Splunk Search

Splunk Search
Community Activity
priya1926
Hi, I am trying this cmd  index="wineventlog" host IN (*) EventCode=6006 OR EventCode="6005" Type=Information| transa...
by priya1926 Path Finder in Splunk Search 12-20-2021
0 2
0
2
g_paternicola
HelloI'm trying to injest event from this Microsoft event viewer:[WinEventLog://Microsoft-Windows-TerminalServices-Cl...
by g_paternicola Path Finder in Splunk Search 12-20-2021
0 7
0
7
jackin
Hi,Search 1: It is used to findout the server healthindex=win sourcetype="xmlwineventlog" host=Prod_UI_*| eval Status...
by jackin Path Finder in Splunk Search 12-19-2021
0 1
0
1
bosseres
Hello,Is it possible to user OR with regex?For example i have search | regex something="", and I need | regex somethi...
by bosseres Contributor in Splunk Search 12-19-2021
0 2
0
2
nanoo1
Hi,I need an help with splunk search query where in an incident need to be generated for a log backup failure after 3...
by nanoo1 Loves-to-Learn Everything in Splunk Search 12-19-2021
0 13
0
13
einars
Playing around to find a way to gather IP-Addresses from one type of search, to gather other type of information abou...
by einars Engager in Splunk Search 12-19-2021
0 2
0
2
mah
Hi,I want to find specific strings in all event in order to classify them into two values, like "if there is "A" or "...
by mah Builder in Splunk Search 12-19-2021
0 1
0
1
limalbert
 I could retrieve the list of the transactions as a single event below. Transactions start with "Dashboard Load:" and...
by limalbert Path Finder in Splunk Search 12-18-2021
0 3
0
3
martin61
I would like to create an alert when new QID from qualys is published.  For that I'm using FIRST_FOUND_DATETIME field...
by martin61 Engager in Splunk Search 12-17-2021
0 1
0
1
Mmilaham
Hello,I am trying to write a query that will display failed logins (Account_Name, Host, Count).First Queryindex=winev...
by Mmilaham Loves-to-Learn in Splunk Search 12-17-2021
0 3
0
3
alex_collins_in
I'm trying to plot the following as a scatter chart:The y-axis should be the namespace. Namespace is a small set of s...
by alex_collins_in New Member in Splunk Search 12-17-2021
0 1
0
1
rajg369
e.ghow to get sum of below in single querysum(val_2) by applicationsum(val_2) by val_1Query Result(single query)colum...
by rajg369 Explorer in Splunk Search 12-17-2021
0 3
0
3
jdepp
I have tried multiple ways to do this including join, append but in each case all I get is one column result being di...
by jdepp Path Finder in Splunk Search 12-17-2021
2 6
2
6
yuanliu
How to perform calculations on a given day of week?  Specifically, I want to compare a given time value, say given_da...
by SplunkTrust SplunkTrust in Splunk Search 12-17-2021
0 5
0
5
fatsug
We were presented with a situation where non-admin users needed access to Splunk license data from the _internal inde...
by fatsug Builder in Splunk Search 12-17-2021
0 2
0
2
marco1987
Hello splunkers,i need to understand the best way to forward my data in multisite indexer cluster for Disaster Recove...
by marco1987 Explorer in Splunk Search 12-17-2021
0 2
0
2
jerinvarghese
HI All,I have a DB querry, need a help in date filter.  | dbxquery connection="ITDW" shortnames=true query="SELECT G...
by jerinvarghese Communicator in Splunk Search 12-17-2021
0 0
0
0
ashraf_sj
Hi, I have a script which can pull the service status for each of the service,I have defined it to be a common source...
by ashraf_sj Explorer in Splunk Search 12-17-2021
0 2
0
2
d_T
Hi Splunk Community,I have run into an interesting scenario where I need to write a field extraction that will parse ...
by d_T New Member in Splunk Search 12-17-2021
0 1
0
1
Redjon_27
Hello,I'm working in Splunk enterprise with the search queries.I use a Website monitoring app for my website.I run a ...
by Redjon_27 New Member in Splunk Search 12-17-2021
0 1
0
1
gcusello
Hi at all,I noted a strange thing:in a splunk 8.2.2 with ES 6.6.2, the customer scheduled some daily reports with a t...
by SplunkTrust SplunkTrust in Splunk Search 12-17-2021
0 0
0
0
priya1926
Hi All, I am using the below search to calculate time difference between two events ie., 6006 and 60056006 is event s...
by priya1926 Path Finder in Splunk Search 12-16-2021
0 2
0
2
kartm2020
Search query :1 index="main" earliest=06/01/2019:00:00:00 latest=now | stats first(status) by src destination port ...
by kartm2020 Communicator in Splunk Search 12-16-2021
0 21
0
21
kteng2024
Hello, Can i please know how to get the all forwarders IP addresses that a reporting to splunk without use of intern...
by kteng2024 Path Finder in Splunk Search 12-16-2021
0 7
0
7
samindam
I have a requirement for having start and stop times with there status be projected over time as a line graph.I have ...
by samindam Observer in Splunk Search 12-16-2021
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...