| Thread Info | |||||
|---|---|---|---|---|---|
| 
        Please help!I have a lookup table and some data in two different indexes. Please help with a search that will produce...
        
         
           by 
           
                
                    
                        hank72
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Good Afternoon, 
  So I've recently been hired on as a Splunk admin/analyst.  The scope of my job really relies on my...
        
         
           by 
           
                
                    
                        Ab_Splunk
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-13-2022
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi , I am trying to figure out how to write a query to create an alert that will alert me whenever a user is logged o...
        
         
           by 
           
                
                    
                        websplunk01
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-13-2022
             
           
         
        | 
		
		0
   | 
	  
	  18
	 | |||
| 
        My main query looks like:...| stats min(_time) AS SESSION_START_TIME max(Source_Network_Address) AS EMP_SRC_IP...| ev...
        
         
           by 
           
                
                    
                        eranhauser
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  12
	 | |||
| 
         In above image i couldn’t able to access the date input,It’s actually a client server as user I couldn’t able access...
        
         
           by 
           
                
                    
                        Veeru
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        My data is like this illustration purposes only:
  LocalIp aip10.10.10.1192.168.1.110.10.10.2172.58.100.4110.10.12.38...
        
         
           by 
           
                
                    
                        jenkinsta
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        I have been asked to ensure that the DOD CAC can be used to log into the Splunk Search Heads. Does anyone know how to...
        
         
           by 
           
                
                    
                        scc00
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               05-01-2018
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hello, 
  I would like change bare host name to host name with a domain name. According to all articles I have change...
        
         
           by 
           
                
                    
                        Wojt3k
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hi,
  various tables from a database are read by Splunk. I need to combine fields from all 3 datasources. The ID-fiel...
        
         
           by 
           
                
                    
                        ManfredGrill
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        While most Warn and Errors show up on the Job dropdown (1) some are also displayed in an area right below the search ...
        
         
           by 
           
                
                    
                        nunoaragao
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        Hello there,
  I want to make a top 10 of applications based on top 10 of categories.
  Here is an example:
  Categor...
        
         
           by 
           
                
                    
                        BigShak
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi all, I have been using a subsearch in a timechart command to dynamically select the correct span. The query looks ...
        
         
           by 
           
                
                    
                        just_me
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-18-2022
             
           
         
        | 
		
		0
   | 
	  
	  0
	 | |||
| 
        If i have n numbers of router in my index  and i want to know the current status of router if its connected or failed...
        
         
           by 
           
                
                    
                        i_am_manish
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hello,Can someone please help me with a query to find who deleted the files of users (user=x, y, z) from a folder. in...
        
         
           by 
           
                
                    
                        innoce
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        Is there a way to add a field to an event from a different event assuming they have a common key using a simple searc...
        
         
           by 
           
                
                    
                        armahalma
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               01-12-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        I've been able to configure SSO for CAC via Apache proxy and everything works fine. I'm trying to figure out how to d...
        
         
           by 
           
                
                    
                        bwgates
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               03-27-2018
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Can a search time limit be applied differently by index rather than by role? 
  Currently, we have a search roll limi...
        
         
           by 
           
                
                    
                        timgren
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        index IN (A,B) sourcetype IN (A,B) earliest=-12h latest=@m| transaction UUID keepevicted=true| eval ReportKey="Today"...
        
         
           by 
           
                
                    
                        Veeru
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               01-13-2022
             
           
         
        | 
		
		0
   | 
	  
	  6
	 | |||
| 
        Hi All,
  I have done a index search for disk data and then lookup to the CSV to check as per the Application which s...
        
         
           by 
           
                
                    
                        ravinayan_acc
                    
                
           
             
             
               Loves-to-Learn Lots
             
           
           in
           Splunk Search
           
           
              
               01-13-2022
             
           
         
        | 
		
		0
   | 
	  
	  1
	 | |||
| 
        recently we onboarded these logs but most of the fields are not extracted though these values are mentioned with =. I...
        
         
           by 
           
                
                    
                        srivenna
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-12-2022
             
           
         
        | 
		
		0
   | 
	  
	  5
	 | |||
| 
        Hi, 
  I want to create the following excel table using splunk. The first 3 columns are based on the output of a quer...
        
         
           by 
           
                
                    
                        Ctpelster
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Dear Splunk Community,
  I'm trying to extract a list of changed fields, but they should only be listed if they have ...
        
         
           by 
           
                
                    
                        plcd63
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  4
	 | |||
| 
        Hi
   
   
    I have events like this:
   
   
     
   
   
    1900/10/26|
    1900/10/25|333|CHECKOUT |U |2222|00...
        
         
           by 
           
                
                    
                        indeed_2000
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               01-17-2022
             
           
         
        | 
		
		0
   | 
	  
	  3
	 | |||
| 
        Hi 
  what is the usecase of integrating Splunk with ETL tools? Send splunk data to ETL? Send ETL data to splunk?
   ...
        
         
           by 
           
                
                    
                        indeed_2000
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               01-16-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 | |||
| 
        Hi
  I am working on query to retrieve count of repeated, unique and total visits by user through different channels....
        
         
           by 
           
                
                    
                        trinath465
                    
                
           
             
             
               Engager
             
           
           in
           Splunk Search
           
           
              
               01-14-2022
             
           
         
        | 
		
		0
   | 
	  
	  2
	 |