Splunk Search

Splunk Search
Community Activity
SplunkDash
Hello, I have some issues to create PROPS Conf file for following sample data events. It's a text file with header in...
by SplunkDash Motivator in Splunk Search 08-23-2021
0 0
0
0
kuriakose
Hi, I am attempting to create a search for a password spraying attempt. I need the IP address and Hostname made with ...
by kuriakose Explorer in Splunk Search 08-23-2021
0 3
0
3
rjoller
HelloIn my base search I'm looking for stores with the minimum count of 1 for 4 differend kind of errors. I count the...
by rjoller Explorer in Splunk Search 08-23-2021
0 4
0
4
shazbot79
Hi, I have the following SPL as a dashboard panel which shows realtime searches. This is so I can contact the owners ...
by shazbot79 Path Finder in Splunk Search 08-23-2021
0 5
0
5
leecholim
Hi all,my data as below:11111_aaaa/ppppaaaa1110_bb/kjmI want to remove anything after /, like this11111_aaaa1110_bb T...
by leecholim Engager in Splunk Search 08-23-2021
0 7
0
7
Tim00
Hi all,have been using the splunklib package in Python to connect to the Splunk API for some time now, and it works f...
by Tim00 Explorer in Splunk Search 08-23-2021
0 2
0
2
pm771
Hello,I noticed that ... WHERE somefield = string1 OR string2works the same way as ... WHERE somefield = string1 OR s...
by pm771 Communicator in Splunk Search 08-23-2021
0 4
0
4
rj
how to get this two stats result in one query(earliest=-24h@h index="s_data_sum" (type="c" OR type="s") (sourcetype="...
by rj Loves-to-Learn Lots in Splunk Search 08-23-2021
0 5
0
5
mhuntington
I hate to say it, but I am a Splunk-newb. I plan on taking a Splunk course, but for now, I am just trying to get my f...
by mhuntington Explorer in Splunk Search 08-22-2021
2 8
2
8
cquinney
Greetings Splunkers,I've been banging my head against the keyboard to try and resolve this comparison issue, I know t...
by cquinney Communicator in Splunk Search 08-22-2021
0 7
0
7
sx
Hi, I am trying to compare the between two events (json format), say, I can pipe with "head 2" to output only two eve...
by sx Engager in Splunk Search 08-22-2021
0 4
0
4
SplunkDash
Hello,I was using Transform type Field Extraction, I have an issue to select my Delimiter and facing some errors (not...
by SplunkDash Motivator in Splunk Search 08-22-2021
0 8
0
8
shakSplunk
Hi all,I am looking to check if there has been a event within the last 3 hrs for three different categories. If an ev...
by shakSplunk Path Finder in Splunk Search 08-22-2021
0 3
0
3
kartm2020
Hi All, Hope you guys are doing fine.I do have few doubts with relates to field comparison. Please find the below sam...
by kartm2020 Communicator in Splunk Search 08-22-2021
0 6
0
6
jokovitch
I have a data in Splunk likeindex="main"FnameCountryfname1USAfname1USAfname3USA I want to add and change some datawhe...
by jokovitch Explorer in Splunk Search 08-22-2021
0 6
0
6
moinyuso96
Currently my Splunk Search is shown as below:SerialDescriptionDateTimeStartTimeEndTimeMY111Registration2021-05-01 00:...
by moinyuso96 Path Finder in Splunk Search 08-22-2021
0 1
0
1
keesling
When editing searches in ITSI, control-e expands macros and control-z undoes the last change.  I know this only by be...
by keesling Engager in Splunk Search 08-21-2021
0 0
0
0
RYEAMAN
0
1
SplunkDash
Hello,Please let me know how I would break the events, write TIME_PREFIX and TIME_FORMAT for my PROPS Conf.  file  fo...
by SplunkDash Motivator in Splunk Search 08-20-2021
0 11
0
11
cyberdiver
My goal is to calculate a score of confidence based on how anomalous the amount of failed logins is compared to activ...
by cyberdiver Explorer in Splunk Search 08-20-2021
0 0
0
0
raysonjoberts
I have a csv file that that I am using for a lookup which has multiple values in a particular field. I am trying to d...
by raysonjoberts Path Finder in Splunk Search 08-20-2021
0 4
0
4
EberlinM
How can I split a field, into many other fields, but without using a delimiter, and using the position range instead?...
by EberlinM Engager in Splunk Search 08-20-2021
0 2
0
2
miyuog13
I want to get a predicted value from the data statistics.Is it possible to output the predicted value for each patter...
by miyuog13 Engager in Splunk Search 08-20-2021
0 1
0
1
Splunkin
Hi Splunkers,I have query where i want to filter out all the legitimate process by path process which ive identify th...
by Splunkin Explorer in Splunk Search 08-20-2021
0 1
0
1
Karthikeyan
Hi Experts,I have a requirement to in which a table is ingested to Splunk. And the table has a field named Time showi...
by Karthikeyan Engager in Splunk Search 08-20-2021
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...