Splunk Search

Splunk Search
Community Activity
avi7326
Can anyone help me to provide the URL to download or steps of how to use Splunk AI. 
by avi7326 Path Finder in Splunk Search 10-07-2024
0 3
0
3
darkins
My query returns these events, i need to compute the total time A was in this state and total time B was in this stat...
by darkins Engager in Splunk Search 10-07-2024
0 4
0
4
sdkp03
I have a splunk query which generates output in csv/table format. I wanted to convert this to a json format before wr...
by sdkp03 Communicator in Splunk Search 10-07-2024
0 7
0
7
msarkaus
Hello, I'm attempting to display a group of logs by the tranId. We log multiple user actions under a single tranId.  ...
by msarkaus Path Finder in Splunk Search 10-07-2024
0 2
0
2
Real_captain
Hi Team Can you please let me know how can i use the below Field extraction formula directly using the rex command ? ...
by Real_captain Path Finder in Splunk Search 10-07-2024
0 7
0
7
emmanuelkatto23
Hi everyone,My name is Emmanuel Katto. I’m currently working on a project where I need to analyze large datasets in S...
by emmanuelkatto23 New Member in Splunk Search 10-07-2024
0 3
0
3
SarSec
Greetings ,Does anyone know if it's possible to create a script that writes splunk search quey based on the alerts re...
by SarSec New Member in Splunk Search 10-06-2024
0 2
0
2
Mallik657
I have a Sample Data like below. Now i need to display single value count of Completed and Pending in 2 different sin...
by Mallik657 Explorer in Splunk Search 10-05-2024
0 10
0
10
Hemant_h
"c7n:MatchedFilters": [ "tag:ApplicationFailoverGroup", "tag:AppTier", "tag:Attributes", "tag:DBNodes", "tag:rk_aws_n...
by Hemant_h Engager in Splunk Search 10-05-2024
0 8
0
8
hthwal
How do I generate reports and run stats on key=value from just message field . Ignoring rest of the fields. {"cluster...
by hthwal Explorer in Splunk Search 10-05-2024
0 11
0
11
whitecat001
User receiving duplicated field names in splunk result for example when i run a search i get an output for the       ...
by whitecat001 Explorer in Splunk Search 10-05-2024
0 3
0
3
807mohd
Hello,I'm trying to achieve a result set which can be used in an alert later on.Basically when search is executed, it...
by 807mohd Explorer in Splunk Search 10-04-2024
0 4
0
4
corecost
I am trying to track a set of service desk ticket status across time.  The data input is a series of ticket updates t...
by corecost Explorer in Splunk Search 10-04-2024
0 3
0
3
Richy_s
I'm comparing two indexes, A and B, using the hostname as the common field. My current search successfully identifies...
by Richy_s Path Finder in Splunk Search 10-04-2024
0 11
0
11
DATT
I have a lookup table that we update on daily basis with two fields that are relevant here, NAME and ID. NAMEIDToront...
by DATT Path Finder in Splunk Search 10-04-2024
0 6
0
6
sverdhan
 i have a query that will calculate the volume of data ingested in a sourcetype--   index=federated:infosec_apg_share...
by sverdhan Loves-to-Learn Lots in Splunk Search 10-04-2024
0 2
0
2
nawneel
I have a large data set in my KV Store collections. These fields also contains time specific fields. I would like to ...
by nawneel Communicator in Splunk Search 10-04-2024
1 7
1
7
Rajaion
Hello community,I need to set up a dashboard that tracks the status of an alert from Splunk OnCall. An alert can have...
by Rajaion Path Finder in Splunk Search 10-04-2024
0 4
0
4
Steave4app
Hi Guys, How to find SQL Injection activity or OWASP attacks through the Splunk
by Steave4app New Member in Splunk Search 10-04-2024
0 4
0
4
otto1
Hello Splunkers, I started to use splunk uni forwarder in my job and I am kinda new to systems.My dashboard working g...
by otto1 Observer in Splunk Search 10-03-2024
0 1
0
1
jwhughes58
This is the search with some anonymization. index=index_1 sourcetype=sourcetype_1 field_1 IN ( [ search index=in...
by jwhughes58 Contributor in Splunk Search 10-03-2024
0 6
0
6
LearningGuy
How do I dedup or filter out data with condition?For example:Below I want to filter out row that contains name="name0...
by LearningGuy Motivator in Splunk Search 10-03-2024
0 11
0
11
anayi
I'm trying to create an alert. The alert's query ends with " | stats values(*) as * by actor.displayName | stats coun...
by anayi Observer in Splunk Search 10-03-2024
0 2
0
2
JandrevdM
Good day,I have done a join on two indexes before to add more information to one event. example get department for a ...
by JandrevdM Path Finder in Splunk Search 10-03-2024
0 1
0
1
JandrevdM
Good day,I am trying to find the latest event for my virtual machines to determine if they are still active or decomm...
by JandrevdM Path Finder in Splunk Search 10-03-2024
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...