Splunk Search

Splunk Search
Community Activity
indeed_2000
Hiwhat is the rex for mq error code here is the log:2021-10-08 06:52:12,785 ERROR TOPIC-00000 [Utility] MQJCA1011: Fa...
by indeed_2000 Motivator in Splunk Search 10-11-2021
0 1
0
1
indeed_2000
hiwhat is the rex for error number and error message of this log:  (separately)23:43:51.411 app module: 100:  Not Fou...
by indeed_2000 Motivator in Splunk Search 10-11-2021
0 1
0
1
shreyarathod
Query to see which application has followed which integration method to on board the data on Splunk cloud like HEC,TC...
by shreyarathod New Member in Splunk Search 10-11-2021
0 0
0
0
plunkzombie
I need a way to evaluate a simple math expression.The following query works, and expr evaluates to result with a valu...
by plunkzombie Engager in Splunk Search 10-11-2021
0 4
0
4
joe06031990
Hi,I'm trying to build a search to find the count, min,max and Avg within the 99th percentile, all work apart from th...
by joe06031990 Communicator in Splunk Search 10-11-2021
0 4
0
4
abdul
i am getting two diffrent results in total. query1 is providing acurate result. query2 as soom as adding |lookup loca...
by abdul Explorer in Splunk Search 10-10-2021
0 2
0
2
SplunkDash
Hello,I have 4 python scripts  to parse data that we receive in Linux machine once a day where HF has installed. Curr...
by SplunkDash Motivator in Splunk Search 10-10-2021
0 3
0
3
indeed_2000
HiI have log file like this, need to extract "id" from lines that A=20 and match these lines to lines where that B=10...
by indeed_2000 Motivator in Splunk Search 10-10-2021
0 15
0
15
kjordans
I need to create a table that includes the filename, the domain name of which file came from, the source IP, the dest...
by kjordans Engager in Splunk Search 10-09-2021
1 1
1
1
danifor10
Hello I am looking a simple SPL to  to detect activity from users without MFA in AWS.I have the search below which su...
by danifor10 New Member in Splunk Search 10-09-2021
0 0
0
0
shashi584
I want to delete this field (VID) from one of my search query, this is not available under  Field extractions.and wha...
by shashi584 Explorer in Splunk Search 10-09-2021
0 3
0
3
Morrel
Hallo.can anyone please help me.i want search sourcetype for this IP10.2.123.123 OR 22.222.222.22 OR 33.333.333.33 | ...
by Morrel New Member in Splunk Search 10-09-2021
0 2
0
2
kumarnis45
Hi,     I have recently integrated and migrated AWS Simple Queue Serivce (SQS) logs to splunk. I am trying to search ...
by kumarnis45 Path Finder in Splunk Search 10-09-2021
0 0
0
0
SplunkDash
Hello,I have Universal Forward and Heavy Forward in Linux machine, how would I stop and restart them.  Any help will ...
by SplunkDash Motivator in Splunk Search 10-09-2021
0 3
0
3
indeed_2000
hi i want to use sendmail spl command but it give me below errorcommand="sendemail", (535, '5.7.3 Authentication unsu...
by indeed_2000 Motivator in Splunk Search 10-08-2021
0 4
0
4
SamHTexas
We have Splunk Ent. + ES. I have a dashboard that I 'd like to install in Security Essentials. What level permission ...
by SamHTexas Builder in Splunk Search 10-08-2021
0 0
0
0
jaydiare
I need help to use the values from a lookup table into multiple fields, where the output from the lookup table is a l...
by jaydiare Explorer in Splunk Search 10-08-2021
0 2
0
2
data_explorer88
I have a list of files name under one field called "attachment"  and I would like to split this string into multiple ...
by data_explorer88 Explorer in Splunk Search 10-08-2021
0 2
0
2
yk010123
I am trying to produce the following output :app_namerequest_idtimeworkload at the time(requests per second)App112310...
by yk010123 Path Finder in Splunk Search 10-08-2021
0 4
0
4
graziaedu
Hello,I have a field with this values/v1/accounts/96ea01b5-7ea7-4dc6-b534-39ae8b114bba/transactions/v1/accounts/ff572...
by graziaedu Explorer in Splunk Search 10-08-2021
0 4
0
4
Gunnar
Hi all,strange thing - when using mean() and avg() in the same stats command, whichever is written first is empty, wh...
by Gunnar Explorer in Splunk Search 10-08-2021
0 6
0
6
mlg
Hi,I am new to Splunk and working with parking records. I am calculating the current wait_time based off upcoming par...
by mlg Observer in Splunk Search 10-08-2021
0 1
0
1
dtccsundar
Hi,my regex was like below ,search| rex field=_raw "Status=(?<Status>\"\w+\s+\w+\".*?)," |stats count by StatusMy out...
by dtccsundar Path Finder in Splunk Search 10-08-2021
0 2
0
2
mlg
Hi, I am new to Splunk and working with parking records. Within my events, I have a permit_expiry field, which is a d...
by mlg Observer in Splunk Search 10-08-2021
0 1
0
1
yvassilyeva
Hi!I have the following data and would like to check, for those records with the same ID, if one record has CREATED_D...
by yvassilyeva Path Finder in Splunk Search 10-08-2021
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...