Splunk Search

Splunk Search
Community Activity
munisb
Hi,I am trying to figure this out - I have a data set that I need to compare the DNS values. The index data contains ...
by munisb Explorer in Splunk Search 08-17-2021
0 2
0
2
ervinsmith
Example: a series of events all have the same incident number (1170820) outlining the lifecycle of the ticket (from o...
by ervinsmith Explorer in Splunk Search 08-17-2021
0 3
0
3
shakSplunk
Hi all,I'm trying to convert the message body of my events into fields. The structure of the event message is in a co...
by shakSplunk Path Finder in Splunk Search 08-17-2021
1 1
1
1
MarieHe
Hello,I would like to enter the info from a lookup table into my dashboard search. lookup table name: FIP.csvcontent:...
by MarieHe New Member in Splunk Search 08-17-2021
0 3
0
3
Mahipal456
Hi All,I need to extract  the fields from the below xml data tried xpath and xmlkv but not working as expected.<item>...
by Mahipal456 Loves-to-Learn Lots in Splunk Search 08-17-2021
0 17
0
17
graziaedu
I have the follow queryindex=index |spath output=traceSteps path=traceSteps{}|table traceSteps|mvexpand traceSteps|re...
by graziaedu Explorer in Splunk Search 08-17-2021
0 2
0
2
toontech
How do I get a list of AD groups a specific user was removed from in the last week please. We had a Helpdesk person a...
by toontech New Member in Splunk Search 08-17-2021
0 3
0
3
xindeNokia
Search failed with error msg: Error in 'IndexScopedSearch': The search failed. More than 1000000 events found at tim...
by xindeNokia Path Finder in Splunk Search 08-17-2021
0 3
0
3
joe06031990
Hello,I have the bellow search:index=test sourcetype=Test|stats count by _time|eventstats perc99(count) as p99|eval P...
by joe06031990 Communicator in Splunk Search 08-17-2021
0 2
0
2
mayurr98
Hello, The question is pretty straightforward. I would like to alert if 3 failed logins followed by 1 successful logi...
by mayurr98 Super Champion in Splunk Search 08-17-2021
0 1
0
1
dm1
So I need to run search on a firewall index where I need to look for field values matching from two lookup files, one...
by dm1 Builder in Splunk Search 08-16-2021
0 5
0
5
szimmer661
I'd like to force consistency across all dashboard charts. For instance, in all charts, I'd like a certain server or...
by szimmer661 Explorer in Splunk Search 08-16-2021
1 5
1
5
shakSplunk
Hi all,I have a field that has a time value such as (_time field):2021-08-12 15:18:42However, when I got to use the r...
by shakSplunk Path Finder in Splunk Search 08-16-2021
0 4
0
4
iamsplunker
I've a query which has column like AccountNO eventType _time and differenceI'm trying to find the time difference of ...
by iamsplunker Communicator in Splunk Search 08-16-2021
0 0
0
0
edwinmae
We are using Splunk Enterprise, using SmartStore (S3).Example: Index A, with frozentimeperiodinsecs = 7776000 (~90 da...
by edwinmae Path Finder in Splunk Search 08-16-2021
0 4
0
4
SailorManDan
Hello, I am trying to only return the values of certain fields to be used in a subsearch. The problem I'm encounterin...
by SailorManDan Explorer in Splunk Search 08-16-2021
1 3
1
3
learningsplunk
Hello Splunk community,When trying to splice multiple events so that it can generate a specific output from a Splunk ...
by learningsplunk Path Finder in Splunk Search 08-16-2021
0 2
0
2
Nauman_Javaid
I have query something like this: index=sample source=test (earliest=-1d@d latest=@d) OR (earliest=-2d@d latest=-1d@d...
by Nauman_Javaid Loves-to-Learn in Splunk Search 08-16-2021
0 1
0
1
shanecifaldi
I need some help with an alert i have been stuck on. I have a DBCONNECT lookup that returns a value once a day. This ...
by shanecifaldi Loves-to-Learn Everything in Splunk Search 08-16-2021
0 0
0
0
shakSplunk
Hi all,I'm trying to dynamically add columns to two fixed columns based on the environment value selected. For instan...
by shakSplunk Path Finder in Splunk Search 08-16-2021
0 13
0
13
moonie
Hello, I'm working on a really complex search where I need to combine results from different lookup tables. One looku...
by moonie Explorer in Splunk Search 08-16-2021
0 3
0
3
analiaeg
Hello everyone. In my team we are investigating how to build a new application that does "Root Cause Analysis" (simi...
by analiaeg Explorer in Splunk Search 08-15-2021
0 5
0
5
SplunkDash
Hello,I wrote a PROPS Configuration file for following csv file but getting error message. Any help will be highly ap...
by SplunkDash Motivator in Splunk Search 08-15-2021
0 4
0
4
indeed_2000
HiI have compress file that contain several files. in source just show compress file. e.g compress files name is log....
by indeed_2000 Motivator in Splunk Search 08-15-2021
0 1
0
1
Shimon81
 I want to run a base query where some fields has a value which is present in inputlookup table For example,  I have ...
by Shimon81 Explorer in Splunk Search 08-15-2021
0 7
0
7
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors