Splunk Search

Splunk Search
Community Activity
corehan
Hello dears,How can i sort these field values ?Field = "port"0/1/0/2/0/8/0/7/0/2/0/3/0/5/0/2/0/6/0/3/0/16/0/20/18/0/6...
by corehan Explorer in Splunk Search 09-30-2021
0 16
0
16
Abe_T
I am sure I am sure I am missing something easy but, for some reason, when I compare these two values (they are in st...
by Abe_T Explorer in Splunk Search 09-30-2021
0 6
0
6
tkerr1357
Hi All,I am looking to create an alert based on the following base search. index=wineventlog w19tax.exe app_name=W19T...
by tkerr1357 Path Finder in Splunk Search 09-30-2021
0 2
0
2
pacifikn
Hello dear All, 1* How to calculate average size of a syslog message for a particular source in GB using Splunk query...
by pacifikn Communicator in Splunk Search 09-30-2021
0 2
0
2
yko84109
I have lookup with CIDR advanced field which contains: id cidr_field 1 1.1.1.1/24 2 8.8.8.8/24  If I se...
by yko84109 Loves-to-Learn in Splunk Search 09-30-2021
0 3
0
3
Abhineet
we have two device AUSTDPVPN1 and AUSTDPVPN2 and current user logged in count on device as 0 and 2867.I want whenever...
by Abhineet Loves-to-Learn Everything in Splunk Search 09-30-2021
0 9
0
9
TheColorBlack
Hey guys, I need some quick help creating a nested stats table and grouping by multiple values within that table. My ...
by TheColorBlack Path Finder in Splunk Search 09-30-2021
0 1
0
1
PickleRick
I was wondering... how are foreach-generated searches treated regarding the searches limits?I mean - normally you hav...
by SplunkTrust SplunkTrust in Splunk Search 09-30-2021
0 2
0
2
rodrigomarfei
Hello,I need a help with a search that seems very easy, but I'm unable to achieve the results I want.The events are r...
by rodrigomarfei Explorer in Splunk Search 09-30-2021
0 3
0
3
dababi1234
I am new to Splunk and would appreciate if anyone helps me on this. I would like to set up a Splunk alert for SocketT...
by dababi1234 New Member in Splunk Search 09-30-2021
0 5
0
5
gabrieleguidoni
Hello I would like to pass a value from a joined search (e.g. in this case the "Side") to the final table.I tried dif...
by gabrieleguidoni Loves-to-Learn in Splunk Search 09-30-2021
0 1
0
1
korhanacar
Hi Guys,I have a question about the data model.   Eventually, I want to create complex correlation rules by finding m...
by korhanacar Engager in Splunk Search 09-30-2021
0 0
0
0
priyangshupal
I have a json like this: { "A": [ { "B": [ { "status": "2", "value": "1" ...
by priyangshupal Engager in Splunk Search 09-30-2021
0 1
0
1
splunkcol
Hello there,I have spent a good time researching lateral movement in Splunk, unfortunately I have not found much.I ha...
by splunkcol Builder in Splunk Search 09-29-2021
0 2
0
2
jaibalaraman
Hi Team When i tried running the below eval command, i am getting some error message often.I wrote this below command...
by jaibalaraman Path Finder in Splunk Search 09-29-2021
0 8
0
8
tmarlette
So I have a search that triggers based upon how much memory is being used on any of my linux machines.   index=nix so...
by tmarlette Motivator in Splunk Search 09-29-2021
0 0
0
0
tinylund
| rex field=_raw "(?<dscvIP>[^\.]\d+\.\d+\.\d+\.\d+[\s|\:])"Using the above rex command to try to capture IP addresse...
by tinylund Explorer in Splunk Search 09-29-2021
0 5
0
5
willprince
I constantly see the below error on my search head. What causes this and how do I go about fixing it. I have removed...
by willprince Engager in Splunk Search 09-29-2021
10 9
10
9
GenRockeR
Hi guys. Why Splunk have many errors in log file and what can I do in this situation? 05-17-2019 18:58:08.036 +0300...
by GenRockeR Explorer in Splunk Search 09-29-2021
0 8
0
8
TheBravoSierra
I run a search head cluster with Splunk Enterprise. Typically I update apps via the back end CLI, but am wondering if...
by TheBravoSierra Path Finder in Splunk Search 09-29-2021
0 4
0
4
Shaurdonnay
I am trying to figure out how to pull fields to show the exact count of numbers and letters in a result. Like, if I h...
by Shaurdonnay Engager in Splunk Search 09-29-2021
0 2
0
2
mfudali
Hi, I have a Table created by: eval Actor=actor |eval "Total Time (max/avg/p50/p99)"=maxT + ", " + avgT + ", " + p50T...
by mfudali Explorer in Splunk Search 09-29-2021
0 1
0
1
SplunkDash
Hello,I have some issues in writing PROPS configuration file for the sample data/events given below. I have given 4 e...
by SplunkDash Motivator in Splunk Search 09-29-2021
0 2
0
2
Ida_2017
Dear communityI am struggling with how to allow different format in a search input, but still finding the correspondi...
by Ida_2017 Explorer in Splunk Search 09-29-2021
0 5
0
5
neerajs_81
Hello All,I have a search query that performs lookups against a CSV file and outputs only those hosts that are in the...
by neerajs_81 Builder in Splunk Search 09-29-2021
0 2
0
2
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...