Splunk Search

Splunk Search
Community Activity
bcain22
I am new to Splunk and I am trying to parse an Aide scan log file to display each line. Currently, Splunk just reads ...
by bcain22 Engager in Splunk Search 03-21-2022
0 1
0
1
Daniel_K
Hi experts,I would appreciate some design help with a query where I want to see all src_ip's querying for two differe...
by Daniel_K Explorer in Splunk Search 03-21-2022
0 7
0
7
hj9b7Cn
Looking for some help with this one.I'm building a few charts that are meant to serve as vulnerability trending. Our ...
by hj9b7Cn Engager in Splunk Search 03-21-2022
0 3
0
3
btcs2
| chart count over date_month by seriesName  , I have a search that display counts over month by seriesname . but ins...
by btcs2 Engager in Splunk Search 03-21-2022
0 6
0
6
ccntech
I am trying to create a report that will show month over month reporting for web service average response time as a p...
by ccntech Explorer in Splunk Search 03-21-2022
0 2
0
2
ayush-choudhary
i am using transaction command to check the start time and end time of a transaction. I have used:| transaction TxnId...
by ayush-choudhary Explorer in Splunk Search 03-21-2022
0 3
0
3
bijodev1
 The below table is for one User, like wise I have to pull the details for many users - who visited multiple url on d...
by bijodev1 Communicator in Splunk Search 03-21-2022
0 7
0
7
neeravmathur
Hi Guys, We have 1 indexer and 1 Search head in 2 different datacenter locations. (Lets say DC-A and DC-B) Since DC-A...
by neeravmathur Path Finder in Splunk Search 03-21-2022
0 6
0
6
goken
Hi all, Below is my search command: | inputlookup servicereport.csv | search "FNN" = [ | inputlookup extract.csv ...
by goken New Member in Splunk Search 03-20-2022
0 2
0
2
msg4sunil
How do combine the below 2 searches into one? 1. * orderid|stats count by id returns something like  2022-03-21T00:10...
by msg4sunil Path Finder in Splunk Search 03-20-2022
0 4
0
4
fredv44
Hi,From these logs (unique index): 2022-03-16 16:43:43.279 traceId="1234" svc="Service1" url="/customer/{customerGuid...
by fredv44 Explorer in Splunk Search 03-20-2022
0 4
0
4
jip31
hello I use appdncols command in order to aggregate in a table the result of different search I have 2 issues with t...
by jip31 Motivator in Splunk Search 03-20-2022
0 11
0
11
dimigs
The message format we chose uses a field called scope to control the level of aggregation you want (by request_type, ...
by dimigs Engager in Splunk Search 03-19-2022
0 6
0
6
nnehme
Greetings I am new to Splunk. I need to know if it is possible to draw a diagram using the below search results: Sour...
by nnehme New Member in Splunk Search 03-19-2022
0 3
0
3
jip31
hello I use a transpose command in order to have _time field displayed in column instead row First question : how to ...
by jip31 Motivator in Splunk Search 03-19-2022
0 4
0
4
huan_an
query | bin _time span=30m | chart avg(throughput) by _time server Hi, I want only the avg(throughput) by _time serve...
by huan_an Explorer in Splunk Search 03-19-2022
0 1
0
1
Razziq
Hello, We are currently working with two sets of data that have similar fields. We would like to align matching event...
by Razziq Explorer in Splunk Search 03-19-2022
0 3
0
3
umithchada
Hello, I am trying to find the list of elapsed time over a specific time using our os process sourcetype.Looks someth...
by umithchada Explorer in Splunk Search 03-18-2022
0 4
0
4
JustinSC
I had a situation where I wanted to know if the mstats p90(cpu) over 5 minutes of a host was above a certain value; b...
by JustinSC Explorer in Splunk Search 03-18-2022
0 0
0
0
Rapidz
Currently I have a search query that will show when an event happens with the device_id, count, and the device name. ...
by Rapidz Explorer in Splunk Search 03-18-2022
0 1
0
1
trajedy
Hi all, I've been working on getting the number of active VPN users from our ASA logs by a simple query to get the la...
by trajedy New Member in Splunk Search 03-18-2022
0 2
0
2
SIEMStudent
Hi Splunkers,I'm performing some searches to monitor Windows user failure attempts. The failure itself is not a probl...
by SIEMStudent Path Finder in Splunk Search 03-18-2022
0 3
0
3
msg4sunil
Team, Can you please help me with the splunk query for the below? Thank you Splunk query returns the below 1 1 1 2 2...
by msg4sunil Path Finder in Splunk Search 03-18-2022
0 8
0
8
avni26
Hi , I want to display two charts , one column and line chart in single panel based on condition. For example, if re...
by avni26 Explorer in Splunk Search 03-18-2022
0 5
0
5
michaelsplunk1
Hi there! I want to add columns to this table that I copied from the docs about timewrap. I want to add columns that ...
by michaelsplunk1 Path Finder in Splunk Search 03-18-2022
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors