Splunk Search

Splunk Search
Community Activity
PickleRick
I'm not that bad in searching  but this case is a little over my head and I need some clever idea.I have postfix log...
by SplunkTrust SplunkTrust in Splunk Search 02-25-2022
0 4
0
4
Stefanie
I am in the process of creating a search to detect significant hard drive decreases. Using the results from my search...
by Stefanie Builder in Splunk Search 02-25-2022
0 2
0
2
EspenLysvik
How do I make a search that includes to events. The first event is a 'CALL' with parameters and the second event is t...
by EspenLysvik Explorer in Splunk Search 02-25-2022
0 6
0
6
SimonM
Its a basic request however has been causing me grief: Easiest / most efficient way to find Destination IP (dstip) fo...
by SimonM New Member in Splunk Search 02-25-2022
0 1
0
1
iMarko
Hi, I'm writing a splunk query to find emails with specific file types attachedI have the regex working which pulls t...
by iMarko Engager in Splunk Search 02-25-2022
0 2
0
2
doesntmatter
I'm trying something like this:   my base search | where data.value1 == data.value2  my base search | where data.valu...
by doesntmatter Observer in Splunk Search 02-24-2022
0 1
0
1
rajureddi121195
can i get the data of indexers which is having more than 45 days old data.
by rajureddi121195 New Member in Splunk Search 02-24-2022
0 2
0
2
avni26
Hi Team,I have multiple jobs runs daily . Showing the status of these jobs in table. Now, I want to highlight the cel...
by avni26 Explorer in Splunk Search 02-24-2022
0 0
0
0
incognito
Hello,  I have the next following event : {<!-- --> [-]    dimensionMap: { [&#43;]    }   dimensions: [ [&#43;]    ]   timestamps: [ ...
by incognito Explorer in Splunk Search 02-24-2022
0 1
0
1
ranjithan
name uuid sysfs size dm-st paths failures action path_faults vend prod revmpatha 360002ac000000000000010e30001c751 dm...
by ranjithan Path Finder in Splunk Search 02-24-2022
0 3
0
3
ejacq
Dear Splunkers, we are trying to build a baseline of login events. We are using this example.   The search is at the ...
by ejacq New Member in Splunk Search 02-24-2022
0 0
0
0
Mofizul
Have a search result as GET https://…. | Status: 403 | Message: Forbidden | Duration: 166 | x-req-id: ssv5s-ssy67-78v...
by Mofizul Loves-to-Learn Lots in Splunk Search 02-24-2022
0 5
0
5
skyblue123
Hi,I'm new to Splunk and I was trying to compare values in the same field and group them subsequently.The events had ...
by skyblue123 Engager in Splunk Search 02-24-2022
0 4
0
4
user9025
I have two queries: 1. index&#61;A sourcetype&#61;B  "ERROR_A" | rex field&#61;_raw "loginid (?&lt;login_id&gt;\d&#43;) ::" | deduploginid ...
by user9025 Path Finder in Splunk Search 02-23-2022
0 4
0
4
ashinde3
Hi all,So, I have this URL/API endpoint as http://xml.app.com/pay/ent/auth/service/getId and I want to extract getId ...
by ashinde3 Engager in Splunk Search 02-23-2022
0 2
0
2
Mofizul
  index&#61;instance1 sourcetype&#61;source1 "Invalid-Access" | fields reqId | table reqId   The above query gives me a table...
by Mofizul Loves-to-Learn Lots in Splunk Search 02-23-2022
0 4
0
4
dm1
As the title says, I have a list of subnets and I would like to create a search which would show traffic (using Palo ...
by dm1 Contributor in Splunk Search 02-23-2022
0 1
0
1
Stuartb_
In my first post, I need to search Splunk using the REST API. How do I get the system to actually return me some resu...
by Stuartb_ New Member in Splunk Search 02-23-2022
0 1
0
1
chrisboy68
Hi, struggling why I can't seem to get this working. I want to have an alert evaluate to true (trigger) based on if i...
by chrisboy68 Contributor in Splunk Search 02-23-2022
0 1
0
1
riginoommen
My query is:   Mozilla/5.0 (X11; Linux x86_64; Catchpoint) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88...
by riginoommen Explorer in Splunk Search 02-23-2022
0 7
0
7
talbot7
What Capabilities do I need to enable so a user can change sharing permission on their searches?
by talbot7 Path Finder in Splunk Search 02-23-2022
1 2
1
2
simon9
Hi all, I'm a beginner working with splunk. I have 2 Logfiles with the same Name, but from 2 different Hosts. I would...
by simon9 Explorer in Splunk Search 02-23-2022
0 7
0
7
10061987
Hi all,Hope you are well. I have a task about getting users'Chrome extension list with Splunk Search with queries. I ...
by 10061987 Engager in Splunk Search 02-23-2022
0 3
0
3
kumarvarun1252
Currently we manually monitor splunk dashboards during our deploys. We would like to automate this. For this, we woul...
by kumarvarun1252 New Member in Splunk Search 02-23-2022
0 1
0
1
nmsaraujo
Hello all,   I have a scenario where I need to make calculations regarding license consumed, per host. However, since...
by nmsaraujo Explorer in Splunk Search 02-23-2022
0 0
0
0
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...
Top Solution Authors