Splunk Search

Splunk Search
Community Activity
codekiln
I have a JSON-based log file for which every line is a valid JSON document. When searching it like this:source="/path...
by codekiln Explorer in Splunk Search 10-26-2021
0 2
0
2
amitkore3483
Hi,I have logs coming with server names listed into it and my requirement is to the distinct count of server by assig...
by amitkore3483 New Member in Splunk Search 10-26-2021
0 2
0
2
anooshac
This question is related my previous post.https://community.splunk.com/t5/Splunk-Search/XML-field-Extraction/m-p/5719...
by anooshac Communicator in Splunk Search 10-26-2021
0 4
0
4
Cydraech
Greetings dear Splunk Community, I'll try to keep it short and simple:I have a Query that gets multiple fields, but o...
by Cydraech Explorer in Splunk Search 10-26-2021
0 2
0
2
GRC
Hello champions,I run the below 1,2,3 queries on the given datasets to find out which users ran the enable command on...
by GRC Path Finder in Splunk Search 10-26-2021
0 8
0
8
srinivas_gowda
Hello all, I am trying to extract a field from the below event and the extraction is working fine on events that is c...
by srinivas_gowda Path Finder in Splunk Search 10-26-2021
0 3
0
3
97WaterPolo
Hello,So this is my first time trying to consolidate logs and use the data extraction and I am a little lost. I have ...
by 97WaterPolo Engager in Splunk Search 10-26-2021
0 4
0
4
ankitarath2011
I have multiple concurrent saved searches(around 6). All searches have outputlookup command which is writing to separ...
by ankitarath2011 Path Finder in Splunk Search 10-25-2021
0 0
0
0
phamxuantung
I have a rather complicated query that go like this:  index=* source=* earliest=-4mon@mon latest=@mon RESPONSE_CODE="...
by phamxuantung Communicator in Splunk Search 10-25-2021
0 3
0
3
GRC
Hi Champions,In this below mentioned dataset. I want to create a conditional splunk query. Ex: I want to check first ...
by GRC Path Finder in Splunk Search 10-25-2021
0 3
0
3
Bhanuchander
While running arules command across multiple fields, The 'Given fields' generated with various 'Implied fields'. But ...
by Bhanuchander Loves-to-Learn in Splunk Search 10-25-2021
0 0
0
0
SplnkUse
Hello! A dashboard runs a search and I want to create an alert for this. So I replicated the search code to the alert...
by SplnkUse Path Finder in Splunk Search 10-25-2021
0 4
0
4
djreschke
I have a props conf file that is not parsing data as i expected. I can see in the raw log that the IIS log has the he...
by djreschke Communicator in Splunk Search 10-25-2021
0 1
0
1
sonomauser
Hello Splunk Wizards,I know there are plenty of people who've had similar issues, but I haven't been able to use thei...
by sonomauser Explorer in Splunk Search 10-25-2021
0 6
0
6
g_paternicola
Hello everyone,I have the following inputs.conf file which is actually working for the first 2 stanza, but not for th...
by g_paternicola Path Finder in Splunk Search 10-25-2021
0 0
0
0
maramel
I'm trying to use the map command and it seems to fail when I try using some functions within the subsearch (specific...
by maramel Engager in Splunk Search 10-25-2021
0 1
0
1
candrew0710
Hello, I am new to Splunk and I am looking for a way to write a rule to detect SMB traffic. Thanks
by candrew0710 New Member in Splunk Search 10-25-2021
0 0
0
0
email2vamsi
Hi Experts,|search filed1=Enabled OR "Enabled" OR "Disabled" OR DisabledThe above search is returning four rows.If i ...
by email2vamsi Explorer in Splunk Search 10-25-2021
0 4
0
4
devak
HI AllI have IP flow based information being ingested into Splunk, which consists of source_ip, source_port, destinat...
by devak Engager in Splunk Search 10-25-2021
0 2
0
2
anooshac
Hi all, I have a xml file as below.<?xml version="1.0" encoding="UTF-8"?><suite name="abc" timestamp="20.08.2021 15:4...
by anooshac Communicator in Splunk Search 10-25-2021
0 4
0
4
Bleepie
Dear Splunk community,In Splunk, I am looking for logs that say "started with profile: [profile name]" and retrieve t...
by Bleepie Communicator in Splunk Search 10-25-2021
0 1
0
1
Ashwini008
Hi,I have a radio button with 3 choice values. When any of the radio button is clicked or hovered it should show me s...
by Ashwini008 Builder in Splunk Search 10-25-2021
0 3
0
3
neerajs_81
All, I have a simple requirement to list failed login attempts from same src_ip in a span of 5 mins.  i have seen 2 o...
by neerajs_81 Builder in Splunk Search 10-25-2021
0 1
0
1
aseqa
I have configured an automatic lookup, however when I try to do a search it gives a message "Could not load lookup=LO...
by aseqa New Member in Splunk Search 10-25-2021
0 0
0
0
deca2499
Hey all,I hope this is the correct board for this question, but I am having an issue when I try to export a search to...
by deca2499 Engager in Splunk Search 10-24-2021
0 9
0
9
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...