Splunk Search

Splunk Search
Community Activity
bheptinstall
I have a dashboard setup that returns a few searches for my organization. When I click the export button underneath t...
by bheptinstall Engager in Splunk Search 04-12-2022
0 2
0
2
jpfrancetic
Greetings Splunk Community, I am currently working on a search and I am trying to drop rows that have "NULL" in them....
by jpfrancetic Path Finder in Splunk Search 04-12-2022
0 1
0
1
saurav47
Hey Team, I have some 150+ ip addresses in CIDR format (IE 96.24.0.0/16, etc) , i am getting my search result with on...
by saurav47 Loves-to-Learn Lots in Splunk Search 04-12-2022
0 1
0
1
Allene139
I have 2 searches and I want to link 2 together in one table.The first search: index=very_big_index caseNumber=123456...
by Allene139 Explorer in Splunk Search 04-12-2022
0 4
0
4
neerajs_81
GentlemenMy raw events have a field called login_time which has values of format ( 2022-04-11 10:52:08 ) .  This is t...
by neerajs_81 Builder in Splunk Search 04-12-2022
0 6
0
6
bijodev1
Hi Team, when I use curl - I am able to get the output in JSON format. But when I am trying to use requests module, I...
by bijodev1 Communicator in Splunk Search 04-12-2022
0 7
0
7
greekleo89
Hi all, New to splunk and i have seen that this has been asked many times but most of the results are based on matchi...
by greekleo89 Loves-to-Learn Everything in Splunk Search 04-12-2022
0 9
0
9
neerajs_81
Hi All,  I have two sourcetypes in the same index, however the fields names are different but the value is same for t...
by neerajs_81 Builder in Splunk Search 04-12-2022
0 3
0
3
tehong
Hi Experts!I am trying to REPLACE the join command to the stats command because the subsearch result exceeds 50000.Ho...
by tehong Explorer in Splunk Search 04-11-2022
0 2
0
2
azleeshah
Im trying to nullified  data in "status" field  for any value match as "InActive" based on accounttype . Appreciate h...
by azleeshah Explorer in Splunk Search 04-11-2022
0 2
0
2
azleeshah
username to split  - domain\user expected result  for user2 field -         domain                                   ...
by azleeshah Explorer in Splunk Search 04-11-2022
0 2
0
2
corehan
Hello dears, Can i list search result with stat count like hourly trend ? Example; Hour : 00:00 EventCount: 10 Hour :...
by corehan Explorer in Splunk Search 04-11-2022
0 5
0
5
will09222
Hi, I am new to splunk. Currently using this query to get the count index=* SrcCountry=* | stats count by SrcCountry....
by will09222 New Member in Splunk Search 04-11-2022
0 1
0
1
POR160893
Hi, I have an index of log events and I have been asked to exclude all events with a certain string in it. The String...
by POR160893 Builder in Splunk Search 04-11-2022
0 4
0
4
vangal_sandeep
I have some data and  I am trying to  extract fields from multi line raw data.   TIMESTAMP=23-12-2021,Eligible_to_be_...
by vangal_sandeep New Member in Splunk Search 04-11-2022
0 2
0
2
Kisame27
2022-04-11 05:46:26 POST /BestMarket.Internal.Market.Transactions/MarketTransactionService  ContractName="BestMarket....
by Kisame27 Explorer in Splunk Search 04-11-2022
0 1
0
1
kiran007
Hi, I need list of all the successful events details in the 'If' condition. For those successful list I need to extra...
by kiran007 Explorer in Splunk Search 04-11-2022
0 4
0
4
KeithH
Hi All,I hope someone can enlighten me with this seemingly simple problem.I have this very simple search return 32 ro...
by KeithH Communicator in Splunk Search 04-11-2022
0 6
0
6
pavanae
Hi Splunkers,  I have defined a filed as follows using eval condition        | eval body = "Sample Example :-" . " -...
by pavanae Builder in Splunk Search 04-10-2022
0 2
0
2
ebs
Hi, I'm trying to round the average of my response_time but still getting undesirable results (all the decimal places...
by ebs Communicator in Splunk Search 04-10-2022
0 7
0
7
usscommunity
Hi Could you please help me with using REX/REGEX inside eval? Here is what I'm trying to do  | makeresults | eval Use...
by usscommunity Loves-to-Learn Lots in Splunk Search 04-09-2022
0 2
0
2
aamer86
I have created a lookup for a threat feed CSV file we are using. After deleting all the Lookup CSV files and removing...
by aamer86 Path Finder in Splunk Search 04-09-2022
0 1
0
1
wcooper003
This search works fine but is slow: host=host1 sourcetype="WinEventLog:Security" EventCode=5156 | timechart span=1d...
by wcooper003 Communicator in Splunk Search 04-08-2022
0 7
0
7
JChris_
I have the following events in splunk:     company,name,email,status Acme,John Doe,john.doe@example.com,inactive Comp...
by JChris_ Path Finder in Splunk Search 04-08-2022
0 4
0
4
dfiore42
I need a query to view disk encryption (DAR) of all my hosts, be it Bit Locker, LUKS, etc.index=* host=* | ???Thank y...
by dfiore42 New Member in Splunk Search 04-08-2022
0 1
0
1
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...