Splunk Search

Splunk Search
Community Activity
jlph
I would like to run a query for any user additions to privileged Active Directory groups. I am storing the AD groups ...
by jlph Loves-to-Learn in Splunk Search 04-17-2021
0 1
0
1
biers04
I am working on statsing firewall data into a sparkline.  However, when I run the search, the sparkline caps out at 1...
by biers04 Explorer in Splunk Search 04-16-2021
0 0
0
0
aquinojason
Hi,Is there a way from a dashboard perspective that I present a chart from 2 big groups and if I click on the legend ...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 5
0
5
aquinojason
Hi, Below is a result of a lookup command, how do I exclude the other information if I based in on BusinessUnit, For ...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 4
0
4
Sathya0Q
 I recently started learning Splunk . Could you help me!!Have list of users and particular looking for search query t...
by Sathya0Q Engager in Splunk Search 04-16-2021
0 1
0
1
sumandevops
Example:My search is index=* source=*xyz*I am getting an event with plenty of lines in string formatI want to display...
by sumandevops Engager in Splunk Search 04-16-2021
0 9
0
9
aquinojason
Hi, I am trying to do the following:1. Using this | inputlookup Application.csv where BusinessUnit = BU1, it will fil...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 2
0
2
jason_hotchkiss
Greeting Splunkers:Referring to: eval - Splunk Documentation where:round(X,Y)Returns X rounded to the amount of decim...
by jason_hotchkiss Communicator in Splunk Search 04-16-2021
0 2
0
2
emallinger
Hello,I'm faced today with something I do not understand.Here the structure of my event (JSON structured) : { dateRep...
by emallinger Communicator in Splunk Search 04-16-2021
0 2
0
2
SamHTexas
Where do I find a list of orphaned searches, Reports and Alerts so they an be deleted or disabled? For the purpose of...
by SamHTexas Builder in Splunk Search 04-16-2021
0 4
0
4
pgawron2
I'm currently trying to find workstations that haven't been logged into by a human over a period of time.My first que...
by pgawron2 Loves-to-Learn in Splunk Search 04-16-2021
0 9
0
9
dyapasrikanth
I am getting statistics like below (only 3 categories) Category Amount cat1 20 cat2 30 cat3 40 and add...
by dyapasrikanth Path Finder in Splunk Search 04-15-2021
0 3
0
3
REACHGPRAVEEN
Good Evening All,I am looking for a solution to a splunk panel when I try to click on any cell value it should open e...
by REACHGPRAVEEN Explorer in Splunk Search 04-15-2021
0 1
0
1
joemiller
Looking at the example field below (part of a JSON event), I'm trying to figure out how at search time to pair up the...
by joemiller Path Finder in Splunk Search 04-15-2021
0 5
0
5
totalnet32
I don't know how to query my duo servers to find out how any users many are set to disabled and some users might have...
by totalnet32 New Member in Splunk Search 04-15-2021
0 0
0
0
dab55
Hi all,I'm trying to create a chart containing two timecharts for different time frames (e.g. today/yesterday). How c...
by dab55 Engager in Splunk Search 04-15-2021
0 3
0
3
Chandu53000
Hi All,I'm new to Splunk and want to execute a splunk query without using CLI or GUI.Options like ETL tool or a shell...
by Chandu53000 Observer in Splunk Search 04-15-2021
0 1
0
1
nadeige1
Hello,I am using the chart command in order to display data using a line chart:| chart values("torque") as variable o...
by nadeige1 Engager in Splunk Search 04-15-2021
1 2
1
2
sumandevops
I have field DivionsID with data of Exe.123, how to trim this to just 123 ?
by sumandevops Engager in Splunk Search 04-15-2021
0 7
0
7
logginz85
Hi all.This rule has been driving me crazy for a while now, and the teams working on it too.Just looking for a way to...
by logginz85 Explorer in Splunk Search 04-15-2021
0 0
0
0
satyajit7
I have a 1st query by taking input from the dashboard and where I got id as a result from that. And I want to use tha...
by satyajit7 Explorer in Splunk Search 04-15-2021
0 7
0
7
jip31
hithe field dv_sys_created_on is a field dateindex="tutu" sourcetype="toto" | stats last(dv_sys_created_on) as Opene...
by jip31 Motivator in Splunk Search 04-15-2021
0 2
0
2
surekhasplunk
I have index=syslog where the hostname comes as fqdn and Ip addressi want rex to modify only hostname field only wher...
by surekhasplunk Communicator in Splunk Search 04-15-2021
0 4
0
4
balcv
I have a list of source ip addresses in a csv file loaded into Splunk as a lookup file.  The file has a single field,...
by balcv Contributor in Splunk Search 04-15-2021
0 6
0
6
nalia_v
Hello everyone,Someone may already be doing the output of grouped events with the definition of location by ip.How no...
by nalia_v Loves-to-Learn Everything in Splunk Search 04-15-2021
0 1
0
1
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors