Splunk Search

Splunk Search
Community Activity
francoisternois
Hi there,I'm trying to do a search that look at the latest status of a given actionid everyday to make a kind of day ...
by francoisternois Path Finder in Splunk Search 12-22-2021
0 2
0
2
v11n
I want to join two source types ST1(has fields id,title) and ST2(no fields only _raw="xid https://www.example.com?q1=...
by v11n New Member in Splunk Search 12-22-2021
0 2
0
2
unitedmarsupial
Our application's log-entries are in JSON and I need to search for certain strings found in the field called message....
by unitedmarsupial Path Finder in Splunk Search 12-22-2021
0 4
0
4
Papemalik1
Hello,I have 2 lookups, L0011 which contains all (Known) products with the vulnerability Log4shell and L0012 with all...
by Papemalik1 New Member in Splunk Search 12-22-2021
0 1
0
1
jcbrendsel
I have several fields that are named as integers. IE, 64, 110, 240, etc. If I try and perform a calculation using e...
by jcbrendsel Path Finder in Splunk Search 12-22-2021
2 8
2
8
rajg369
e.g query| makeresults | eval application="FSD", val_1="A", val_2=4839, val_3=5000 | append [| makeresults | eval app...
by rajg369 Explorer in Splunk Search 12-22-2021
0 4
0
4
Azwaliyana
This serach result will always return 3 rows. I want display all row but in trellis. For the first row, it is the mem...
by Azwaliyana Path Finder in Splunk Search 12-22-2021
0 1
0
1
kilimche
Hi could you please give me an advice how to edit a call to the Splunk Rest API with the following parameter:search |...
by kilimche Explorer in Splunk Search 12-22-2021
0 4
0
4
arusoft
I have two tablesEmailXDocDateCheckedNamea@a.comDoc 11/1/2021aa@a.comDoc 21/15/2021aa@a.comDoc 31/30/2021b EmailYDate...
by arusoft Communicator in Splunk Search 12-21-2021
0 3
0
3
adamsmith47
We have a foo.csv which will be updated regularly, and we have searches which require some of the data in foo.csv to ...
by adamsmith47 Communicator in Splunk Search 12-21-2021
0 3
0
3
jztilly
Hi there,I've got a basic search to provide the most recent timestamp for a successful backup using wineventlog data:...
by jztilly Engager in Splunk Search 12-21-2021
0 3
0
3
genesiusj
Hello,This article, https://research.splunk.com/stories/log4shell_cve-2021-44228/ , lists many log4j attack vectors a...
by genesiusj Builder in Splunk Search 12-21-2021
0 2
0
2
Steve_A200
Hi,Currently, my query produces the correct results but they are all aggregated into single cells, and I would like t...
by Steve_A200 Path Finder in Splunk Search 12-21-2021
0 2
0
2
rayar
I want to search for "index=*" ....what is the best way to run it  ?I tried to run "index=\*" but it's not working 
by rayar Contributor in Splunk Search 12-21-2021
0 5
0
5
wolfgangs
Hi,I have events which contain 3 Fields: "StartDate", "Value_per_month" and "Nr_of_Month". They basically disclose so...
by wolfgangs Engager in Splunk Search 12-20-2021
0 2
0
2
martin61
I'm looking to convert the results for these fields  in PST time zone, so that I can fetch the events based on these ...
by martin61 Engager in Splunk Search 12-20-2021
0 1
0
1
chuck_life09
I have an Index B  which has job_name and job_status details and another index A which has ticket number and job_name...
by chuck_life09 Path Finder in Splunk Search 12-20-2021
0 3
0
3
pavanbmishra
We have below CEF logs coming in from the device where few field doesn't have any value like cs2 below CEF:0|vendor|p...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
pavanbmishra
We need to capture field value for the below CEF log pattern CEF:0|vendor|product|1.1.0.15361|6099|DirectoryAssetSync...
by pavanbmishra Path Finder in Splunk Search 12-20-2021
0 1
0
1
splunkxorsplunk
Hi,Need help to get following results from the search.  all helps will be appreciated. On the image below, same color...
by splunkxorsplunk Explorer in Splunk Search 12-20-2021
0 4
0
4
nanoo1
Hi,I need a help with a query to display the count based on a particular message. For example, "Failed project on ABC...
by nanoo1 Loves-to-Learn Everything in Splunk Search 12-20-2021
0 5
0
5
mah
Hi,I have a table like this : part_of_urlcount/test11/test22/test33 I want to drilldown with a link which open a new ...
by mah Builder in Splunk Search 12-20-2021
0 6
0
6
mah
Hi,I have a table like this : testcounttest AA1test AB2test C3 I want to merge "test AA" and "test AB" which will giv...
by mah Builder in Splunk Search 12-20-2021
0 1
0
1
priya1926
Hi, I am trying this cmd  index="wineventlog" host IN (*) EventCode=6006 OR EventCode="6005" Type=Information| transa...
by priya1926 Path Finder in Splunk Search 12-20-2021
0 2
0
2
g_paternicola
HelloI'm trying to injest event from this Microsoft event viewer:[WinEventLog://Microsoft-Windows-TerminalServices-Cl...
by g_paternicola Path Finder in Splunk Search 12-20-2021
0 7
0
7
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...