Splunk Search

Splunk Search
Community Activity
dmbr
Hi Splunkheads, Need some advice here. I have built a simple lookup table and simple search for known bad ip addresse...
by dmbr Explorer in Splunk Search 05-20-2021
0 1
0
1
shreyasathavale
I have admin user and power user (role=power), when i search a particular index (iis_web) it does not return the out...
by shreyasathavale Communicator in Splunk Search 05-20-2021
0 3
0
3
user93
Hi,So I have a goal to count user visits, but the log polls too frequently, so we are going to define a visit by one ...
by user93 Communicator in Splunk Search 05-20-2021
0 3
0
3
kbohlken
I want to add more columns that will show the sessions.  Such as sudo su ssh etc.  Currently I have this:index="name ...
by kbohlken Observer in Splunk Search 05-20-2021
0 1
0
1
johefu
Hello all,Running the following search (direct count) at different times of the day for the same time period I receiv...
by johefu Loves-to-Learn in Splunk Search 05-20-2021
0 2
0
2
Logan20
Hello!!I have a field value that looks like:abcd124567-1609173498I only want to remove abcd-1609173498 and have the 1...
by Logan20 New Member in Splunk Search 05-20-2021
0 1
0
1
splunkerer
I have a data set as seen below.exec                   arguments/bin/shsh-cuname -p ** /dev/null/sbin/ldconfig/bin/sh...
by splunkerer Path Finder in Splunk Search 05-20-2021
0 4
0
4
RonD
I am creating a search that detects compliance received from palo alto signatureswe are receving 4 sets of dates:app-...
by RonD Explorer in Splunk Search 05-20-2021
0 2
0
2
Godspeed_74
I am trying to fill the null values and using a datamodel. I want to use tstats and fill null values will "Null" usin...
by Godspeed_74 Loves-to-Learn Lots in Splunk Search 05-20-2021
0 6
0
6
szukacz
Hi team,I'm trying to build a search which will search for the alerts which have been triggered for a hosts during sp...
by szukacz Engager in Splunk Search 05-20-2021
0 3
0
3
Sangu
HiI need to extract hostname or IP address from raw log. My log looks like below:somerandometest  host: abc@email.com...
by Sangu Explorer in Splunk Search 05-20-2021
0 2
0
2
jugarugabi
Hi, I have a csv file that is updated by a script once a minute. The output is similar to: time,queuename,vpn,last-me...
by jugarugabi Path Finder in Splunk Search 05-20-2021
0 4
0
4
srinivasgowda
Hello team, I am trying to ignore the value "Total" if its concurrent Os_type matches "Linux" Below is what I tried.|...
by srinivasgowda Explorer in Splunk Search 05-20-2021
0 3
0
3
stephenreece78
hi all, newbee question here but i can't seem to find an answer. I am trying to create a timechart table grouped tabl...
by stephenreece78 Engager in Splunk Search 05-20-2021
0 2
0
2
timrich66
I've been searching and trying options for a couple of days now with this search and cannot find a solution.I am usin...
by timrich66 Communicator in Splunk Search 05-20-2021
0 10
0
10
yuanliu
I have an attribute that is determined by two inputs, one with many possible values, the other few.  I can enlist the...
by SplunkTrust SplunkTrust in Splunk Search 05-19-2021
1 4
1
4
teewenjie22
How to convert below _time    Server      col1     col2       col38am       SerA          1           2             3...
by teewenjie22 Engager in Splunk Search 05-19-2021
0 1
0
1
payton_tayvion
I'm currently trying to create a search that look for employees hired within the last 3 months, but I keep getting al...
by payton_tayvion Path Finder in Splunk Search 05-19-2021
0 1
0
1
malanirishi
Problem: I want to ignore all results from search that have message: <4 digits> in them. For example: { timestamp: 20...
by malanirishi New Member in Splunk Search 05-19-2021
0 1
0
1
chirsf
I'm looking for a way to numerically sort a multivalue field without expanding the field, sorting and then recombinin...
by chirsf Explorer in Splunk Search 05-19-2021
1 3
1
3
mkroczak
Hi there,I'm just a basic user of Splunk in my company and I have 0 experience with programming or SQL please don't g...
by mkroczak Loves-to-Learn in Splunk Search 05-19-2021
0 1
0
1
thaghost99
i would need help splitting this output into its own line.if we can even remove the quotes, comma, curly brackets and...
by thaghost99 Path Finder in Splunk Search 05-19-2021
0 4
0
4
MrPink99
Hi,New to splunk first time lister. Hoping for some help.I am trying to extract nested JSON data from a Widows Event ...
by MrPink99 New Member in Splunk Search 05-19-2021
0 0
0
0
jheiselman
I'm sure this has been asked before, but nothing I'm coming up with for searches against this forum have proved usefu...
by jheiselman Explorer in Splunk Search 05-19-2021
0 3
0
3
chirsf
I have an odd situation with a macro starting with an inputlookup like this: inputlookup ADcomputerslist ```logic tim...
by chirsf Explorer in Splunk Search 05-19-2021
0 3
0
3
Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...