Splunk Search

Splunk Search
Community Activity
nikoloz04
I have O365 logs in Splunk. I want to find all shared files/folders plus display sensitivity labels of these files. A...
by nikoloz04 New Member in Splunk Search 05-07-2021
0 0
0
0
bcouavoux
Hello !My data is in this form  :_time (dd/mm/yyyy), NbRisk, SubProject, GlobalProject02/05/2021, 10 ,  SubProject1, ...
by bcouavoux Explorer in Splunk Search 05-07-2021
0 4
0
4
antonio147
Hi all,I performed an initial search, to this I added a second search, with the map command, where based on the value...
by antonio147 Communicator in Splunk Search 05-07-2021
0 3
0
3
wiar
I have a search result where each 3  follwing lines are a block I want to join to one row like:fld1 fld2 fld3 fld4A  ...
by wiar Explorer in Splunk Search 05-07-2021
0 4
0
4
Am
Hello,Two months ago we had the trial for the Enterprise version but now we are using the free version. Since the fre...
by Am Explorer in Splunk Search 05-07-2021
0 9
0
9
lancair
Desired Outcome : I am trying to create a simple timechart  to show a count of ports and the relative time line on th...
by lancair Observer in Splunk Search 05-07-2021
0 3
0
3
splunkkid
Hello,I'm struggling with the way to make efficient alerts trigger with SPL. I made splunk dashboard to visualize our...
by splunkkid Path Finder in Splunk Search 05-07-2021
0 0
0
0
renuka
<search id="base_query_filter"><query>      Index=a,sourcetype=x,eval y=A+B</query></search><search id="base_query"><...
by renuka Path Finder in Splunk Search 05-06-2021
0 2
0
2
splunkcol
I have 2 servers that receive the logs through Syslog and through a universal forwarder I forward them to 2 indexers....
by splunkcol Builder in Splunk Search 05-06-2021
0 1
0
1
cyp112
Hello,I am trying to use a subsearch on another search but not sure how to format it properlySubsearch:eventtype=pan ...
by cyp112 Engager in Splunk Search 05-06-2021
0 2
0
2
cclva
I have a dashboard which provides a handful of filter criteria, for example, `fieldA=A` and `fieldB=B`.One such crite...
by cclva Explorer in Splunk Search 05-06-2021
0 1
0
1
mdeterville
Hello SMEs:I need some assistance extracting everything between the 1st and 2nd semi-colon ; (FROM THE RIGHT)  from a...
by mdeterville Path Finder in Splunk Search 05-06-2021
0 4
0
4
Alfred
I want to extract from the Message field in the Windows Event Log just the first few words until the period - example...
by Alfred Explorer in Splunk Search 05-06-2021
0 5
0
5
billycn20
i have a working query which is monitoring the success rate based off a value called app_id. i want to extend the cur...
by billycn20 Explorer in Splunk Search 05-06-2021
0 4
0
4
billycn20
I am trying to measure our success rate on our platform. there are two individual events which we care to see in orde...
by billycn20 Explorer in Splunk Search 05-06-2021
0 6
0
6
ajtokar
I have a query where I can see in a snapshot current active users per VPN profile (group). Having a hard time being a...
by ajtokar Engager in Splunk Search 05-06-2021
0 2
0
2
3618475
I have this search that produces a table with has a column that lists the number of segments to a schedule. The table...
by 3618475 Engager in Splunk Search 05-06-2021
0 3
0
3
aikn061
Hi guys,I know this has been asked many times before but it just wont work for me hence the question.I have one index...
by aikn061 Explorer in Splunk Search 05-06-2021
0 7
0
7
wbolten
Hi,I successfully created an SPL that does what I need for a single host but I cannot get it to work for all hosts. T...
by wbolten Path Finder in Splunk Search 05-06-2021
0 3
0
3
new2splunk1
Hello members,I am new to Splunk and able to produce simple stats using STATS count by command but looking for direct...
by new2splunk1 Engager in Splunk Search 05-06-2021
0 2
0
2
aperezy17
I am new to SPLUNK learning with the Enterprise Edition. I created a new host with JSON source type. When I search so...
by aperezy17 New Member in Splunk Search 05-05-2021
0 0
0
0
husainpatanwala
Hi guys I have two statsindex |Exception| countindex |Error |countI want is something like this :index |Exception|Err...
by husainpatanwala Engager in Splunk Search 05-05-2021
0 3
0
3
roopeshetty
Hi Guys, We can see there are 6 hosts which are sending bulk events (logs) to splunk. But we don’t know who is using ...
by roopeshetty Path Finder in Splunk Search 05-05-2021
0 2
0
2
bitbucket
Hello -My data looks like (also attached as PNG for better readability):2021-04-28 - 22:01:14.728 - INFO : Action com...
by bitbucket Engager in Splunk Search 05-05-2021
0 4
0
4
cclva
I have a generic search that I am using to display data for a handful of applications, which look something like this...
by cclva Explorer in Splunk Search 05-05-2021
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...