Splunk Search

Splunk Search
Community Activity
splunk_u1
Hi there!Please allow me to admit, I'm newbie to splunk + sigma  rules for detection.In my test environment, I have i...
by splunk_u1 Engager in Splunk Search 09-14-2021
1 0
1
0
SplunkDash
Hello,I have some issues writing PROPS configuration for XML source file. Sample XML events (2 Events) are given belo...
by SplunkDash Motivator in Splunk Search 09-14-2021
0 2
0
2
_joe
I am looking for a way to limit user searches to only the most recent 30 days, specifically for SmartStore purposes. ...
by _joe Contributor in Splunk Search 09-14-2021
0 5
0
5
Sam2
Hello all, I'm trying to get the stats of the count of events per day, but also the average. ...| stats count by...
by Sam2 Explorer in Splunk Search 09-14-2021
1 7
1
7
AKG1_old1
Hello, I am using child dataset in data model. Not sure how to use fields which are inherited from parent data model...
by AKG1_old1 Builder in Splunk Search 09-14-2021
0 1
0
1
Cydraech
Hello people,I'm very new to Splunk and I'm trying to create a dashboard with the "Statistics Table" Visualisation, t...
by Cydraech Explorer in Splunk Search 09-14-2021
0 3
0
3
SamHTexas
Need help with an SPL to create a search for Please. /opt/splunk/etc/apps/meta_woot/lookups/meta_woot_server_guid.csv...
by SamHTexas Builder in Splunk Search 09-13-2021
0 1
0
1
A44D
There are some keywords that cannot be searched after changing the App.Even more specific keywords within a specific ...
by A44D Explorer in Splunk Search 09-13-2021
0 3
0
3
puet
So I'm trying to change a token when i click a button.Tried it like this:require([ 'jquery', 'splunkjs/mvc', ...
by puet Explorer in Splunk Search 09-13-2021
0 4
0
4
GoodApprentice
Hallo,i am trying to make a Dashboard that takes the time from reports of jobs.That time is not the same as the time ...
by GoodApprentice New Member in Splunk Search 09-13-2021
0 1
0
1
wasifchowdhury
 I have this query and I want to add another data series/line to this chart. How can I do it?index="eniq_voice"|where...
by wasifchowdhury Explorer in Splunk Search 09-13-2021
0 3
0
3
mztopp
For example:|  tstats count from datamodel=test where * by test.url, test.user | rename test.* AS *| search NOT    [ ...
by mztopp Explorer in Splunk Search 09-13-2021
0 4
0
4
Susha
Hi Team,I want to transpose few fields as below ..(index=abc OR index=def) category= * OR NOT blocked =0 AND NOT bloc...
by Susha Engager in Splunk Search 09-13-2021
0 5
0
5
osasfrancis
I have the below test raw logsCEF:0|Forcepoint|Forcepoint DLP|8.8.0|55564097|DLP Syslog|2| act=Permitted duser=destus...
by osasfrancis Path Finder in Splunk Search 09-13-2021
0 6
0
6
nathanluke86
I have a search query to display external files shares that are active (Sharepoint/Onedrive).  This is working and sh...
by nathanluke86 Communicator in Splunk Search 09-13-2021
0 1
0
1
g_paternicola
 Hi everyone, I'm trying to get a simple text from a raw event, but I can't make it works.The event looks like this:a...
by g_paternicola Path Finder in Splunk Search 09-13-2021
0 1
0
1
MuratKuru
Hi AllWe have a distributed environment (no cluster).Splunk Enterprise Version 8.1.3Is there a way to create a dashbo...
by MuratKuru Explorer in Splunk Search 09-13-2021
0 1
0
1
PavanSeerapu
I'm trying to extract field That looks like "Alert-source-key":"[\"abcdd-gdfc-mb40-a801-e40fd9db481e\"]"  I have trie...
by PavanSeerapu Explorer in Splunk Search 09-13-2021
0 4
0
4
indeed_2000
Hiwhat is the spl command to extract users.Here is the sample:2021-09-12 21:40:03,938 ERROR [APPNAME] User H83952 inv...
by indeed_2000 Motivator in Splunk Search 09-13-2021
0 1
0
1
rkishoreqa
Hi all,  I have two chart queries to get the success count and error count which are working as expected.  Now I want...
by rkishoreqa Communicator in Splunk Search 09-13-2021
0 2
0
2
alonKri
Hi Splunk team, I would like to receive your dedicated help. I have a string field, the field's structure is name_tim...
by alonKri Explorer in Splunk Search 09-13-2021
0 7
0
7
dtccsundar
Hi,I have to get % of 2 and 3 values in a same field .Status count True       200False       50Error      10exc      ...
by dtccsundar Path Finder in Splunk Search 09-13-2021
0 1
0
1
robertlynch2020
HiBelow is a simple example of what I am trying to do.I am trying to remove the duplicate out of the process name. So...
by robertlynch2020 Influencer in Splunk Search 09-13-2021
0 2
0
2
nikitha15
Hi ,I want to add a text box in a dashboard panel and the manual input value of that textbox should be added to a new...
by nikitha15 Explorer in Splunk Search 09-13-2021
0 1
0
1
szone
hi all,I have multiple string that are regex, i want to find logs that match with this string.this is a example of my...
by szone Engager in Splunk Search 09-13-2021
0 5
0
5
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...