Splunk Search

Splunk Search
Community Activity
rockb
I just installed splunk and imported my license.I have a series of Windows event viewer files that have been exported...
by rockb Explorer in Splunk Search 05-12-2021
0 3
0
3
Sean_oldR3dF0x
I am struggling with subsearches and getting and correlating data in a single output.I need to figure out which users...
by Sean_oldR3dF0x New Member in Splunk Search 05-12-2021
0 3
0
3
sh_tavousi
Hi,I want to know how I can see what SQL queries are used on every table of my SQL databases. I mean, I want to monit...
by sh_tavousi Explorer in Splunk Search 05-12-2021
0 1
0
1
aferchichi
Hi, I specified the following in transforms.conf SOURCE_KEY = MetaData:Host REGEX = ^8\.\d{1,3}\.\d{1,3}\.\d{1,3}$ ...
by aferchichi New Member in Splunk Search 05-12-2021
0 11
0
11
wiar
I have the following output from a searchfld1 fld2 fld3 fld4A               BI                 J                  B  ...
by wiar Explorer in Splunk Search 05-12-2021
0 4
0
4
ebs
Hi,I'm using the following datamodel search:| datamodel Test_Ping_Access summariesonly=true search | search "Ping_Acc...
by ebs Communicator in Splunk Search 05-11-2021
0 2
0
2
ebs
Hi,I created a data model and the searches were working previously but now it keeps failing and I don't know why. Is ...
by ebs Communicator in Splunk Search 05-11-2021
0 2
0
2
spicy
The case function seems to finding the first true statement and displays that value. Is there another function or dif...
by spicy Path Finder in Splunk Search 05-11-2021
0 2
0
2
gamecocks20
I have a set of data with X categories and each category is getting measured (measurements are positive or negative d...
by gamecocks20 Loves-to-Learn in Splunk Search 05-11-2021
0 0
0
0
Traer001
Hello,I am trying to assign a value from one field to all earlier instances of a field until a non-null value is met....
by Traer001 Path Finder in Splunk Search 05-11-2021
0 2
0
2
jaibalaraman
Hi Team I am trying to extract the OS details from the user agent using the below eval command, however I am not able...
by jaibalaraman Path Finder in Splunk Search 05-11-2021
0 3
0
3
pedromvieira
Hi. I'd like to use KV Store lookup in an accelerated Data Model. When I set data model this messages occurs: 01-10...
by pedromvieira Communicator in Splunk Search 05-11-2021
2 5
2
5
moinyuso96
So what I have now from my search so farProduct     Status    TimeA                   Start        8.00 AMA          ...
by moinyuso96 Path Finder in Splunk Search 05-11-2021
0 2
0
2
SS1
Hi,I need some help with the regex,Currently we have below two paths, note the naming format is different for the log...
by SS1 Path Finder in Splunk Search 05-10-2021
0 4
0
4
ebs
Hi,I'm trying to create an eval expression in my data model which is based on _time. Can you please advise on what I'...
by ebs Communicator in Splunk Search 05-10-2021
0 3
0
3
jhick
Currently my splunk search to get a list of macs of the security cameras with their respective IP is index = dhcp 00:...
by jhick Observer in Splunk Search 05-10-2021
0 1
0
1
phamxuantung
Hello I have some event logs that show batch purchase like this: Event 1: <BankID>Bank A</BankID> <value>5</value> <s...
by phamxuantung Communicator in Splunk Search 05-10-2021
0 1
0
1
abowesman
The following example | makeresults | eval FilePath="\\Temp.exe" | where match(FilePath, "(?i)\\Temp\.exe$") Creates ...
by abowesman Explorer in Splunk Search 05-10-2021
0 0
0
0
ershad_c
The date field sometimes has 2 spaces and sometimes 1 space, depending on whether the date is a single digit or doubl...
by ershad_c Engager in Splunk Search 05-10-2021
0 2
0
2
keshavgupta
SpoilerHow to split/extract substring before the first - from the right side of the field on splunk searchHow to spli...
by keshavgupta Engager in Splunk Search 05-10-2021
0 1
0
1
kirrusk
how to use horseshoe meter for below queryindex = *   | table podname cluster status | dedup podname cluster status |...
by kirrusk Communicator in Splunk Search 05-10-2021
0 1
0
1
yifatcy
Hi,I've been trying for hours and nothing works, so I figure you might help me out.I have the following very long que...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 2
0
2
Flobzh
Dear all,I'm trying to retrieve some log metadata and associate them to all my events.Exemple: When my application st...
by Flobzh Explorer in Splunk Search 05-10-2021
0 1
0
1
or1515
Hi,My query:index=ph_windows_sec sourcetype=XmlWinEventLog (EventCode=630 OR EventCode=4726 OR EventCode=624 OR Event...
by or1515 Loves-to-Learn Everything in Splunk Search 05-10-2021
0 2
0
2
yifatcy
Hi,Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each c...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 0
0
0
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors