Splunk Search

Splunk Search
Community Activity
wangkevin1029
Hi, Splunkers, when I run a splunk search,  I use  NOT  string  to exclude result with this string.if I have a dashbo...
by wangkevin1029 Communicator in Splunk Search 12-25-2021
0 15
0
15
yuanliu
I was surprised by this result: In a field starting with a value that can be interpreted as an integer, groupby treat...
by SplunkTrust SplunkTrust in Splunk Search 12-24-2021
0 2
0
2
vishwasgopala
INFO [] () process='isValid', result='failed', dacNumber='[DAC_111_646]',  accountNumber=1122333INFO [] () process='i...
by vishwasgopala Engager in Splunk Search 12-24-2021
0 2
0
2
zacksoft_wf
There is a SPL search, ending with stats that generates 300 events.Now that Search, lets call it "SEARCH-1" is saved ...
by zacksoft_wf Contributor in Splunk Search 12-23-2021
0 1
0
1
Matthew86
Hi Guys, Hope you can help me out. Consider the following data in Splunk:   { attrs: { account: 85859303 ...
by Matthew86 Explorer in Splunk Search 12-23-2021
0 3
0
3
francoisternois
Hi there,I'm trying to do a search that look at the latest status of a given actionid everyday to make a kind of day ...
by francoisternois Path Finder in Splunk Search 12-22-2021
0 2
0
2
v11n
I want to join two source types ST1(has fields id,title) and ST2(no fields only _raw="xid https://www.example.com?q1=...
by v11n New Member in Splunk Search 12-22-2021
0 2
0
2
unitedmarsupial
Our application's log-entries are in JSON and I need to search for certain strings found in the field called message....
by unitedmarsupial Path Finder in Splunk Search 12-22-2021
0 4
0
4
Papemalik1
Hello,I have 2 lookups, L0011 which contains all (Known) products with the vulnerability Log4shell and L0012 with all...
by Papemalik1 New Member in Splunk Search 12-22-2021
0 1
0
1
jcbrendsel
I have several fields that are named as integers. IE, 64, 110, 240, etc. If I try and perform a calculation using e...
by jcbrendsel Path Finder in Splunk Search 12-22-2021
2 8
2
8
rajg369
e.g query| makeresults | eval application="FSD", val_1="A", val_2=4839, val_3=5000 | append [| makeresults | eval app...
by rajg369 Explorer in Splunk Search 12-22-2021
0 4
0
4
Azwaliyana
This serach result will always return 3 rows. I want display all row but in trellis. For the first row, it is the mem...
by Azwaliyana Path Finder in Splunk Search 12-22-2021
0 1
0
1
kilimche
Hi could you please give me an advice how to edit a call to the Splunk Rest API with the following parameter:search |...
by kilimche Explorer in Splunk Search 12-22-2021
0 4
0
4
arusoft
I have two tablesEmailXDocDateCheckedNamea@a.comDoc 11/1/2021aa@a.comDoc 21/15/2021aa@a.comDoc 31/30/2021b EmailYDate...
by arusoft Communicator in Splunk Search 12-21-2021
0 3
0
3
adamsmith47
We have a foo.csv which will be updated regularly, and we have searches which require some of the data in foo.csv to ...
by adamsmith47 Communicator in Splunk Search 12-21-2021
0 3
0
3
jztilly
Hi there,I've got a basic search to provide the most recent timestamp for a successful backup using wineventlog data:...
by jztilly Engager in Splunk Search 12-21-2021
0 3
0
3
genesiusj
Hello,This article, https://research.splunk.com/stories/log4shell_cve-2021-44228/ , lists many log4j attack vectors a...
by genesiusj Builder in Splunk Search 12-21-2021
0 2
0
2
Steve_A200
Hi,Currently, my query produces the correct results but they are all aggregated into single cells, and I would like t...
by Steve_A200 Path Finder in Splunk Search 12-21-2021
0 2
0
2
rayar
I want to search for "index=*" ....what is the best way to run it  ?I tried to run "index=\*" but it's not working 
by rayar Contributor in Splunk Search 12-21-2021
0 5
0
5
wolfgangs
Hi,I have events which contain 3 Fields: "StartDate", "Value_per_month" and "Nr_of_Month". They basically disclose so...
by wolfgangs Engager in Splunk Search 12-20-2021
0 2
0
2
martin61
I'm looking to convert the results for these fields  in PST time zone, so that I can fetch the events based on these ...
by martin61 Engager in Splunk Search 12-20-2021
0 1
0
1
chuck_life09
I have an Index B  which has job_name and job_status details and another index A which has ticket number and job_name...
by chuck_life09 Path Finder in Splunk Search 12-20-2021
0 3
0
3
pavanbmishra
We have below CEF logs coming in from the device where few field doesn't have any value like cs2 below CEF:0|vendor|p...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
pavanbmishra
We need to capture field value for the below CEF log pattern CEF:0|vendor|product|1.1.0.15361|6099|DirectoryAssetSync...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
splunkxorsplunk
Hi,Need help to get following results from the search.  all helps will be appreciated. On the image below, same color...
by splunkxorsplunk Explorer in Splunk Search 12-20-2021
0 4
0
4
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors