Splunk Search

Splunk Search
Community Activity
schou87
I am relatively new to this wonderful tool called SPLUNK. Please excuse me if this question has already been answered...
by schou87 Path Finder in Splunk Search 05-09-2021
0 4
0
4
Msugiyama
Dear ALL,I want to insert a value into a subsearch using the search result as a variable.Do the following search to g...
by Msugiyama Path Finder in Splunk Search 05-09-2021
0 2
0
2
prajwal_94
For the below query, searching for the values of 2nd occurence of earliest and latest events so that the timechart wo...
by prajwal_94 Explorer in Splunk Search 05-09-2021
0 2
0
2
hvdtol
I would kindly need some help for a query i am not able to create.I have  inputlookups as source.And i want to filter...
by hvdtol Path Finder in Splunk Search 05-09-2021
0 4
0
4
PaintItParker
Right now I have something like this: index=my_index sourcetype=my_sourcetype | rex field=message "- (?<User>\S+) -:"...
by PaintItParker Explorer in Splunk Search 05-08-2021
0 3
0
3
cboonyan
I am aiming to provide headers to my generated report. I have 3 hosts, host1 host2 and host3. My report is configured...
by cboonyan New Member in Splunk Search 05-08-2021
0 1
0
1
Matthew
Hi Guys, Wondering if you can help me out with the following. Within a single event I have to fields: 1) expiry_date2...
by Matthew Engager in Splunk Search 05-08-2021
0 2
0
2
sh_tavousi
Hi,I have 2 servers with the same names and I have installed universal forwarder on both servers. In forwarder manage...
by sh_tavousi Explorer in Splunk Search 05-08-2021
0 3
0
3
junlozhang
Let's say the data looks like:StudentNameStudentIdGradeExamDateTom1602021-04-01Jerry2702021-04-01Tom1622021-04-07Jerr...
by junlozhang Explorer in Splunk Search 05-08-2021
0 2
0
2
obais9346
Example:field1=ADOBE INC.field2=ADOBE SYSTEMS&sep1; INCORPORATEDi want to match this as both fields containing "ADOBE...
by obais9346 Engager in Splunk Search 05-07-2021
0 3
0
3
Hemnaath
Hi All,   Can any one guide me how to find, how much data is getting ingested into Splunk from a particular HEC token...
by Hemnaath Motivator in Splunk Search 05-07-2021
0 3
0
3
nikoloz04
I have O365 logs in Splunk. I want to find all shared files/folders plus display sensitivity labels of these files. A...
by nikoloz04 New Member in Splunk Search 05-07-2021
0 0
0
0
bcouavoux
Hello !My data is in this form  :_time (dd/mm/yyyy), NbRisk, SubProject, GlobalProject02/05/2021, 10 ,  SubProject1, ...
by bcouavoux Explorer in Splunk Search 05-07-2021
0 4
0
4
antonio147
Hi all,I performed an initial search, to this I added a second search, with the map command, where based on the value...
by antonio147 Communicator in Splunk Search 05-07-2021
0 3
0
3
wiar
I have a search result where each 3  follwing lines are a block I want to join to one row like:fld1 fld2 fld3 fld4A  ...
by wiar Explorer in Splunk Search 05-07-2021
0 4
0
4
Am
Hello,Two months ago we had the trial for the Enterprise version but now we are using the free version. Since the fre...
by Am Explorer in Splunk Search 05-07-2021
0 9
0
9
lancair
Desired Outcome : I am trying to create a simple timechart  to show a count of ports and the relative time line on th...
by lancair Observer in Splunk Search 05-07-2021
0 3
0
3
splunkkid
Hello,I'm struggling with the way to make efficient alerts trigger with SPL. I made splunk dashboard to visualize our...
by splunkkid Path Finder in Splunk Search 05-07-2021
0 0
0
0
renuka
<search id="base_query_filter"><query>      Index=a,sourcetype=x,eval y=A+B</query></search><search id="base_query"><...
by renuka Path Finder in Splunk Search 05-06-2021
0 2
0
2
splunkcol
I have 2 servers that receive the logs through Syslog and through a universal forwarder I forward them to 2 indexers....
by splunkcol Builder in Splunk Search 05-06-2021
0 1
0
1
cyp112
Hello,I am trying to use a subsearch on another search but not sure how to format it properlySubsearch:eventtype=pan ...
by cyp112 Engager in Splunk Search 05-06-2021
0 2
0
2
cclva
I have a dashboard which provides a handful of filter criteria, for example, `fieldA=A` and `fieldB=B`.One such crite...
by cclva Explorer in Splunk Search 05-06-2021
0 1
0
1
mdeterville
Hello SMEs:I need some assistance extracting everything between the 1st and 2nd semi-colon ; (FROM THE RIGHT)  from a...
by mdeterville Path Finder in Splunk Search 05-06-2021
0 4
0
4
Alfred
I want to extract from the Message field in the Windows Event Log just the first few words until the period - example...
by Alfred Explorer in Splunk Search 05-06-2021
0 5
0
5
billycn20
i have a working query which is monitoring the success rate based off a value called app_id. i want to extend the cur...
by billycn20 Explorer in Splunk Search 05-06-2021
0 4
0
4
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...