows:   "data": { "a": 100, "b": 200 } "data": { "a": 50, "c": 75 } ...      ...
by mldavis195 Explorer in Splunk Search 06-06-2022
0 3
0
3
rmalghan
I have a search criteria with extraction, It seems to be extracting the value. But it's showing up in it's own column...
by rmalghan Explorer in Splunk Search 06-06-2022
0 5
0
5
wmuselle
I have created a collection in app/local/collections.conf a matching lookup in app/local/transforms.conf I have 5 key...
by wmuselle Path Finder in Splunk Search 06-06-2022
0 2
0
2
juancamiloll
Hi everyone I am currently getting logs from microsoft 365 and one of its panels shows the impossible simultaneous lo...
by juancamiloll Explorer in Splunk Search 06-05-2022
0 4
0
4
Veeru
HelloGood Day!I have the events in the raw data where i want to extract the drive information  into few field and con...
by Veeru Path Finder in Splunk Search 06-05-2022
0 3
0
3
shrek
Lets just say I have multiple events like this: names John Sam Todd favorite_colors Blue Yellow Green Each event mig...
by shrek Engager in Splunk Search 06-04-2022
0 2
0
2
jpolcari
This one seems pretty straight forward, but I haven't been able to find an answer anywhere. I'm looking to calculate ...
by jpolcari Communicator in Splunk Search 06-04-2022
0 6
0
6
thedonaldblake
Newbie in Splunk here. How do I extract the value zzz@zzz.com(at the end of the below payload) in a new field named "...
by thedonaldblake Engager in Splunk Search 06-03-2022
0 1
0
1
umeshchandra
Hi  I am using Cisco WSA proxy and i need help on creating a usecase for Proxy avoindance/bypass  can you please help...
by umeshchandra Observer in Splunk Search 06-03-2022
0 0
0
0
ositaumeozulu
please i will be glad to get answer to this query | eval  InT = if(((lastpickupdate + DaysOfARVRefil  + 28) > IIT), "...
by ositaumeozulu Explorer in Splunk Search 06-03-2022
0 3
0
3
Kk
Hi All, I have been working on the luhn algorithm to validate the credit card. For that, I have used the below link q...
by Kk Path Finder in Splunk Search 06-03-2022
0 2
0
2
Italy1358
I need help to append this rest command to my query. The problem is that the rest command is adding to the first row ...
by Italy1358 Path Finder in Splunk Search 06-03-2022
0 2
0
2
kelz
Hi Splunkers,I was wondering if this is possible on tstats command. Get the dynamic value from savedsearch result or ...
by kelz Explorer in Splunk Search 06-03-2022
0 2
0
2
spinnerdog
I have this Query that produces two multi value fields, keys and values.  What i need to do is pair each entry in the...
by spinnerdog Explorer in Splunk Search 06-03-2022
0 3
0
3
edwinmae
Hi, I try to calculate the duration I have extracted 2 fields, start_time and end_time -- I believe both times shoul...
by edwinmae Path Finder in Splunk Search 06-03-2022
0 2
0
2
yaharga
I have a field called query that's like so:(index="abc" OR index="def") (host="ghi" OR host="jkl") (sourcetype="mno" ...
by yaharga Path Finder in Splunk Search 06-03-2022
0 7
0
7
KMoryson
Hi, I am working on a way to find an orphaned asset based on asset inventory I have in a lookup, which looks somethin...
by KMoryson Explorer in Splunk Search 06-03-2022
0 4
0
4
Sasti
Hi All,      I'm trying to extract the username from the _raw field using regex, how do I extract the username. The u...
by Sasti Engager in Splunk Search 06-03-2022
0 6
0
6
michael92956
Hopefully I can explain this in a way where it can be understood and fingers crossed answered.  I have a search that ...
by michael92956 New Member in Splunk Search 06-03-2022
0 1
0
1
sashib
Hi I need to extract only name values (first word value eg:james) from the below Name filed I tried with  rex field=N...
by sashib Explorer in Splunk Search 06-03-2022
0 4
0
4
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors