Splunk Search

Splunk Search
Community Activity
Cydraech
Greetings dear Splunk Community, I'll try to keep it short and simple:I have a Query that gets multiple fields, but o...
by Cydraech Explorer in Splunk Search 10-26-2021
0 2
0
2
GRC
Hello champions,I run the below 1,2,3 queries on the given datasets to find out which users ran the enable command on...
by GRC Path Finder in Splunk Search 10-26-2021
0 8
0
8
srinivas_gowda
Hello all, I am trying to extract a field from the below event and the extraction is working fine on events that is c...
by srinivas_gowda Path Finder in Splunk Search 10-26-2021
0 3
0
3
97WaterPolo
Hello,So this is my first time trying to consolidate logs and use the data extraction and I am a little lost. I have ...
by 97WaterPolo Engager in Splunk Search 10-26-2021
0 4
0
4
ankitarath2011
I have multiple concurrent saved searches(around 6). All searches have outputlookup command which is writing to separ...
by ankitarath2011 Path Finder in Splunk Search 10-25-2021
0 0
0
0
phamxuantung
I have a rather complicated query that go like this:  index=* source=* earliest=-4mon@mon latest=@mon RESPONSE_CODE="...
by phamxuantung Communicator in Splunk Search 10-25-2021
0 3
0
3
GRC
Hi Champions,In this below mentioned dataset. I want to create a conditional splunk query. Ex: I want to check first ...
by GRC Path Finder in Splunk Search 10-25-2021
0 3
0
3
Bhanuchander
While running arules command across multiple fields, The 'Given fields' generated with various 'Implied fields'. But ...
by Bhanuchander Loves-to-Learn in Splunk Search 10-25-2021
0 0
0
0
SplnkUse
Hello! A dashboard runs a search and I want to create an alert for this. So I replicated the search code to the alert...
by SplnkUse Path Finder in Splunk Search 10-25-2021
0 4
0
4
djreschke
I have a props conf file that is not parsing data as i expected. I can see in the raw log that the IIS log has the he...
by djreschke Communicator in Splunk Search 10-25-2021
0 1
0
1
sonomauser
Hello Splunk Wizards,I know there are plenty of people who've had similar issues, but I haven't been able to use thei...
by sonomauser Explorer in Splunk Search 10-25-2021
0 6
0
6
g_paternicola
Hello everyone,I have the following inputs.conf file which is actually working for the first 2 stanza, but not for th...
by g_paternicola Path Finder in Splunk Search 10-25-2021
0 0
0
0
maramel
I'm trying to use the map command and it seems to fail when I try using some functions within the subsearch (specific...
by maramel Engager in Splunk Search 10-25-2021
0 1
0
1
candrew0710
Hello, I am new to Splunk and I am looking for a way to write a rule to detect SMB traffic. Thanks
by candrew0710 New Member in Splunk Search 10-25-2021
0 0
0
0
email2vamsi
Hi Experts,|search filed1=Enabled OR "Enabled" OR "Disabled" OR DisabledThe above search is returning four rows.If i ...
by email2vamsi Explorer in Splunk Search 10-25-2021
0 4
0
4
devak
HI AllI have IP flow based information being ingested into Splunk, which consists of source_ip, source_port, destinat...
by devak Engager in Splunk Search 10-25-2021
0 2
0
2
anooshac
Hi all, I have a xml file as below.<?xml version="1.0" encoding="UTF-8"?><suite name="abc" timestamp="20.08.2021 15:4...
by anooshac Communicator in Splunk Search 10-25-2021
0 4
0
4
Bleepie
Dear Splunk community,In Splunk, I am looking for logs that say "started with profile: [profile name]" and retrieve t...
by Bleepie Communicator in Splunk Search 10-25-2021
0 1
0
1
Ashwini008
Hi,I have a radio button with 3 choice values. When any of the radio button is clicked or hovered it should show me s...
by Ashwini008 Builder in Splunk Search 10-25-2021
0 3
0
3
neerajs_81
All, I have a simple requirement to list failed login attempts from same src_ip in a span of 5 mins.  i have seen 2 o...
by neerajs_81 Builder in Splunk Search 10-25-2021
0 1
0
1
aseqa
I have configured an automatic lookup, however when I try to do a search it gives a message "Could not load lookup=LO...
by aseqa New Member in Splunk Search 10-25-2021
0 0
0
0
deca2499
Hey all,I hope this is the correct board for this question, but I am having an issue when I try to export a search to...
by deca2499 Engager in Splunk Search 10-24-2021
0 9
0
9
mgbersales
Hi, I am trying to filter events based on a lookup table with a time range. My lookup table looks like this: startDay...
by mgbersales Loves-to-Learn in Splunk Search 10-24-2021
0 1
0
1
cyberkmb
0
0
bdunstan
Hi,I have a query which I am not sure why its not working,Assume I have the following JSON record, which has been ext...
by bdunstan Path Finder in Splunk Search 10-24-2021
0 1
0
1
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors