Splunk Search

Splunk Search
Community Activity
aferns0804
I am running a search job to view Vulnerability results/data. The search runs every week Saturday evening.  I want to...
by aferns0804 Engager in Splunk Search 03-24-2021
0 3
0
3
exchanger
Hello, With Appendcols I now have both values in one line. However, I would like to compare the values with each othe...
by exchanger Path Finder in Splunk Search 03-24-2021
0 2
0
2
SamHTexas
How do I get a complete list of users logging into Splunk Enterprise & ES. Please share SPL strings used. How to prep...
by SamHTexas Builder in Splunk Search 03-24-2021
0 3
0
3
VijaySrrie
Hi,I have a lookup file which takes some time to load (Look up has 19Lakhs data) - This lookup is used in a dashboard...
by VijaySrrie Builder in Splunk Search 03-24-2021
0 1
0
1
mullica1
Greetings-I'm putting together a dashboard query that shows uid's and systems as a result. I would like to resolve th...
by mullica1 Engager in Splunk Search 03-24-2021
0 6
0
6
kranthimutyala
Hi Splunkers,I have the below logs and trying to create an alert if a process run is taking more than the expected ti...
by kranthimutyala Path Finder in Splunk Search 03-24-2021
0 1
0
1
fdevera
Hi I have this search here where I want to limit the results to only events that have more than 1 url hit on an src_i...
by fdevera Path Finder in Splunk Search 03-24-2021
0 3
0
3
vinothn
Hi team,I am trying to send earliest and latest time values from lookup to saved search but i am not able to get resu...
by vinothn Path Finder in Splunk Search 03-24-2021
0 1
0
1
vn_g
i have to upload the .csv file that gets generated on my local machine through a script to SH clustered environment u...
by vn_g Path Finder in Splunk Search 03-24-2021
0 8
0
8
Vignesh-107
I have a query result . i want to append the three colors  based on values  and the table is dynamic based on the tim...
by Vignesh-107 Path Finder in Splunk Search 03-24-2021
0 1
0
1
rbachu1
Hi Everyone, I have two events like below on the same index though. I captured all fields through rex command but una...
by rbachu1 Explorer in Splunk Search 03-24-2021
0 5
0
5
jonthree
I have 4 applications integrated with each other -  their names let's say A, B, C, D respectively. All these applicat...
by jonthree Explorer in Splunk Search 03-23-2021
0 2
0
2
jeganl
Hi Ninjas, I'm trying to make a table that should list date, domains, action_types, action_type_usage_in_MB, Domain_u...
by jeganl Engager in Splunk Search 03-23-2021
0 2
0
2
ebarnhill
Noob here. Can anyone tell me why the following search:search sourcetype=srt  | table serialNumberwill give me a one-...
by ebarnhill Engager in Splunk Search 03-23-2021
0 1
0
1
daryllj
Hi all- we want to get a bit more elegant with correlation searching between two different indexes.  There seems to b...
by daryllj Path Finder in Splunk Search 03-23-2021
0 2
0
2
Rjbeckwith
Hi all, I have a table like this_timefile1.txtfile2.txtfile3.txt*.txt1472160022147216002214721600001472160099...14721...
by Rjbeckwith Explorer in Splunk Search 03-23-2021
0 2
0
2
gl_splunkuser
Hello everyone, I have a situation, I would like to read a lookup and for each field that match with a search criteri...
by gl_splunkuser Path Finder in Splunk Search 03-23-2021
0 0
0
0
kranthimutyala
Hi Splunkers,we have a transaction which runs for every 4hours and usually take 5mins to complete.Im trying to set up...
by kranthimutyala Path Finder in Splunk Search 03-23-2021
0 1
0
1
jason_hotchkiss
I have a field with similar values:myFieldJCH CornJCH CarrotJCH AppleME/OrangeI would like to populate a new field de...
by jason_hotchkiss Communicator in Splunk Search 03-23-2021
0 2
0
2
simo
Hi all,I have two scheduled searches, is there the possibility to launch the second one at the end of the first?can y...
by simo Path Finder in Splunk Search 03-23-2021
0 3
0
3
sh254087
I am trying to retrieve and display the user name of the logged in user as a label or a non-editable text on the dash...
by sh254087 Communicator in Splunk Search 03-23-2021
0 1
0
1
ocallender
I have a series of events that always start with EventTypeName = "Node Down" but there are three scenarios I'm trying...
by ocallender Explorer in Splunk Search 03-23-2021
0 0
0
0
sshanmua
I am trying to create a Splunk alert where the log line is delimited with comma,I need to get the field 4 and check i...
by sshanmua New Member in Splunk Search 03-23-2021
0 3
0
3
novotxms
We are receiving around 300gigs of syslog data everyday and we want to filter all the logs and index only what the ne...
by novotxms Loves-to-Learn in Splunk Search 03-23-2021
0 3
0
3
jugarugabi
Hi, Following search query produces output in table below:index=_pods  pod=* project=project_name state="Running"| ev...
by jugarugabi Path Finder in Splunk Search 03-23-2021
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...