Splunk Search

Splunk Search
Community Activity
ebarnhill
I am looking to create a confusion matrix out of a tabled query of the form[query] | table unchanged true predWhere, ...
by ebarnhill Engager in Splunk Search 06-07-2021
0 1
0
1
guido93
From a search I composed a table, let's call it T1, formed by two columns table name, sourcetypeNow I need to create ...
by guido93 New Member in Splunk Search 06-07-2021
0 3
0
3
thenormalone
I have a boolean field which I get from the search, now when I do a stats count by boolean_field, the pie chart will ...
by thenormalone Path Finder in Splunk Search 06-07-2021
0 3
0
3
newBie001
Hello All,Could you please suggest to me whether this option is good or is there any optimized search query? query --...
by newBie001 Loves-to-Learn in Splunk Search 06-07-2021
0 1
0
1
splunkerer
I am providing data from one input in the dashboard, and want to search provided input strings in different fields wh...
by splunkerer Path Finder in Splunk Search 06-07-2021
0 4
0
4
3amer92
Hello!So I'm new to Splunk, and I have a very long event but I'm only interested in the below two lines (there are a ...
by 3amer92 Explorer in Splunk Search 06-07-2021
0 0
0
0
Laxman24
Hi All,I need some help in searching,I have the following data : Field1Field22021-05-14X03:02:57YXa2021-05-13X05:12:1...
by Laxman24 Explorer in Splunk Search 06-07-2021
0 2
0
2
mani9059
Hi Team, I am trying to extract complete URL from the below splunk search i tried many ways can you please help me on...
by mani9059 Engager in Splunk Search 06-07-2021
0 3
0
3
mani9059
0
1
Splunk_Ryan
I would like to extract user name, source IP, source port and access protocol from the following 2 events from /var/l...
by Splunk_Ryan Explorer in Splunk Search 06-06-2021
0 6
0
6
tkdguq0110
How can I use abstract command?My query is| makeresults| eval test = " 123456789123456"| abstract maxlines=1 This que...
by tkdguq0110 Path Finder in Splunk Search 06-06-2021
0 0
0
0
ebs
This is my base search:| datamodel Test summariesonly=true search| search "TEST.date"=2021-05-23 | rename "TEST.date"...
by ebs Communicator in Splunk Search 06-06-2021
0 10
0
10
ebs
Hi,I want to create a search that is able to grab both the start and end times of a specific action, but to create th...
by ebs Communicator in Splunk Search 06-06-2021
0 1
0
1
new2splunk1
Hi Splunk experts, I'm generating stats from 3 indexes (System A, B, C) and the results look like this:Table 1:The to...
by new2splunk1 Engager in Splunk Search 06-05-2021
0 4
0
4
harry_123
Hello, I have alerts that look like belowMay 13 17:15:30 11.2.3.22 0000017768: NOXXXXXX10A: May 13 2021 17:15:30.467 ...
by harry_123 Loves-to-Learn Lots in Splunk Search 06-04-2021
0 13
0
13
vijaykuma
  index=_internal host="ip" source=*license_usage.log* type="Usage"     [| inputlookup all_cs_indexes.csv     | renam...
by vijaykuma New Member in Splunk Search 06-04-2021
0 1
0
1
splunkerer
Hello,I am creating a dashboard, no matter which input can be used, but need is to paste multiple input into dashboar...
by splunkerer Path Finder in Splunk Search 06-04-2021
0 6
0
6
shrogers
Can I please get some assistance on the below?I'm trying to add a filter TRAN_CLASS!=6 to the below query. When I add...
by shrogers Loves-to-Learn Everything in Splunk Search 06-04-2021
0 4
0
4
vijaykuma
We have requirement to Integrate Oracle Unified Directory(Authentication and OS logs) with splunk. Action points: Pre...
by vijaykuma New Member in Splunk Search 06-04-2021
0 0
0
0
ivana27
Hello Splunkers,please help.I have two types of search result and i want to make alert only when 1.) occured:1.) 2021...
by ivana27 Path Finder in Splunk Search 06-04-2021
0 1
0
1
renuka
Hello All"Good Day"index="aedc"| rex field=source "-_(?<source>\S+)"| rex "(?<ModuleID>MY\d+)"| rex "(?<Path>/F.\s\S+...
by renuka Path Finder in Splunk Search 06-04-2021
0 3
0
3
Atif
Hi,I'am sending some events each minute to Splunk : TIMEIDINOUT08:00A1008:00B00    08:01A2108:01B2208:01C40    08:02A...
by Atif Explorer in Splunk Search 06-04-2021
0 3
0
3
RmDok
`base search | stats values(zipcode), count(zipcode) as c by country | sort -c | head 10`which gives me most appeared...
by RmDok Loves-to-Learn Lots in Splunk Search 06-04-2021
0 3
0
3
a_n
Hello,I have a dashboard with Choropleth map presenting events from various countries (categorical Color mode).In the...
by a_n Path Finder in Splunk Search 06-04-2021
0 0
0
0
junier16
im looking for the field "is_prohibited=true". This is field is located in one of lookup table, event type, or tag. H...
by junier16 Explorer in Splunk Search 06-03-2021
0 1
0
1
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors