Splunk Search

Splunk Search
Community Activity
lslschr21
HiI wanted to write a search that show all hosts that sends new since 24hrs into Splunk. The problem now is that I wa...
by lslschr21 Loves-to-Learn Lots in Splunk Search 05-27-2021
0 0
0
0
moayadalghamdi
Hola Splunkers !! i want to search in two indexes with one common values in between, for exapmle: index=Exchange_serv...
by moayadalghamdi Path Finder in Splunk Search 05-27-2021
0 1
0
1
Daniel_Pham
I created a report for finding list intersection of two setA: inputlookup spam_ip (Indicator of compromise)B: index=m...
by Daniel_Pham Explorer in Splunk Search 05-27-2021
0 2
0
2
SG
Hi, I have a list of values as shown below SG_0-1622095994335.pngfrom the above picture data I wanted to pick the ave...
by SG Path Finder in Splunk Search 05-26-2021
0 2
0
2
ebs
Hi,Bit out of my depth here but I have done an eval so we divide the events in the index by the URLs and I have 4 cat...
by ebs Communicator in Splunk Search 05-26-2021
0 0
0
0
parkz
I have a field of titles that are filled with sentences about why a test was failed in a security audit, but they are...
by parkz Explorer in Splunk Search 05-26-2021
0 1
0
1
yuanliu
I've never used |regex, but use |where match() quite often.  Is the former just syntax sugar or is there any differen...
by SplunkTrust SplunkTrust in Splunk Search 05-26-2021
0 4
0
4
dkr3500
Hi,I know there are other ways to get this through the deployment server, but I'm trying to find a SPL to get results...
by dkr3500 Path Finder in Splunk Search 05-26-2021
0 1
0
1
Daniel_Pham
I'm new to Splunk And I'm trying to build summary index i have KVStore and indexA: inputlookup spam_ip (which is Indi...
by Daniel_Pham Explorer in Splunk Search 05-26-2021
0 7
0
7
bitofrumncoke
Strangest thing. I have some Infoblox logs coming in from a Syslog-NG server where we have a UF installed. UF is succ...
by bitofrumncoke New Member in Splunk Search 05-26-2021
0 2
0
2
nm8181
Hello,I am trying to extract the full line from the raw data log matching a pattern in the line.  Sample data:blah bl...
by nm8181 Engager in Splunk Search 05-26-2021
0 2
0
2
verifi81
Hi everyone. I'm trying to get this query going  with one search but I can't seem to do that. I can only get it to wo...
by verifi81 Path Finder in Splunk Search 05-26-2021
0 10
0
10
sbrewerton
HelloI have a query that examins events can outputs how many of each level of event there areindex=* eval level=lower...
by sbrewerton Engager in Splunk Search 05-26-2021
0 1
0
1
sangs8788
HiI have a query which results me data in the below format,Screenshot 2021-05-26 at 6.52.22 PM.pngI am trying to put ...
by sangs8788 Communicator in Splunk Search 05-26-2021
0 0
0
0
onur
Hi,In our organization, some teams would like to see the new index logs. To explain, they want to see who created a n...
by onur Explorer in Splunk Search 05-26-2021
0 1
0
1
auaave
Hi guys, I am making a dashboard with Error Duration per RobotId. Since the duration is in seconds, I rounded it to ...
by auaave Communicator in Splunk Search 05-26-2021
0 10
0
10
JiachengWei
Hi Guys, I'd like to calculate the time delta. Here is the sample:_time                                    _raw 2021-...
by JiachengWei Engager in Splunk Search 05-26-2021
0 5
0
5
Learner
Hi everyone, below is my sample query index=xyz source=ABC | stats count If I schedule this search then result have t...
by Learner Path Finder in Splunk Search 05-26-2021
0 1
0
1
Learner
Hi everyone,index=xyz source="something" |stats earliest(_time) as minTime latest(_time) as maxTime values(activityNa...
by Learner Path Finder in Splunk Search 05-26-2021
0 4
0
4
KongJian
Scenarioexample Index:Index=os, Ingesteddata _time, type, id08:00,A,108:10,A,208:11,A,308:12,A,408:13,A,509:00,B,109:...
by KongJian Engager in Splunk Search 05-26-2021
0 3
0
3
sashaank
So I am trying to run a splunk search using Splunk REST API which finds a list of triggered alerts.  | rest /services...
by sashaank Observer in Splunk Search 05-26-2021
0 0
0
0
syedabuthahir
How to change a span of 1 week time to start from Monday to friday usually span=1w it will show data from monday 00:0...
by syedabuthahir Explorer in Splunk Search 05-25-2021
0 4
0
4
klim
I am trying to set up a restricted search for a role so that they can only see data when a field1=customer01. The def...
by klim Path Finder in Splunk Search 05-25-2021
0 3
0
3
ebs
Hi.I've created the following macro: sessionCount(1)With this definition:datamodel Test summariesonly=true search | s...
by ebs Communicator in Splunk Search 05-25-2021
0 4
0
4
kedjjang
WARN DistributedPeer - Peer:https:/:8089 Unable to get server info from https://:8089/services/server/info due to: Co...
by kedjjang Path Finder in Splunk Search 05-25-2021
1 2
1
2
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors