Splunk Search

Splunk Search
Community Activity
arkadyz1
Not sure that I've picked the correct location - moderators, please move.I found that I cannot normally run a search ...
by arkadyz1 Builder in Splunk Search 08-25-2021
0 3
0
3
dmbr
Here is a basic tstats search I use to check network traffic.  | tstats summariesonly=t fillnull_value="MISSING" coun...
by dmbr Explorer in Splunk Search 08-25-2021
0 3
0
3
nnonm111
I'm going to check the permission and rejection of the scan attack per hour.At this point, what I wrote...Which is ap...
by nnonm111 Path Finder in Splunk Search 08-25-2021
0 5
0
5
munisb
Hi, I have finally got my search to work that compares data between index and lookup (csv) file that contains assets ...
by munisb Explorer in Splunk Search 08-25-2021
0 1
0
1
Anesthetize
Hey Splunk gang, I have a dashboard that I am creating and it will ingest a file every 5 minutes.  I need to create a...
by Anesthetize Engager in Splunk Search 08-25-2021
0 1
0
1
PickleRick
I'm watching the Fundamentals 2 course (finally XD) and I've come across the search ending with something like: | sor...
by SplunkTrust SplunkTrust in Splunk Search 08-25-2021
0 3
0
3
493600
Hello, I have a simple dashboard that has 2 panels:1)Types of dashboards (single value component defining count of ea...
by 493600 Explorer in Splunk Search 08-25-2021
0 0
0
0
Sandeep_J
I want to try a search for "9.com"However the results return 89.com,five9.com,guru99.com How to execute this. Please ...
by Sandeep_J New Member in Splunk Search 08-25-2021
0 2
0
2
rahul_n
Hi.I have a Splunk dashboard, and there is a requirement to send the dashboard as a pdf report everyday. I can see th...
by rahul_n Explorer in Splunk Search 08-25-2021
0 5
0
5
harishalipaka
[Updated]HI All,@ITWhisperer Please help me on thisI have data like below - HostNameLastConnectedABC23/08/2021 10:04A...
by harishalipaka Motivator in Splunk Search 08-25-2021
0 12
0
12
Naren26
I am trying to find the occurrence whenever the state changes due to the error. Below are my sample events:2021/08/01...
by Naren26 Path Finder in Splunk Search 08-25-2021
0 3
0
3
arielamar123
Hi, I have 2 multivalue fields I want to make a simple line chart out of them. Each event looks like this x: [0.1,0.2...
by arielamar123 Loves-to-Learn in Splunk Search 08-25-2021
0 5
0
5
SplunkDash
Hello, I have some issues to create PROPS Conf file for following sample data events. It's a text file with header in...
by SplunkDash Motivator in Splunk Search 08-25-2021
0 6
0
6
syedtabs
Dear All,I am new to splunk, I want to extract data from one of the log file and like to create the dashboard visuali...
by syedtabs New Member in Splunk Search 08-25-2021
0 3
0
3
noott211
index="fw" app="ping"| bin _time span=10m| stats count by client_ip,dest_ip| stats list(dest_ip) AS dest_ip , list(co...
by noott211 Path Finder in Splunk Search 08-25-2021
0 1
0
1
shugup2923
I have time field which have values such as 9AM-10PM, 10:00AM-11:00PM, I want to change 9AM-10PM to 9:00AM-10:00 PM, ...
by shugup2923 Path Finder in Splunk Search 08-25-2021
0 3
0
3
splunky_monkey
I am trying to set up an alert in Splunk that will email a user whenever their Windows session is X days old. It woul...
by splunky_monkey Loves-to-Learn Lots in Splunk Search 08-25-2021
0 0
0
0
sam1010
 So I have added a table drilldown to this pie chart but I need the rows in table displayed according to the value I ...
by sam1010 Explorer in Splunk Search 08-25-2021
0 3
0
3
cheriemilk
Hi team,I have below data in splunk. And I want to get the time duration when below range.ACT start with "AUTOSAVEFOR...
by cheriemilk Path Finder in Splunk Search 08-24-2021
0 3
0
3
iamsplunker
Hello Splunk Community I'm working on a SPL to give _time difference of list of eventTypes as per the algorithm. Curr...
by iamsplunker Communicator in Splunk Search 08-24-2021
0 4
0
4
andreaswpv
Hi need to calculate the average based on a condition. testing=true vs testing=false  (lets say field A)field B has t...
by andreaswpv Explorer in Splunk Search 08-24-2021
0 2
0
2
Karthikeyan
Hello Experts,Requirement is to show the no. of jobs started, completed in last 4 hours.I have injested job log files...
by Karthikeyan Engager in Splunk Search 08-24-2021
0 5
0
5
Karthikeyan
Hi Experts,I have a a job log file, that gets ingested to Splunk with naming convention "trace_08_19_2021_06_36_03_**...
by Karthikeyan Engager in Splunk Search 08-24-2021
0 5
0
5
middlemiddle
I'm using the following to eval current_day:| inputlookup Files_And_Thresholds| eval current_day=lower(strftime(relat...
by middlemiddle Explorer in Splunk Search 08-24-2021
0 4
0
4
joe06031990
Hi,I have the bellow search:I am trying to use acceleration reporting however because the event stats I can't, I have...
by joe06031990 Communicator in Splunk Search 08-24-2021
0 0
0
0
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors