Splunk Search

Splunk Search
Community Activity
RobHoz
Hello, I'm trying to filter one lookup with the values of an other lookup.This is the situation:Lookup roles.csv cont...
by RobHoz Engager in Splunk Search 11-22-2021
0 2
0
2
SMM10
We have specific ID's that track how request process through the system. What I want to do search for all these ID's ...
by SMM10 Explorer in Splunk Search 11-21-2021
0 2
0
2
lilvermi
I have raw data, I would like to search for domains within the data, output it to a field and then run stats to show ...
by lilvermi New Member in Splunk Search 11-21-2021
0 1
0
1
indeed_2000
Hi I got this error when I search on specific index.index="myindex"Error in 'IndexScopedSearch': The search failed. M...
by indeed_2000 Motivator in Splunk Search 11-20-2021
0 2
0
2
mbojorq3
I am trying to extract the name of log output but struggling with how to. I have this query<query>index=dap ("user lo...
by mbojorq3 New Member in Splunk Search 11-19-2021
0 1
0
1
dtccsundar
I am using below query,index=A sourcetype IN (Compare,Fire)| fillnull value="" | search Name="*SWZWZQ0001*" OR Name="...
by dtccsundar Path Finder in Splunk Search 11-19-2021
0 2
0
2
bergen288
My python is 3.8.5 and splunk-sdk is 1.6.16.  My Splunk developer gives me a URL and I get its search string to retri...
by bergen288 Engager in Splunk Search 11-19-2021
0 7
0
7
cfloquet
Hello, thank you for taking the time to read and consider my question. I'm trying to integrate a .json file which con...
by cfloquet Path Finder in Splunk Search 11-19-2021
0 11
0
11
bogdan_nicolesc
Hi there, I'm trying so hard to do a new field in Splunk, but i don't know where i do "wrongs".I would like to extrac...
by bogdan_nicolesc Communicator in Splunk Search 11-19-2021
0 5
0
5
axm1295
Hi all,I am new to Splunk and have been trying to work on a use case to detect anomalous switches from one type of ac...
by axm1295 New Member in Splunk Search 11-19-2021
0 2
0
2
dtccsundar
Hi ,Like below ,Sourcetype =FireName                  OS Compare_VersionCompare_Agent InstalledsysidABC11        wind...
by dtccsundar Path Finder in Splunk Search 11-19-2021
0 4
0
4
dtccsundar
i am not able differentiate which sourcetype the Name belongs too after outer join.This is needed becoz when the Name...
by dtccsundar Path Finder in Splunk Search 11-19-2021
0 6
0
6
Glasses
Hi - I have been not having much luck creating what I need.I am looking for the best way to display the percentages o...
by Glasses Builder in Splunk Search 11-18-2021
0 1
0
1
sureshtskumar
Hi,I am working with my proxy logs and trying to find a way to get same URLs visited by multiple clients. To add clar...
by sureshtskumar Explorer in Splunk Search 11-18-2021
0 4
0
4
JeremyJ123
I am trying to search through transactions and check their response codes so that we can determine a percentage of fa...
by JeremyJ123 New Member in Splunk Search 11-18-2021
0 1
0
1
Durwood
I am looking to identify specific assets that have not been logged into in over a set time. I am fairly new to all of...
by Durwood Engager in Splunk Search 11-18-2021
0 6
0
6
bhargavi
Hello all, kindly help with Regex..I am seeing the below messages in splunkd logs. Though values are actually being e...
by bhargavi Path Finder in Splunk Search 11-18-2021
0 5
0
5
colny
Hi, The cloudtrail logs in splunk come in without proper event break; I only got it to recognize the first event's ti...
by colny Engager in Splunk Search 11-18-2021
0 4
0
4
rafadvega
Hi,I would like to count the values of a multivalue field by value. For example: | makeresults | eval values_type=sp...
by rafadvega Path Finder in Splunk Search 11-18-2021
0 1
0
1
robertlynch2020
@Kenshiro70  I have just read your most brilliant answer hearhttps://community.splunk.com/t5/Splunk-Search/What-exact...
by robertlynch2020 Influencer in Splunk Search 11-18-2021
0 0
0
0
Mick_OBrien
I have a search string that gives me count of txns processed by a job.......| rex field=_raw "Total txns:(?<TxnsCount...
by Mick_OBrien Path Finder in Splunk Search 11-18-2021
0 11
0
11
sowmiyansk
Can someone please help me with the below Query 1. Account lockouts(4740) and then go back in time one hour to find l...
by sowmiyansk New Member in Splunk Search 11-18-2021
0 4
0
4
mm12
Hi All,I need splunk query to identify orders which are ordered but not submitted even after 72 hoursAny one help me ...
by mm12 Explorer in Splunk Search 11-18-2021
0 8
0
8
kranthi851
Hi How to create an alert for lockouts in Windows Event Logs with the details of failed activity in last hour by src...
by kranthi851 New Member in Splunk Search 11-18-2021
0 8
0
8
SIEMStudent
Hi guys,I have a doubt regarding the mapping of connection from the same source IP to different destination IP.In my ...
by SIEMStudent Path Finder in Splunk Search 11-18-2021
0 2
0
2
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...
Top Solution Authors