Splunk Search

Splunk Search
Community Activity
noott211
I want to see the result values of Src_ip and dst_ip are the same and "ok" and the number of these result values. Wha...
by noott211 Path Finder in Splunk Search 12-15-2021
0 1
0
1
mato666666
Hi,I have a very specific problem. I have a field with following values at different timestamps. Example:1,3,2002,3,4...
by mato666666 Explorer in Splunk Search 12-15-2021
0 5
0
5
lmonahan
Is it valid to use a where clause to compare a string value to a multivalue field in order to know if that value is o...
by lmonahan Path Finder in Splunk Search 12-14-2021
0 1
0
1
rberman
Hi, I have a field called "catgories" whose value is in the format of a JSON array. The array is a list of one or mor...
by rberman Path Finder in Splunk Search 12-14-2021
0 4
0
4
jbreeves
Hi, I'm attempting to build a query to find destination IP addresses that became source IPs for traffic in a 5min win...
by jbreeves New Member in Splunk Search 12-14-2021
0 3
0
3
umeshcreddy
Hi Actually i made  lookup with the list of ip address in .csv file. I want to write a query if there is traffic from...
by umeshcreddy Engager in Splunk Search 12-14-2021
0 1
0
1
jaibalaraman
Hi Team I am trying to find out recent CVE-2021-44228( log4j)I tried " index=aws *log4j*", nut not sure how to find o...
by jaibalaraman Path Finder in Splunk Search 12-14-2021
0 5
0
5
SplnkUse
HelloI am a Splunk user, not admin, and I seem to be able to do a search like:| rest splunk_server=local servicesNS/-...
by SplnkUse Path Finder in Splunk Search 12-14-2021
0 0
0
0
shreyasamin64
need help on using command strptime/strftime EX: input: December 7, 2021 1:00:01 PM         output: 12/1/2021   13:00...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 2
0
2
shreyasamin64
need help on removing only endpoint from the data set input :                                                        ...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 1
0
1
09128028400
Hello every bodyI have been struggling with a serious problem recently my splunk version is 7.2 when I use  span Comm...
by 09128028400 Engager in Splunk Search 12-14-2021
0 6
0
6
amagson
Hello all,I need a hand with a basic Splunk search. I appreciate this is Splunk 101 basics, but with other commitment...
by amagson Loves-to-Learn in Splunk Search 12-14-2021
0 2
0
2
rxalex
Hi Folks, I have been trying to pull some data associated with latest Run ID (associated with execution), I am having...
by rxalex Engager in Splunk Search 12-14-2021
0 2
0
2
poiromaniax
Hey all,Firstly - the title doesnt actually encapsulate what Im trying to do, Ill try break it down simply:I have AWS...
by poiromaniax Explorer in Splunk Search 12-13-2021
0 2
0
2
Sarvoday
0
1
phamxuantung
I try to use the query eval ID = if(ORG="MC",ID=substr(ID,-6),0) Basically, I want in my result, if ORG="MC", I want ...
by phamxuantung Communicator in Splunk Search 12-13-2021
0 1
0
1
kapoorsumit2020
Team,I'm newbie in writing Splunk queries. Could you please provide me guidance how to design a SPL for below use cas...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-13-2021
0 7
0
7
AndreiIssakov
Hello!Could somebody please suggest if it is possible to do a map search search more effectively?What I am trying to ...
by AndreiIssakov Explorer in Splunk Search 12-13-2021
0 6
0
6
tkw03
Hello, As an admin, I tried to delete a lookup table file. I had copied all the apps back to the search head cluster...
by tkw03 Communicator in Splunk Search 12-13-2021
2 3
2
3
pk87
We save hash values from our ids and I want to search for them. I would expected I can do it this way:index=blub id=s...
by pk87 Engager in Splunk Search 12-13-2021
0 9
0
9
Narendra045
Hi,I have two tables and in first table it contains 13 columns and from second table only one column i need to add to...
by Narendra045 Explorer in Splunk Search 12-13-2021
0 3
0
3
nateNpgh
When running the following search for a 24hr period it is always being auto-finalized due to disk usage limit of 100M...
by nateNpgh Loves-to-Learn Lots in Splunk Search 12-13-2021
0 13
0
13
lostcauz3
 TYPEMonthKPI_1KPI_2GLOBALOct'217624LOCALOct'214667 I'm searching the table like | search TYPE="GLOBAL" | search Mont...
by lostcauz3 Path Finder in Splunk Search 12-12-2021
0 2
0
2
GRC
Hi there,I have 2 separate queries that I built using Rex.1. This query captures the logg on and logg off status of t...
by GRC Path Finder in Splunk Search 12-11-2021
0 2
0
2
GindiKhangura
I am encountering an issue when using a subsearch in a tstats query. Specifically, I am seeing the count of events in...
by GindiKhangura Explorer in Splunk Search 12-10-2021
0 3
0
3
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors