Splunk Search

Splunk Search
Community Activity
ndd
I have a non numerical field (text), and I want to create an enum field. Meaning that I will have a new field with nu...
by ndd Engager in Splunk Search 08-01-2021
0 5
0
5
jt1234567
Hi, so I am trying to record the Earliest connection for IP addresses and the Latest connection for IP addresses howe...
by jt1234567 Loves-to-Learn in Splunk Search 07-31-2021
0 1
0
1
md
Hello all,I'm trying to create an alert for Successful Brute Force Attempts using the Authentication Data Model. Curr...
by md Explorer in Splunk Search 07-31-2021
0 0
0
0
sushil_sh
Hi, We are looking to join two different soucretype which is given below1- first source type for  abc(In this soucety...
by sushil_sh Engager in Splunk Search 07-31-2021
0 2
0
2
dpwtheitguy
All, Just upgraded to 8.2.1 last night and noticed something today with stats. # This search returns 160k+ eventsinde...
by dpwtheitguy Loves-to-Learn Lots in Splunk Search 07-30-2021
0 1
0
1
gvmorley
Hi, I wanted to see if anyone else had come across some strange behaviour when using the (?J) mode modifier in the '...
by gvmorley Contributor in Splunk Search 07-30-2021
6 7
6
7
timrich66
Hi,I need to track the number of times and duration where the CPU used percent is above a threshold number.The search...
by timrich66 Communicator in Splunk Search 07-30-2021
0 0
0
0
longmen
Hi Splunk Experts, I wonder if you could help me putting the below logic in to a search query?Here the link reference...
by longmen Path Finder in Splunk Search 07-30-2021
0 21
0
21
mvishal
Hi All..Is there a way to keep the in chart zoom & pan option button to keep visible even on zero zoom selection
by mvishal Explorer in Splunk Search 07-30-2021
0 0
0
0
flukey
Hi Splunker I'm quite new to splunk. Can you please help me out on this search?I have a table of antivirus database v...
by flukey Engager in Splunk Search 07-30-2021
0 2
0
2
spicy
I am extracting a list of free text string in the _ raw and creating a new field.The list of terms comes from user in...
by spicy Path Finder in Splunk Search 07-29-2021
0 4
0
4
ss394546910
Hi everyone, I got lots of the blow _row after the search:........2002-02-22 17:32:15.592 somedatainformation ==> ASH...
by ss394546910 Engager in Splunk Search 07-29-2021
0 1
0
1
sathishraja92
First attempt creates the splunk SID, but fails on the successive attempts to create search id. Same issue occurs whi...
by sathishraja92 Explorer in Splunk Search 07-29-2021
2 1
2
1
michaelsplunk1
Hello!Sample data:VehicleHour of Daycountdelta(count)car1115--car1120-5car11333car21196car2125-4car31150car31250car31...
by michaelsplunk1 Path Finder in Splunk Search 07-29-2021
0 1
0
1
hoko_joni
In new search window (image attach) There are to column "Time" "Event" How can I automatically(not write each time in...
by hoko_joni New Member in Splunk Search 07-29-2021
0 1
0
1
anooshac
Hi all,I have a multiple json files. The format is like as below.{<!-- -->"ID": "123","TIME": "Jul 11, 2021, 08:55:54 AM","ST...
by anooshac Communicator in Splunk Search 07-29-2021
0 4
0
4
jaysonpryde
Hi,As mentioned in the subject, I wanted to perform a simple subtraction operation on individual values/elements with...
by jaysonpryde Path Finder in Splunk Search 07-28-2021
0 2
0
2
SS1
Hi,I have below output with my search, base search| stats count by User, actionUseractioncountAlexinstall3Alexuninsta...
by SS1 Path Finder in Splunk Search 07-28-2021
0 1
0
1
stauff
Hello All.I am trying to use a lookup to perform a tstats search against a data model, where I want multiple search t...
by stauff Explorer in Splunk Search 07-28-2021
0 2
0
2
Stefanie
I have a scripted input created to monitor certificate expiration.An example event:Tue Jul 27 12:07:55 CDT 2021,/opt/...
by Stefanie Builder in Splunk Search 07-28-2021
0 3
0
3
kooojo
I have an query thatindex &#61;"main" |stats count by Text |sort -count | table count Textresults:countText10dog fish20  ...
by kooojo Engager in Splunk Search 07-28-2021
0 3
0
3
kooojo
I have an query thatindex &#61;"main" |stats count by Text |sort -count | table count Textresults:countText10b'dog fish20...
by kooojo Engager in Splunk Search 07-28-2021
0 1
0
1
sandeepparcha44
HiI am trying to search two strings in message like "Stopped successfully" and "connected" from 6 host names.Please h...
by sandeepparcha44 Explorer in Splunk Search 07-28-2021
0 9
0
9
moonie
Hello,I have a search where I need to combine two inputlookups to find incommon values in a field they both have. The...
by moonie Explorer in Splunk Search 07-28-2021
0 4
0
4
kevin94120
HelloI have a auditd search like type&#61;EXECVE msg&#61;audit(16): a0&#61;"sendmail" a1&#61;"-t"I would like one field with any fiel...
by kevin94120 Explorer in Splunk Search 07-28-2021
0 11
0
11
Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...