Splunk Search

Splunk Search
Community Activity
dhavamanis
can you please tell us, how to get the last 24 hours event count to schedule the report?
by dhavamanis Builder in Splunk Search 01-03-2022
1 2
1
2
brc55
I have 2 sourcetypes, vpn & winevents, how do you write a single query to get winevents of the top 5 busiest machines...
by brc55 Explorer in Splunk Search 01-03-2022
0 3
0
3
vxroot
Hello guys, Splunk newbie here. Hope someone can assist in my case, so index=*_whatever is expected to be filled with...
by vxroot Loves-to-Learn in Splunk Search 01-03-2022
0 7
0
7
jsmithn
I know similar questions have been asked a number of times but trying to follow the suggestions given I still cannot ...
by jsmithn Path Finder in Splunk Search 01-02-2022
0 9
0
9
DonBaldini
I have a join where there are 2 different SLAs (Active and E2E) that need to be linked to incidents on one row. How c...
by DonBaldini Path Finder in Splunk Search 01-02-2022
0 1
0
1
shrinivaskittur
Hi,I need help in evaluation the csv files under "<Splunk directory>\etc\apps\search\lookups" folder. we have multipl...
by shrinivaskittur Explorer in Splunk Search 01-02-2022
0 4
0
4
splunk_luis12
Hi all, I'm trying to find the specific queries for the SH to create Splunk dashboard of the following info (example)...
by splunk_luis12 Path Finder in Splunk Search 01-02-2022
0 2
0
2
bcanfield83
Hello,I'm attempting to use the regex command to filter out any records on the "user" field that do not match the wri...
by bcanfield83 Engager in Splunk Search 01-02-2022
0 3
0
3
eranhauser
How do I pair events 4778 & 4779 for the same Logon_ID when I have multi 4778 and multi 4779?I would like to pair the...
by eranhauser Path Finder in Splunk Search 12-31-2021
0 1
0
1
sumitp10797
   Provide details about client purchase details          1. Total purchase split by product ID         2. Total Prod...
by sumitp10797 New Member in Splunk Search 12-31-2021
0 2
0
2
incognito
Hello, My Splunk query an API and gets a JSON answer.Here is a sample for 1 Host (the JSON answer is very long ≈ 400 ...
by incognito Explorer in Splunk Search 12-31-2021
0 6
0
6
SplnkUse
HelloI want to feed data directly into Excel but I do not have API access nor I can install custom connectors.Is ther...
by SplnkUse Path Finder in Splunk Search 12-31-2021
0 2
0
2
bazcurtis178
Hi,My search result brings back a GUID in the ID field. The GUID refers to a customer. I would like it to reflect the...
by bazcurtis178 Explorer in Splunk Search 12-31-2021
0 9
0
9
sagar_shubham
Hi Team,  Need your help in creating regex to create a field. "User_Claim":("sub":"qweihaytej"; "login_id":"Abc@domai...
by sagar_shubham Explorer in Splunk Search 12-30-2021
0 4
0
4
SplnkUse
HelloIf now, it is 30/12/2021 22:30, how can I search for timestamps from 29/12/2021 00:00:00 (i.e. beginning of 29/1...
by SplnkUse Path Finder in Splunk Search 12-30-2021
0 2
0
2
MelnikovTimofey
I use this guide to deploy my search head cluster. When I try to bring up the cluster captain (step 5): /opt/splunk...
by MelnikovTimofey New Member in Splunk Search 12-30-2021
0 4
0
4
Brainstorms
I have looked for solutions but I have mostly found results regarding only current and past time comparison which is ...
by Brainstorms Explorer in Splunk Search 12-30-2021
0 2
0
2
MarsBar
Hey all,Just started learning Splunk this week, interesting so far. How can I sort the top header from lowest to high...
by MarsBar Engager in Splunk Search 12-30-2021
1 5
1
5
sonicZ
Hello,Looking for some assistance in reconstructing my query, which is currently using | transaction with a traceId v...
by sonicZ Contributor in Splunk Search 12-30-2021
1 6
1
6
neerajs_81
Hello,  I am using the below query to output which of our Searches/Rules are mapped to which Mitre Technique IDs. | i...
by neerajs_81 Builder in Splunk Search 12-29-2021
0 3
0
3
drew_eckhardt
I want to look for requests in a service mesh ingest log which have no corresponding application log entries.My first...
by drew_eckhardt Engager in Splunk Search 12-29-2021
1 3
1
3
Ashwini_5
Hello Experts,  Kindly help to filter out latest one year date for the particular field. For ex:  index="abc" sourcet...
by Ashwini_5 Explorer in Splunk Search 12-29-2021
0 1
0
1
MarsBar
Hey all,I've got an interview and I need to show some level of competency at using Splunk, I'm doing a short presenta...
by MarsBar Engager in Splunk Search 12-29-2021
0 1
0
1
Mick_OBrien
I have a search string that details the last log entry for all running jobs [shown in ascending order] bar a few jobs...
by Mick_OBrien Path Finder in Splunk Search 12-29-2021
0 1
0
1
shanaz
Hi,want to create a search to find anyone who does changes to the sAMAccountName So sAMAccountName could be sAMAccoun...
by shanaz Engager in Splunk Search 12-29-2021
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...