Splunk Search

Splunk Search
Community Activity
krusty
Hi there, we have an issue with hostname extraction from syslog events. Normaly the extraction works fine, but for ...
by krusty Contributor in Splunk Search 07-17-2021
0 7
0
7
splunkerer
Hi Folks,I am trying to enrich my search with subsearch in the same time bucket/bin. The search can be found below.De...
by splunkerer Path Finder in Splunk Search 07-17-2021
0 1
0
1
Lukas85
Hi AllI'm new on splunk and have following problem.We need data from a table depending on the value of a variable. Fo...
by Lukas85 New Member in Splunk Search 07-17-2021
0 1
0
1
jsturgeon
Hello, I am looking to clean up the result data from a Splunk query.How do I remove all the text prior to the user na...
by jsturgeon New Member in Splunk Search 07-16-2021
0 1
0
1
revanthammineni
Hello Splunkers.I'm working on some of the usecases on ES and one of the request that I've got from my upper manageme...
by revanthammineni Path Finder in Splunk Search 07-16-2021
0 2
0
2
shashi584
We have 3 different (Active,Closed,Resolved) records for same Incident and we need to retrieve only Active incident r...
by shashi584 Explorer in Splunk Search 07-16-2021
0 6
0
6
splunkcol
 I have 3 different indexes and they asked me to search by document number.The structure of the logs is different inc...
by splunkcol Builder in Splunk Search 07-16-2021
0 2
0
2
joshiro
Hi, i need help with some datamodel acceleration issues in CIM.The problem is that i accelerated a datamodel with 1y ...
by joshiro Communicator in Splunk Search 07-16-2021
0 3
0
3
radalliance
Hey all, I'm trying to separate out the IP address (Source Network Address:) from the Windows event Message field. I'...
by radalliance Engager in Splunk Search 07-16-2021
0 3
0
3
bhavika100
Our event log has request and response. Request and response body can either be a json object or json array. I need t...
by bhavika100 Explorer in Splunk Search 07-16-2021
0 5
0
5
mdzmuran
Hi Splunk Community.I have an alert, which runs a query regularly, for example hourly 24*7*365. If the alert is trigg...
by mdzmuran Observer in Splunk Search 07-16-2021
0 3
0
3
kronite13
I need to do an analysis on API calls using logs, like avg, min, max, percentile99, percentil95, percentile99 respons...
by kronite13 Explorer in Splunk Search 07-16-2021
1 6
1
6
JChris_
I have an index where one of the relevant fields is a domain. This index is used in a search in a dashboard, where I ...
by JChris_ Path Finder in Splunk Search 07-16-2021
0 5
0
5
bosseres
Hello, communityWhat's skipped search? Do I understand correctly that it's a search which finished with error?How can...
by bosseres Contributor in Splunk Search 07-16-2021
0 2
0
2
joe06031990
Hello,I am trying to get the Perc99 and Perc95 from the total transaction in IIS which the bellow search: source="C:\...
by joe06031990 Communicator in Splunk Search 07-15-2021
0 3
0
3
joe06031990
Good morning,I am looking on generating a search to find the 1% slowest requests from IIS logs however I am not sure ...
by joe06031990 Communicator in Splunk Search 07-15-2021
0 0
0
0
dipocket_org
Every time I search, I get errors:Could not load lookup=LOOKUP-cisco_asa_change_analysisCould not load lookup=LOOKUP-...
by dipocket_org Engager in Splunk Search 07-15-2021
0 2
0
2
indeed_2000
HiHere is my log, what is the rex for extract "0000A0@#0000" and "mymodulename" 2021-07-14 23:59:05,185 INFO [APP] Us...
by indeed_2000 Motivator in Splunk Search 07-15-2021
0 8
0
8
benton
If I run this search I generate two numeric fields, one called number the other called decimal  | makeresults 1 | eva...
by benton Path Finder in Splunk Search 07-15-2021
0 7
0
7
indeed_2000
Hihere is my log:2020-01-19 13:20:15,093 INFO ABC.InEE-Product-00000 [MyProcessor] Detail Packet: M[000] T[111] P[0A0...
by indeed_2000 Motivator in Splunk Search 07-15-2021
0 2
0
2
SplunkDash
Hello,Please let me know how I would write Props Configuration file for this csv file. Segment of sample data for thi...
by SplunkDash Motivator in Splunk Search 07-15-2021
0 5
0
5
msyparker
Hello!I  have a search with timechart that I need to filter time AFTER the timechart based on the current time. I've ...
by msyparker Explorer in Splunk Search 07-15-2021
0 2
0
2
SamHTexas
How do I search for a complete list of all the Apps on my Deployment server ? If possible Excluding the Built In apps...
by SamHTexas Builder in Splunk Search 07-15-2021
0 1
0
1
mybestfriendbob
I have a user that is asking me to look at the file hashes of every file that some into splunk across today and yeste...
by mybestfriendbob Explorer in Splunk Search 07-15-2021
0 2
0
2
henricook
I've got a JSON event that I like to tabulate by using `index=myindex | table *`When I do this though it includes som...
by henricook New Member in Splunk Search 07-15-2021
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors