Splunk Search

Splunk Search
Community Activity
LizAndy123
So I have an IndexIndex= xxxxxx "Stopping iteration"I have the rex for getting the unique IdEvent Sample : Stopping i...
by LizAndy123 Path Finder in Splunk Search 01-27-2025
0 6
0
6
CrossWordKnower
Hi Splunkers! The issue I am having is regarding different results from alerts when some condition is met, compared t...
by CrossWordKnower Explorer in Splunk Search 01-27-2025
0 6
0
6
RGullur
Hi Community, please help me how to extract BOLD/underlines value from below string:[2025-01-22 13:33:33,899] INFO Se...
by RGullur New Member in Splunk Search 01-26-2025
0 5
0
5
welcomerrr
Hello,I am building a splunk app , where I want to have my own custom aggregate function for stats command. Below is ...
by welcomerrr Observer in Splunk Search 01-26-2025
0 6
0
6
BrianLam
I'm calling the API from BTP IS and want to get the result of an alert that I created from before. My alert name is P...
by BrianLam Engager in Splunk Search 01-26-2025
0 3
0
3
Jimenez
Hi all,I have the following issue. I have a table A col1col2AaaBbbCaa And a table BcolAcolBaaFYIbbLOL I need to add t...
by Jimenez Explorer in Splunk Search 01-26-2025
0 6
0
6
nkavouris
I have a base query which yield the field result, result can be either "Pass" or "Fail"Sample query result is attache...
by nkavouris Path Finder in Splunk Search 01-25-2025
0 1
0
1
bochmann
Has anyone run into the interesting effect that isnum() thinks that "NaN" is a number? So isnum("NaN") is true "NaN" ...
by bochmann Path Finder in Splunk Search 01-24-2025
0 7
0
7
ksheikh786
Calculating metrics. I need to count the number of sensors that are created and monitored for each host. I have the i...
by ksheikh786 Loves-to-Learn Lots in Splunk Search 01-24-2025
0 9
0
9
bennch68
Hi All,I am rather hoping someone can assist me in creating a search that can be used for an alert to detect when a c...
by bennch68 Engager in Splunk Search 01-24-2025
0 2
0
2
chrisboy68
Hi, Struggling trying to figure out what I'm doing wrong. I have the following SPL| inputlookup append=t kvstore | ev...
by chrisboy68 Contributor in Splunk Search 01-24-2025
0 5
0
5
varsh_6_8_6
The following is my query.index="xyz"  host="*" |fields host,messagevalue| search "total payment count :"|eval messag...
by varsh_6_8_6 Explorer in Splunk Search 01-24-2025
0 4
0
4
CrossWordKnower
Hi Splunkers, This is my first post as I am new to using splunk, but my issue arising when I am trying to pull specif...
by CrossWordKnower Explorer in Splunk Search 01-23-2025
0 3
0
3
poojak2579
Hi,Can any one please help in creating regex to extract 12 words(Words with characters/letters only) from beginning o...
by poojak2579 Path Finder in Splunk Search 01-23-2025
0 8
0
8
djluke
Hello Splunkers,I was wondering if it's possible to combine adaptive and static thresholds in IT Service Intelligence...
by djluke Path Finder in Splunk Search 01-23-2025
1 0
1
0
navan1
Hello,  I have lookup table which contain fields as below.   user                       shortname email 1            ...
by navan1 Explorer in Splunk Search 01-23-2025
0 1
0
1
Ste
Dear expertsAccording to the documentation after stats, I have only the fields left used during stats.  | tabl...
by Ste Path Finder in Splunk Search 01-23-2025
0 9
0
9
marycordova
I have some reservations about the usefulness of this with so much more usage of IaaS/PaaS/SaaS these days...but sinc...
by SplunkTrust SplunkTrust in Splunk Search 01-22-2025
0 7
0
7
ronj_clark
Combing through firewall logs.  I am extracting source, destination, dest_port.   I have a csv lookup file with ports...
by ronj_clark Explorer in Splunk Search 01-22-2025
0 2
0
2
omcollia
 I have a multivalue field called weeksum that contains the following values2024:47 2024:48 2024:49 2024:50 2024:51 2...
by omcollia Engager in Splunk Search 01-22-2025
0 7
0
7
Karthikeya
I am trying to get total traffic vs attack traffic splunk query in order to keep it in dashboard panel. We have a fie...
by Karthikeya Communicator in Splunk Search 01-22-2025
0 2
0
2
donm
We have a lookup that has all kinds of domain (DNS) information in it with about  60 fields like create date, ASN, na...
by donm Engager in Splunk Search 01-22-2025
0 3
0
3
cmuesing
I am getting an integrity check error on /opt/splunk/bin/python2.7 that says present_but_shouldnt_be. I can find the ...
by cmuesing Explorer in Splunk Search 01-22-2025
0 8
0
8
Karthikeya
Hello,We have a field called client_ip which contains different IP addresses and in events different threat messages ...
by Karthikeya Communicator in Splunk Search 01-21-2025
0 6
0
6
SN1
i want to know in which index is microsoft defender logs getting stored , I know some important fields which are ther...
by SN1 Path Finder in Splunk Search 01-21-2025
0 2
0
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors