Splunk Search

Splunk Search
Community Activity
zacksoft_wf
I see a strange behaviour in Splunk.There is this SPL, when ran between 3/13/2022 6:00 AM to 3/14/2011 6:00 AM time r...
by zacksoft_wf Contributor in Splunk Search 03-14-2022
0 4
0
4
Fe-atSplunk
There are two environments, INT and PROD. The value of IREFFECTIVEDATE in INT is always the same, as is PROD, however...
by Fe-atSplunk Explorer in Splunk Search 03-14-2022
0 9
0
9
sanju2408de
I am facing challenges while extracting the data from emails, using the Microsoft O365 email add on. I want to extrac...
by sanju2408de Explorer in Splunk Search 03-14-2022
0 2
0
2
QQAL2021
We have many completely diff events. Sometimes, we got a result based on Search 1. But we want to exclude some record...
by QQAL2021 Engager in Splunk Search 03-14-2022
0 4
0
4
Borntowin
I would like to match/pick only the event which contains "ccexpire". sample event :- 09/Dec/2021 23:52:39,Query,"SELE...
by Borntowin Loves-to-Learn Everything in Splunk Search 03-13-2022
0 3
0
3
rahmatn
Hi All,I have transaction data from a database and want to compare it with an index in splunk, filtering the transact...
by rahmatn Path Finder in Splunk Search 03-13-2022
0 6
0
6
hketer
Hi All, I'm running the query  | tstats count where index=<index name> by sourcetype No results  OR  | tstats values(...
by hketer Path Finder in Splunk Search 03-13-2022
0 1
0
1
afraanajam
How to search that shows the current uptime of the server? and the date / time / user who last reboot the server?
by afraanajam Loves-to-Learn Everything in Splunk Search 03-13-2022
0 5
0
5
kalibaba2021
I have 3 searches executing against same lookup, and since each lookup needs to be grouped by different set of fields...
by kalibaba2021 Path Finder in Splunk Search 03-13-2022
0 5
0
5
tazzvon
i have the following in a statistical table on a dashboard index=* <do search> | dedup B C | table _time B C D E F J ...
by tazzvon Engager in Splunk Search 03-13-2022
0 3
0
3
aaa2324
Hi Team, I am looking to get incremental count of some data in dashboard. For example : If the count for a certain ta...
by aaa2324 Explorer in Splunk Search 03-13-2022
0 3
0
3
cj04
<title> Clam Scan Results </title> <event> <search> ref="anti-virus scan results"> </search> <option name="list.drill...
by cj04 Explorer in Splunk Search 03-12-2022
0 3
0
3
Jaycybersec
Hello , I have installed forwarder on Linux system and able to see logs in searches but the when i open a detailed lo...
by Jaycybersec Explorer in Splunk Search 03-12-2022
0 5
0
5
ccntech
I am trying to produce a table that can display 5xx status code counts per host over a timeframe (this will eventuall...
by ccntech Explorer in Splunk Search 03-12-2022
0 3
0
3
ND
Hi Team,   I want to calculate the % based on two different tables where I am using addcoltotals to calculate grand t...
by ND Path Finder in Splunk Search 03-11-2022
0 1
0
1
kc_prane
 i need  the fields  extracted  by two fields  1) Detail message  = before the comma ( I need the full description) 2...
by kc_prane Communicator in Splunk Search 03-11-2022
0 6
0
6
P_Orourke
Hi, I have 2 timecharts where I need to show a TOTAL count across specified field values. The first timechart must sh...
by P_Orourke Loves-to-Learn Lots in Splunk Search 03-11-2022
0 1
0
1
bnybln030
Hi i want to extract the mac_algorithms field with regex from a nmap scan result. Does anyone have an idea how it wor...
by bnybln030 Engager in Splunk Search 03-11-2022
0 13
0
13
Bala
stats count(eval(searchmatch(Bala))) as A count(eval(searchmatch(kasa))) as B count(eval(searchmatch(reddy))) as C  A...
by Bala Explorer in Splunk Search 03-11-2022
0 8
0
8
bijodev1
Hi Team,  I have the following result in place with 30min bucket using stats values() and then xyseries  time        ...
by bijodev1 Communicator in Splunk Search 03-11-2022
0 4
0
4
anooshac
Hi all, I have 2 queries, from one i get a list of files and the other query should use these files as their source t...
by anooshac Communicator in Splunk Search 03-11-2022
0 7
0
7
Gian89
Hello Community, I have quite a strange issue to face...For a project I'm working on, I would need to create a new ca...
by Gian89 Explorer in Splunk Search 03-11-2022
0 4
0
4
jip31
Hello I use 2 separate search almost identical Now I want to merge these 2 search in one search Here is the search   ...
by jip31 Motivator in Splunk Search 03-11-2022
0 14
0
14
darls15
Hi I'm fairly new to Splunk and I need to round my time field up/down to the nearest hour. For example... If now retu...
by darls15 Explorer in Splunk Search 03-11-2022
0 3
0
3
dm1
I am indexing email data that Splunk reads from an inbox folder (via TA-mailclient). Those emails contain a csv file ...
by dm1 Builder in Splunk Search 03-10-2022
0 4
0
4
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...