Splunk Search

Splunk Search
Community Activity
arusoft
I have duration for multiple websites.How can I get 3 least duration for each websites. So here is exampleDuration_in...
by arusoft Communicator in Splunk Search 12-15-2021
0 14
0
14
cheecheng
Hello, I have the following query.<base query> | rex field=msg "HTTP/1.1\\\" (?<http_status>\d{3})" | where http_sta...
by cheecheng Engager in Splunk Search 12-15-2021
0 4
0
4
SplunkDash
Hello,I have some issues with Field Extraction, since there are some inconsistences in the structure of its field val...
by SplunkDash Motivator in Splunk Search 12-15-2021
0 14
0
14
Ashwini008
Hi,I am getting the following error on my search head whenever i run query in a newly created app.Search results migh...
by Ashwini008 Builder in Splunk Search 12-15-2021
0 1
0
1
ashvinpandey
I am stuck with a query where I am trying to pass the field value from sub search to parent search:Query:  index=f5 s...
by ashvinpandey Contributor in Splunk Search 12-15-2021
0 3
0
3
kajalchopade071
if i have employees list .for each employee there are two status logged in and logged out, i need to find out the eac...
by kajalchopade071 Path Finder in Splunk Search 12-15-2021
0 1
0
1
kajalchopade071
suppose if i have user1,user2,user3 i need to find out last log message of each user h
by kajalchopade071 Path Finder in Splunk Search 12-15-2021
0 2
0
2
noott211
I want to see the result values of Src_ip and dst_ip are the same and "ok" and the number of these result values. Wha...
by noott211 Path Finder in Splunk Search 12-15-2021
0 1
0
1
mato666666
Hi,I have a very specific problem. I have a field with following values at different timestamps. Example:1,3,2002,3,4...
by mato666666 Explorer in Splunk Search 12-15-2021
0 5
0
5
lmonahan
Is it valid to use a where clause to compare a string value to a multivalue field in order to know if that value is o...
by lmonahan Path Finder in Splunk Search 12-14-2021
0 1
0
1
rberman
Hi, I have a field called "catgories" whose value is in the format of a JSON array. The array is a list of one or mor...
by rberman Path Finder in Splunk Search 12-14-2021
0 4
0
4
jbreeves
Hi, I'm attempting to build a query to find destination IP addresses that became source IPs for traffic in a 5min win...
by jbreeves New Member in Splunk Search 12-14-2021
0 3
0
3
umeshcreddy
Hi Actually i made  lookup with the list of ip address in .csv file. I want to write a query if there is traffic from...
by umeshcreddy Engager in Splunk Search 12-14-2021
0 1
0
1
jaibalaraman
Hi Team I am trying to find out recent CVE-2021-44228( log4j)I tried " index=aws *log4j*", nut not sure how to find o...
by jaibalaraman Path Finder in Splunk Search 12-14-2021
0 5
0
5
SplnkUse
HelloI am a Splunk user, not admin, and I seem to be able to do a search like:| rest splunk_server=local servicesNS/-...
by SplnkUse Path Finder in Splunk Search 12-14-2021
0 0
0
0
shreyasamin64
need help on using command strptime/strftime EX: input: December 7, 2021 1:00:01 PM         output: 12/1/2021   13:00...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 2
0
2
shreyasamin64
need help on removing only endpoint from the data set input :                                                        ...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 1
0
1
09128028400
Hello every bodyI have been struggling with a serious problem recently my splunk version is 7.2 when I use  span Comm...
by 09128028400 Engager in Splunk Search 12-14-2021
0 6
0
6
amagson
Hello all,I need a hand with a basic Splunk search. I appreciate this is Splunk 101 basics, but with other commitment...
by amagson Loves-to-Learn in Splunk Search 12-14-2021
0 2
0
2
rxalex
Hi Folks, I have been trying to pull some data associated with latest Run ID (associated with execution), I am having...
by rxalex Engager in Splunk Search 12-14-2021
0 2
0
2
poiromaniax
Hey all,Firstly - the title doesnt actually encapsulate what Im trying to do, Ill try break it down simply:I have AWS...
by poiromaniax Explorer in Splunk Search 12-13-2021
0 2
0
2
Sarvoday
0
1
phamxuantung
I try to use the query eval ID = if(ORG="MC",ID=substr(ID,-6),0) Basically, I want in my result, if ORG="MC", I want ...
by phamxuantung Communicator in Splunk Search 12-13-2021
0 1
0
1
kapoorsumit2020
Team,I'm newbie in writing Splunk queries. Could you please provide me guidance how to design a SPL for below use cas...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-13-2021
0 7
0
7
AndreiIssakov
Hello!Could somebody please suggest if it is possible to do a map search search more effectively?What I am trying to ...
by AndreiIssakov Explorer in Splunk Search 12-13-2021
0 6
0
6
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...