Splunk Search

Splunk Search
Community Activity
Harshi1993
My query is :index="stage*" source="*record service*" | eval type=case(like(message, "%successful generated account%"...
by Harshi1993 New Member in Splunk Search 09-02-2021
0 3
0
3
mcaulsc
Hi,I have data as below sample:Date Time val1 val2 val3 ......21/08/31 01:00:00 2 1 2 2 2 2 2 1 1 2 69 1 0 2 0 0 3 32...
by mcaulsc Path Finder in Splunk Search 09-02-2021
0 2
0
2
splunknewbie81
Hi All, I am having some trouble extracing out the following with the following details 1. username 2. Default Msg3. ...
by splunknewbie81 Engager in Splunk Search 09-02-2021
0 12
0
12
btshivanand
Hi all,We have 3 search heads are in cluster. serach head 1 is captain.Recently we upgraded to 7.2.3 to 8.0.3.after t...
by btshivanand Path Finder in Splunk Search 09-01-2021
0 3
0
3
rczone
Hello All, So i have a field like below with JSON file   {"results_appcodes": [{"count": 2, "app_code": "XYZ", "group...
by rczone Path Finder in Splunk Search 09-01-2021
0 7
0
7
SplunkDash
Hello,How I would write my Props Configuration (Tme Prefix, Time Format,  LINE/EVENT Breaker...etc) for following HTM...
by SplunkDash Motivator in Splunk Search 09-01-2021
0 5
0
5
SplunkDash
Hello,I have some issues using following input configuration file for windows machine: [monitor://T:\Toshtest\logs\te...
by SplunkDash Motivator in Splunk Search 09-01-2021
0 1
0
1
IrishGuru
Hello, I have an indexed list of internal IPs that I have been able to get a count for based on a CIDR list on a CSV ...
by IrishGuru Loves-to-Learn Lots in Splunk Search 09-01-2021
0 0
0
0
spicy
I have a list of hundreds of string values that need to be extracted from a fieldthe problem is the values that need ...
by spicy Path Finder in Splunk Search 09-01-2021
0 5
0
5
rj1
I'm trying to create a query that basically says: Show me events that contain A, B, C or D where the latest is A or B...
by rj1 Engager in Splunk Search 09-01-2021
0 2
0
2
aubine
(This is a continuation of https://community.splunk.com/t5/Splunk-Search/Creating-a-search-that-looks-up-values-from-...
by aubine Explorer in Splunk Search 09-01-2021
0 0
0
0
aubine
I have two logfiles, logfile1.log and logfile2.log. I have created their own field extractions for both of them. Here...
by aubine Explorer in Splunk Search 09-01-2021
0 4
0
4
newtosplunk14
From the logs, I need to get the count of events from the below msg field value which matches factType=COMMERCIAL and...
by newtosplunk14 Explorer in Splunk Search 09-01-2021
0 2
0
2
klaudiac
Hi guys,  Probably very simple question but I just tangled myself in the logic. I want to create 2 fields, one with t...
by klaudiac Path Finder in Splunk Search 09-01-2021
0 6
0
6
marco_carolo
Hello there.What I'm trying to do is the following: search | bucket span=60s _time | stats count by _time | ... I wan...
by marco_carolo Path Finder in Splunk Search 09-01-2021
0 13
0
13
BernardEAI
I'm working on calculating the storage space taken up by a specific user. I would like to calculate the total size of...
by BernardEAI Communicator in Splunk Search 09-01-2021
0 4
0
4
SamHTexas
I need to find a list of saved searches that don't use the index name in searching please. Any way to list the name o...
by SamHTexas Builder in Splunk Search 08-31-2021
0 4
0
4
Madhusri
Hi,Current tableExpectedfstatuscountsuccess604Userdefined39 Need to sum the "password mismach","policy policy constra...
by Madhusri Engager in Splunk Search 08-31-2021
0 2
0
2
sahil237888
Hi Team, I have data with me as below. 2021-08-31 00:05:28|Test|Event|[c.f.d.aop.sql.database ] 2ms :testing82021-08-...
by sahil237888 Path Finder in Splunk Search 08-31-2021
0 1
0
1
SamHTexas
How do I search (any SPLs) for Dashboards that are not working (either built-in or created by users) or having errors...
by SamHTexas Builder in Splunk Search 08-31-2021
0 1
0
1
SamHTexas
How do I make sure the the ES KVstores are working & mapped properly to use them & avoid such errors? I appreciate so...
by SamHTexas Builder in Splunk Search 08-31-2021
0 0
0
0
SamHTexas
I am getting an error with MITRE ATT&CK app that the API key needs to be corrected. Please advise. Thanks a million.
by SamHTexas Builder in Splunk Search 08-31-2021
0 0
0
0
iamsplunker
Hello Splunk Community,I've a query which lists accountNumber , targetAccountNumber, eventType, eventTimeThe query is...
by iamsplunker Communicator in Splunk Search 08-31-2021
0 4
0
4
nnonm111
I'm going to stats through two lookups.srcip.csv fieldsrc_ip , subnetmaksdest.csv fielddest_ip,subnetmakssrc_ip , des...
by nnonm111 Path Finder in Splunk Search 08-31-2021
0 1
0
1
moinyuso96
The contents of my lookup file, test12345.csv is shown below.ProductNumber,SerialNumber,StatusDateTime,Status"A12345 ...
by moinyuso96 Path Finder in Splunk Search 08-31-2021
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors