Splunk Search

Splunk Search
Community Activity
Laxman24
Hi All,I need some help in searching,so I have 1 index but it has multiple sources,Index = Index1and within the index...
by Laxman24 Explorer in Splunk Search 06-09-2021
0 2
0
2
avikc100
 Am getting data in this format now.but i need to show only those row where sum of all column values are > 500am tryi...
by avikc100 Path Finder in Splunk Search 06-09-2021
0 3
0
3
sSiDs
Hi team!Couldn't find any info about it....but how make a proper search string to see what MAC address was on flappin...
by sSiDs New Member in Splunk Search 06-08-2021
0 1
0
1
Traer001
Hello,I have events like this:2021-06-07 17:53:01 UserId:123 Session complete2021-06-07 17:25:01 UserId:123 Start ses...
by Traer001 Path Finder in Splunk Search 06-08-2021
0 1
0
1
Traer001
Hello,I am trying to get an event inside of a transaction to use for duration calculation. My events currently look l...
by Traer001 Path Finder in Splunk Search 06-08-2021
0 1
0
1
Cristian
Hi,I created a custom StreamingCommand which makes REST API calls to get user details, based on a userid.If command i...
by Cristian Observer in Splunk Search 06-08-2021
0 0
0
0
Atif
Hi,I have some events like :---------------------------------TXID;RECEIVER;STATUSAA11;RCV00001;OKAA11;RCV00001;KOAA11...
by Atif Explorer in Splunk Search 06-08-2021
0 2
0
2
actionabledata
All, Hopefully a straightforward question.Is it possible to increase the following setting in a .../appname/local/lim...
by actionabledata Path Finder in Splunk Search 06-08-2021
0 1
0
1
Gene
Dear Splunkers, can you please help with the following problem:We use single instance and PaloAlto logs are sent thro...
by Gene Path Finder in Splunk Search 06-08-2021
0 3
0
3
vrmandadi
I am trying to  join two searches with a common fieldEvent1:Jun 7 14:55:37 v3**v sudo: pam_sss(sudo:auth): authentica...
by vrmandadi Builder in Splunk Search 06-08-2021
0 4
0
4
3DGjos
Hello, I have to parse this very custom LOG, and i'm having trouble figuring out how to do this: I have two differen...
by 3DGjos Communicator in Splunk Search 06-08-2021
0 10
0
10
Susha
Hi All,i have 221180 ips in csv(deattackerv1.csv)  with only one field "ip" .. where i want to check if we have any h...
by Susha Engager in Splunk Search 06-08-2021
0 7
0
7
AceOfSpades
I am currently working on a log and filtering data.Splunk has identified uri_query as a field.I have come across an e...
by AceOfSpades Engager in Splunk Search 06-08-2021
0 4
0
4
Rokas_Strazdas
Following is the data I have:Time (DD/MM/YYYY 00:00:00)Delay_class (String value, example "B. > 15 MIN" or "A. < 15MI...
by Rokas_Strazdas Engager in Splunk Search 06-08-2021
0 3
0
3
cave_splunker
I'm trying to create a dashboard that shows the count of new vulnerabilities between this month and last month, using...
by cave_splunker Explorer in Splunk Search 06-08-2021
1 8
1
8
dm1
I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in...
by dm1 Contributor in Splunk Search 06-07-2021
2 0
2
0
splunkkid
Hello,I have several different type of searches and made all of those as base search. And now I want to make input to...
by splunkkid Path Finder in Splunk Search 06-07-2021
0 6
0
6
logtastic
Hello,I am comparing a host.csv file with two columns "IP" and "DNS" I want to compare the IP column to my base searc...
by logtastic Explorer in Splunk Search 06-07-2021
0 1
0
1
mlevsh
Hi,We are using Splunk DB Connect on search heads to run "|dbxquery" command with SQL queries to Snowflake DB.Sometim...
by mlevsh Builder in Splunk Search 06-07-2021
0 1
0
1
ebarnhill
I am looking to create a confusion matrix out of a tabled query of the form[query] | table unchanged true predWhere, ...
by ebarnhill Engager in Splunk Search 06-07-2021
0 1
0
1
guido93
From a search I composed a table, let's call it T1, formed by two columns table name, sourcetypeNow I need to create ...
by guido93 New Member in Splunk Search 06-07-2021
0 3
0
3
thenormalone
I have a boolean field which I get from the search, now when I do a stats count by boolean_field, the pie chart will ...
by thenormalone Path Finder in Splunk Search 06-07-2021
0 3
0
3
newBie001
Hello All,Could you please suggest to me whether this option is good or is there any optimized search query? query --...
by newBie001 Loves-to-Learn in Splunk Search 06-07-2021
0 1
0
1
splunkerer
I am providing data from one input in the dashboard, and want to search provided input strings in different fields wh...
by splunkerer Path Finder in Splunk Search 06-07-2021
0 4
0
4
3amer92
Hello!So I'm new to Splunk, and I have a very long event but I'm only interested in the below two lines (there are a ...
by 3amer92 Explorer in Splunk Search 06-07-2021
0 0
0
0
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors