Splunk Search

Splunk Search
Community Activity
fahimeh
Hello,As an admin, I deleted a user in Splunk Web, but when I try to add a user during an investigation, I still see ...
by fahimeh Explorer in Splunk Search 09-07-2024
0 3
0
3
Siddharthnegi
hello  I am getting a field port in event .ports="['22', '68', '6556']"how can i display them in separate rows.
by Siddharthnegi Contributor in Splunk Search 09-06-2024
0 2
0
2
woodcock
All 4 things use the $argument$ syntax. I am trying to use sendemail inside of a macro and have tried \$search\$, $$...
by Esteemed Legend in Splunk Search 09-06-2024
1 11
1
11
att35
Need some help in extracting Group Membership details from Windows Event Code 4627.As explained in this answer,https:...
by att35 Builder in Splunk Search 09-05-2024
0 2
0
2
cmiles416
I have an application to analyse phone call data from multiple locations. I want to generate a report that provides ...
by cmiles416 Explorer in Splunk Search 09-05-2024
2 5
2
5
ramuzzini
Hello, working on monitoring if someone has moved a file outside a specific folder inside a preset folder structure o...
by ramuzzini Path Finder in Splunk Search 09-05-2024
0 2
0
2
jgcsco
I have the following event that needs to calculate concurrency: Event, starttime=yyyy-mm-dd hh:mm:ss, duration=, sou...
by jgcsco Path Finder in Splunk Search 09-05-2024
1 14
1
14
wpb162
I am trying to delete users that just use Splunk authentication. I have the admin role. I have tried both the web GUI...
by wpb162 Explorer in Splunk Search 09-05-2024
0 9
0
9
jeck11
I'm missing something and it's probably blatantly obvious....I have a search returning a number but I want to have a ...
by jeck11 Path Finder in Splunk Search 09-05-2024
0 1
0
1
jbrenner
Let's say I have the following SPL query.  Ignore the regexes, thery're not important for the example:index=abc | rex...
by jbrenner Path Finder in Splunk Search 09-05-2024
0 3
0
3
nehamvinchankar
Hi all,I have one lookup which was having around 1000 entries recently someone has updated the lookup and all entries...
by nehamvinchankar Path Finder in Splunk Search 09-04-2024
0 5
0
5
BJanota29
I am currently working on creating an alert for a possible MFA fatigue attack from our Entra ID sign in logs. The log...
by BJanota29 New Member in Splunk Search 09-04-2024
0 1
0
1
andra_pietraru
My events have a few fields that are of the type: field_Name=failed What query should I write to get all that fields...
by andra_pietraru Path Finder in Splunk Search 09-04-2024
0 8
0
8
Satcom9
ACCU_DILAMZ9884 Failed, cueType=Splicer, SpliceEventID=0x00000BBC, SessionID=0x1A4D3100 SV event=454708529 spot=VAF00...
by Satcom9 Engager in Splunk Search 09-03-2024
0 2
0
2
tengugurl1
I have a standard printed statement that shows something like this:[29/Aug/2024:23:59:48 +0000] "GET /rest/LMNOP[29/A...
by tengugurl1 Engager in Splunk Search 09-03-2024
0 5
0
5
splunkn
Could anyone tell me the difference between outputlookup and outputcsv? If there no differences, is there any specif...
by splunkn Communicator in Splunk Search 09-03-2024
5 5
5
5
TheWiszard
Hi Guys, Has anyone done a search were you can monitor the CPU on the Fortinet Firewalls? Its on the App but doesn't ...
by TheWiszard Engager in Splunk Search 09-03-2024
0 3
0
3
elensare
I try to use lookup to specify span option value in bin command with map | inputlookup mylookupup.csv | fields Index,...
by elensare Engager in Splunk Search 09-03-2024
0 1
0
1
Siddharthnegi
hi i want to extract purple part.[Time:29-08@17:53:05.654] [60569222] 17:53:05.654 10.82.10.245 local3.notice [S=2952...
by Siddharthnegi Contributor in Splunk Search 09-03-2024
0 2
0
2
bwheelerice
The data coming into one of our indexers recently changed. Now the format is different, and the fields are different....
by bwheelerice Engager in Splunk Search 09-02-2024
0 8
0
8
tomjb94
Hi -  We have a requirement to join the below eval statement searches, would it be possible if someone could assist w...
by tomjb94 Observer in Splunk Search 09-02-2024
0 2
0
2
romanpro
 
by romanpro Explorer in Splunk Search 09-02-2024
0 3
0
3
dataisbeautiful
Hi AllI did a look around for a syntax definition for SPL in Notepad++ and didn't find one. Attached is my attempt. F...
by dataisbeautiful Communicator in Splunk Search 09-02-2024
3 0
3
0
user487596
Hello everyone! How can we solve the problem of searching for secrets in all or some splunk indexes so that splunk is...
by user487596 Explorer in Splunk Search 09-02-2024
0 5
0
5
munang
Other than poor speed and performance, is there a reason why the map command is considered dangerous?The official doc...
by munang Path Finder in Splunk Search 09-02-2024
1 2
1
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...