Splunk Search

Splunk Search
Community Activity
aikn061
Hi guys,I know this has been asked many times before but it just wont work for me hence the question.I have one index...
by aikn061 Explorer in Splunk Search 05-06-2021
0 7
0
7
wbolten
Hi,I successfully created an SPL that does what I need for a single host but I cannot get it to work for all hosts. T...
by wbolten Path Finder in Splunk Search 05-06-2021
0 3
0
3
new2splunk1
Hello members,I am new to Splunk and able to produce simple stats using STATS count by command but looking for direct...
by new2splunk1 Engager in Splunk Search 05-06-2021
0 2
0
2
aperezy17
I am new to SPLUNK learning with the Enterprise Edition. I created a new host with JSON source type. When I search so...
by aperezy17 New Member in Splunk Search 05-05-2021
0 0
0
0
husainpatanwala
Hi guys I have two statsindex |Exception| countindex |Error |countI want is something like this :index |Exception|Err...
by husainpatanwala Engager in Splunk Search 05-05-2021
0 3
0
3
roopeshetty
Hi Guys, We can see there are 6 hosts which are sending bulk events (logs) to splunk. But we don’t know who is using ...
by roopeshetty Path Finder in Splunk Search 05-05-2021
0 2
0
2
bitbucket
Hello -My data looks like (also attached as PNG for better readability):2021-04-28 - 22:01:14.728 - INFO : Action com...
by bitbucket Engager in Splunk Search 05-05-2021
0 4
0
4
cclva
I have a generic search that I am using to display data for a handful of applications, which look something like this...
by cclva Explorer in Splunk Search 05-05-2021
0 1
0
1
sbarinov
Hi, I am trying to compare event type count statistics for 2 days using the following search:earliest=-48h latest=-24...
by sbarinov Path Finder in Splunk Search 05-05-2021
0 2
0
2
maxmukimov
Hi,  I have the following query:  | bin _time span=1d | stats count as ProductCount by applysourcetype, product, _tim...
by maxmukimov Explorer in Splunk Search 05-05-2021
0 7
0
7
Lombs
Hey Splunkers,in the last days I'm trying to learn and understand the principles of LISPY to understand the fllowing ...
by Lombs Engager in Splunk Search 05-04-2021
1 0
1
0
timyong80
 Hello,How can I extract multiple values from a string after each slash? For example below, I would like to extract f...
by timyong80 Explorer in Splunk Search 05-04-2021
0 6
0
6
stevenulbrich
Hello - I am looking for recommendations on combining 2 searches that use the same Lookup CSV but different columns i...
by stevenulbrich Explorer in Splunk Search 05-04-2021
0 0
0
0
stevenulbrich
Hello - I have Splunk report that was generated 5 years ago.  I was looking for advice.  Can it be updated to work be...
by stevenulbrich Explorer in Splunk Search 05-04-2021
0 3
0
3
cindygibbs_08
Hello friends,Thank you so much for your help in advance.I have a field named "ERROR_COLAB" in which a series of resp...
by cindygibbs_08 Communicator in Splunk Search 05-04-2021
0 2
0
2
dbashyam
Hi, I am trying to extract the following [04 May 2021 13:13:59,786] [Nsh-Proxy-Thread-93] [INFO] [abc@abc.com:abc:10....
by dbashyam Explorer in Splunk Search 05-04-2021
0 3
0
3
Nidd
I have a list of unstructured logs like below for which I have to extract certain fields. Tried using "Extract fields...
by Nidd Path Finder in Splunk Search 05-04-2021
0 2
0
2
mah
Hi,I have a table like that : testtotalproductA_xxxxproductA_zzzzproductB_xxxxproductB_zzzz1220.230.360.440.55 What I...
by mah Builder in Splunk Search 05-04-2021
0 4
0
4
Matioski7
Hello,I'm trying to show this event as a table:  2021-05-04 11:28:56.722, TIME="2021-05-04 11:28:56.722", ID="0a7a270...
by Matioski7 Explorer in Splunk Search 05-04-2021
0 4
0
4
aaa2324
Hi Team,I would like to compare below 5 different columns and get one more column as a count.category code  text  cou...
by aaa2324 Explorer in Splunk Search 05-04-2021
0 3
0
3
bz
I am trying to get an alert to recognize a lookup file with a whitelist for external devices.  Some devices I don't c...
by bz New Member in Splunk Search 05-04-2021
0 0
0
0
aquinojason
Hi,I have a list of accounting codes in a lookup table. I use that to identify applications under that accounting cod...
by aquinojason Path Finder in Splunk Search 05-04-2021
0 2
0
2
Flo-Paris
Hello,i searched few hours how to extract the RULE_NAME field from my Firewall logs without success.RULE_NAME is at t...
by Flo-Paris Explorer in Splunk Search 05-04-2021
0 3
0
3
pacifikn
Greetings!!Dear all!Hope you are well. I need your support on how to calculate the size of events we received per day...
by pacifikn Communicator in Splunk Search 05-04-2021
0 4
0
4
aaa2324
How to compare the incoming data with dynamic date and time with the lookup table, examplei have incoming data in bel...
by aaa2324 Explorer in Splunk Search 05-03-2021
0 3
0
3
Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors