Splunk Search

Splunk Search
Community Activity
abowesman
The following example | makeresults | eval FilePath="\\Temp.exe" | where match(FilePath, "(?i)\\Temp\.exe$") Creates ...
by abowesman Explorer in Splunk Search 05-10-2021
0 0
0
0
ershad_c
The date field sometimes has 2 spaces and sometimes 1 space, depending on whether the date is a single digit or doubl...
by ershad_c Engager in Splunk Search 05-10-2021
0 2
0
2
keshavgupta
SpoilerHow to split/extract substring before the first - from the right side of the field on splunk searchHow to spli...
by keshavgupta Engager in Splunk Search 05-10-2021
0 1
0
1
kirrusk
how to use horseshoe meter for below queryindex = *   | table podname cluster status | dedup podname cluster status |...
by kirrusk Communicator in Splunk Search 05-10-2021
0 1
0
1
yifatcy
Hi,I've been trying for hours and nothing works, so I figure you might help me out.I have the following very long que...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 2
0
2
Flobzh
Dear all,I'm trying to retrieve some log metadata and associate them to all my events.Exemple: When my application st...
by Flobzh Explorer in Splunk Search 05-10-2021
0 1
0
1
or1515
Hi,My query:index=ph_windows_sec sourcetype=XmlWinEventLog (EventCode=630 OR EventCode=4726 OR EventCode=624 OR Event...
by or1515 Loves-to-Learn Everything in Splunk Search 05-10-2021
0 2
0
2
yifatcy
Hi,Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each c...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 0
0
0
keyu921
Resolved
by keyu921 Explorer in Splunk Search 05-10-2021
0 1
0
1
junlozhang
I want to concatenate strings with special characters like "\t" and Unicode char "\u0006"I tried  | makeresults | ev...
by junlozhang Explorer in Splunk Search 05-09-2021
0 2
0
2
robayers
I have a field that consists of data separated from a json  data field using this search.index="test-99" sourcetype="...
by robayers Explorer in Splunk Search 05-09-2021
0 8
0
8
schou87
I am relatively new to this wonderful tool called SPLUNK. Please excuse me if this question has already been answered...
by schou87 Path Finder in Splunk Search 05-09-2021
0 4
0
4
Msugiyama
Dear ALL,I want to insert a value into a subsearch using the search result as a variable.Do the following search to g...
by Msugiyama Path Finder in Splunk Search 05-09-2021
0 2
0
2
prajwal_94
For the below query, searching for the values of 2nd occurence of earliest and latest events so that the timechart wo...
by prajwal_94 Explorer in Splunk Search 05-09-2021
0 2
0
2
hvdtol
I would kindly need some help for a query i am not able to create.I have  inputlookups as source.And i want to filter...
by hvdtol Path Finder in Splunk Search 05-09-2021
0 4
0
4
PaintItParker
Right now I have something like this: index=my_index sourcetype=my_sourcetype | rex field=message "- (?<User>\S+) -:"...
by PaintItParker Explorer in Splunk Search 05-08-2021
0 3
0
3
cboonyan
I am aiming to provide headers to my generated report. I have 3 hosts, host1 host2 and host3. My report is configured...
by cboonyan New Member in Splunk Search 05-08-2021
0 1
0
1
Matthew
Hi Guys, Wondering if you can help me out with the following. Within a single event I have to fields: 1) expiry_date2...
by Matthew Engager in Splunk Search 05-08-2021
0 2
0
2
sh_tavousi
Hi,I have 2 servers with the same names and I have installed universal forwarder on both servers. In forwarder manage...
by sh_tavousi Explorer in Splunk Search 05-08-2021
0 3
0
3
junlozhang
Let's say the data looks like:StudentNameStudentIdGradeExamDateTom1602021-04-01Jerry2702021-04-01Tom1622021-04-07Jerr...
by junlozhang Explorer in Splunk Search 05-08-2021
0 2
0
2
obais9346
Example:field1=ADOBE INC.field2=ADOBE SYSTEMS&sep1; INCORPORATEDi want to match this as both fields containing "ADOBE...
by obais9346 Engager in Splunk Search 05-07-2021
0 3
0
3
Hemnaath
Hi All,   Can any one guide me how to find, how much data is getting ingested into Splunk from a particular HEC token...
by Hemnaath Motivator in Splunk Search 05-07-2021
0 3
0
3
nikoloz04
I have O365 logs in Splunk. I want to find all shared files/folders plus display sensitivity labels of these files. A...
by nikoloz04 New Member in Splunk Search 05-07-2021
0 0
0
0
bcouavoux
Hello !My data is in this form  :_time (dd/mm/yyyy), NbRisk, SubProject, GlobalProject02/05/2021, 10 ,  SubProject1, ...
by bcouavoux Explorer in Splunk Search 05-07-2021
0 4
0
4
antonio147
Hi all,I performed an initial search, to this I added a second search, with the map command, where based on the value...
by antonio147 Communicator in Splunk Search 05-07-2021
0 3
0
3
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...