Splunk Search

Splunk Search
Community Activity
shugup2923
I have time field which have values such as 9AM-10PM, 10:00AM-11:00PM, I want to change 9AM-10PM to 9:00AM-10:00 PM, ...
by shugup2923 Path Finder in Splunk Search 08-25-2021
0 3
0
3
splunky_monkey
I am trying to set up an alert in Splunk that will email a user whenever their Windows session is X days old. It woul...
by splunky_monkey Loves-to-Learn Lots in Splunk Search 08-25-2021
0 0
0
0
sam1010
 So I have added a table drilldown to this pie chart but I need the rows in table displayed according to the value I ...
by sam1010 Explorer in Splunk Search 08-25-2021
0 3
0
3
cheriemilk
Hi team,I have below data in splunk. And I want to get the time duration when below range.ACT start with "AUTOSAVEFOR...
by cheriemilk Path Finder in Splunk Search 08-24-2021
0 3
0
3
iamsplunker
Hello Splunk Community I'm working on a SPL to give _time difference of list of eventTypes as per the algorithm. Curr...
by iamsplunker Communicator in Splunk Search 08-24-2021
0 4
0
4
andreaswpv
Hi need to calculate the average based on a condition. testing=true vs testing=false  (lets say field A)field B has t...
by andreaswpv Explorer in Splunk Search 08-24-2021
0 2
0
2
Karthikeyan
Hello Experts,Requirement is to show the no. of jobs started, completed in last 4 hours.I have injested job log files...
by Karthikeyan Engager in Splunk Search 08-24-2021
0 5
0
5
Karthikeyan
Hi Experts,I have a a job log file, that gets ingested to Splunk with naming convention "trace_08_19_2021_06_36_03_**...
by Karthikeyan Engager in Splunk Search 08-24-2021
0 5
0
5
middlemiddle
I'm using the following to eval current_day:| inputlookup Files_And_Thresholds| eval current_day=lower(strftime(relat...
by middlemiddle Explorer in Splunk Search 08-24-2021
0 4
0
4
joe06031990
Hi,I have the bellow search:I am trying to use acceleration reporting however because the event stats I can't, I have...
by joe06031990 Communicator in Splunk Search 08-24-2021
0 0
0
0
PickleRick
Hello.I have a set of hosts which send some stats. In my case these are rsyslog impstats statistics but it can be any...
by SplunkTrust SplunkTrust in Splunk Search 08-24-2021
0 0
0
0
sam1010
This is the table. How can I group together similar names into one entry and the count is added for both of them. For...
by sam1010 Explorer in Splunk Search 08-24-2021
0 3
0
3
MayankChandra
Need help : I have a splunk query where i want to evaluate today (day of week) using now() and then use it to compare...
by MayankChandra Engager in Splunk Search 08-24-2021
0 7
0
7
question_queen
I am looking for a splunk query which can calculate each sourcetype ingesting data in splunk. you can take below samp...
by question_queen New Member in Splunk Search 08-23-2021
0 3
0
3
Shan
As i mentioned below prod column has multiple values and i want to split it based on \n next line command and get the...
by Shan Builder in Splunk Search 08-23-2021
0 6
0
6
torowa
Hi Splunkers.We are having an issue whereby a TAXII feed has stopped being incorporated into the Enterprise Security ...
by torowa Path Finder in Splunk Search 08-23-2021
1 0
1
0
morgantay96
Hi All,Have a search that is not returning what I would like. Need to unest some JSON but having issues.Here is an ex...
by morgantay96 Path Finder in Splunk Search 08-23-2021
0 1
0
1
SkuLLo99
HiI'm trying to find user that login on Non-working hour between 4pm-4am by looking at eventcode=4624.I need to exclu...
by SkuLLo99 Loves-to-Learn in Splunk Search 08-23-2021
0 5
0
5
Cyber_Nerd3
Hey Everyone!I'm in need of some help, advice, Ouija board (lol)...whatever can do the trick. I am wanting to know if...
by Cyber_Nerd3 Engager in Splunk Search 08-23-2021
0 7
0
7
HenrikN
I have logs like of this form:[2021-08-19T13:59:05.607] [INFO] collect - [4a2b9170-0130-11ec-95b3-17c017e0ec5d] {"uid...
by HenrikN Engager in Splunk Search 08-23-2021
0 2
0
2
shrinivaskittur
Hi,I need help in searching field value from the first search to another search with deferent sourcetype and combine ...
by shrinivaskittur Explorer in Splunk Search 08-23-2021
0 4
0
4
Cyber_Nerd3
Hello,I am attempting to combine 2 reports (1 is a normal stats search return and the other is a pie chart using the ...
by Cyber_Nerd3 Engager in Splunk Search 08-23-2021
0 0
0
0
gunnist
Hi,In my query:index="my_local" | sort -DateI get a list of items, and if I look at one item (and lick "show as raw t...
by gunnist Explorer in Splunk Search 08-23-2021
0 3
0
3
SplunkDash
Hello, I have some issues to create PROPS Conf file for following sample data events. It's a text file with header in...
by SplunkDash Motivator in Splunk Search 08-23-2021
0 0
0
0
kuriakose
Hi, I am attempting to create a search for a password spraying attempt. I need the IP address and Hostname made with ...
by kuriakose Explorer in Splunk Search 08-23-2021
0 3
0
3
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors