Splunk Search

Splunk Search
Community Activity
Ste
Dear expertsAccording to the documentation after stats, I have only the fields left used during stats.  | tabl...
by Ste Path Finder in Splunk Search 01-23-2025
0 9
0
9
marycordova
I have some reservations about the usefulness of this with so much more usage of IaaS/PaaS/SaaS these days...but sinc...
by SplunkTrust SplunkTrust in Splunk Search 01-22-2025
0 7
0
7
ronj_clark
Combing through firewall logs.  I am extracting source, destination, dest_port.   I have a csv lookup file with ports...
by ronj_clark Explorer in Splunk Search 01-22-2025
0 2
0
2
omcollia
 I have a multivalue field called weeksum that contains the following values2024:47 2024:48 2024:49 2024:50 2024:51 2...
by omcollia Engager in Splunk Search 01-22-2025
0 7
0
7
Karthikeya
I am trying to get total traffic vs attack traffic splunk query in order to keep it in dashboard panel. We have a fie...
by Karthikeya Communicator in Splunk Search 01-22-2025
0 2
0
2
donm
We have a lookup that has all kinds of domain (DNS) information in it with about  60 fields like create date, ASN, na...
by donm Engager in Splunk Search 01-22-2025
0 3
0
3
cmuesing
I am getting an integrity check error on /opt/splunk/bin/python2.7 that says present_but_shouldnt_be. I can find the ...
by cmuesing Explorer in Splunk Search 01-22-2025
0 8
0
8
Karthikeya
Hello,We have a field called client_ip which contains different IP addresses and in events different threat messages ...
by Karthikeya Communicator in Splunk Search 01-21-2025
0 6
0
6
SN1
i want to know in which index is microsoft defender logs getting stored , I know some important fields which are ther...
by SN1 Path Finder in Splunk Search 01-21-2025
0 2
0
2
poojak2579
Is there any way to search for similar strings dynamically in different  logs?I want to group unique error string com...
by poojak2579 Path Finder in Splunk Search 01-21-2025
0 13
0
13
JyPl4wNYu7GV1uL
Stupid form editor adds extra CRs.Having trouble getting this search to work as desired. I've tried these 2 methods a...
by JyPl4wNYu7GV1uL Explorer in Splunk Search 01-21-2025
0 2
0
2
Amit79
I need help with below splunk query   index=XXX_XXX_XXX | eval job_status=if( 'MSGTXT' = "*ABEND*","ko","ok") | where...
by Amit79 Loves-to-Learn Everything in Splunk Search 01-21-2025
0 1
0
1
Rajaion
Hello community,I am having a problem displaying a graph. I have an index that contains incidents from several monito...
by Rajaion Path Finder in Splunk Search 01-21-2025
0 3
0
3
LizAndy123
So I have an Index which contains the following"Starting iteration"on 1 event and "Stopping iteration" on another eve...
by LizAndy123 Path Finder in Splunk Search 01-21-2025
0 7
0
7
Obsidian_RS400
I have a lookup table with a bunch of IP addresses (ipaddress.csv) and a blank column called hostname. I would like t...
by Obsidian_RS400 New Member in Splunk Search 01-21-2025
0 1
0
1
woodman2
I have such a search and it works fine but not in Dashboard!    index=unis | search *sarch* | eval name = coalesce(C_...
by woodman2 Loves-to-Learn Everything in Splunk Search 01-21-2025
0 5
0
5
josephp
Hi, We recently migrated from a standalone Search Head to a clustered one. However, we are having some issue running ...
by josephp Loves-to-Learn Everything in Splunk Search 01-21-2025
0 3
0
3
deckard1984
Right now a have a table list with fields populated where one process_name is repeating across multiples hosts with s...
by deckard1984 Engager in Splunk Search 01-21-2025
0 3
0
3
bryhoffman
When I click on the raw log and back out of it it shows up as highlighted. How do I default the sourcetype/source to ...
by bryhoffman Explorer in Splunk Search 01-21-2025
0 4
0
4
splunkinator53
Hey,  lately i was working on an SPL and wondered why this aint working. This is simplified  index IN(anonymized_inde...
by splunkinator53 Explorer in Splunk Search 01-20-2025
0 4
0
4
jmartens
I have the following regex that I (currently) use at search time (it will be a field extraction once I get it ironed ...
by jmartens Path Finder in Splunk Search 01-20-2025
0 3
0
3
anmohan0
I want to get the below search executed and display the results in a table for all comma separated values that gets p...
by anmohan0 Explorer in Splunk Search 01-19-2025
0 3
0
3
patpro
Hello,I’m trying to tune Machine Learning Toolkit in order to detect authentication abuse on a web portal (based upon...
by patpro Path Finder in Splunk Search 01-19-2025
0 0
0
0
danielbb
We have a case where we can search and find events that match the search criteria. The client would like to see the e...
by danielbb Motivator in Splunk Search 01-19-2025
0 3
0
3
Afterimage
We have a custom dashboard in Splunk that has a few filters, one of which is a multiselect. This dashboard allows use...
by Afterimage Engager in Splunk Search 01-17-2025
0 3
0
3
Get Updates on the Splunk Community!

Optimize AI at Scale: Must-Attend Observability Sessions at .conf26

conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help ...

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...