Splunk Search

Splunk Search
Community Activity
NatSec
I have two search conditions that I need to trigger alerts from. I have a hundred hosts on a HA cluster. Sometimes ho...
by NatSec Explorer in Splunk Search 02-23-2021
0 2
0
2
REACHGPRAVEEN
Hi ,Please help on this @niketnthe below 2 rows as single panelsearch by employeeid(hyperlink)search by app(hyperlink...
by REACHGPRAVEEN Explorer in Splunk Search 02-23-2021
0 3
0
3
kgs
My goal is to match whatever is after "Commit Description:" up until but not including the " after TASK0123456. I don...
by kgs Loves-to-Learn in Splunk Search 02-23-2021
0 2
0
2
bhartiya008
I  am trying to build a splunk query to get the error summary from a log. I want to capture all the events where ther...
by bhartiya008 Explorer in Splunk Search 02-23-2021
0 7
0
7
eylonronen
Hello everyoneI found a wierd bug in the cascading replication process. The shcluster captain says when he tries to r...
by eylonronen Explorer in Splunk Search 02-23-2021
0 0
0
0
bowesmana
While on a mission to eradicate 'join', I was showing someone how to replace a join statement with stats.However, the...
by SplunkTrust SplunkTrust in Splunk Search 02-23-2021
0 2
0
2
trapper_dave
Hi,I have a dashboard with a dropdown form allowing users to select the time period they wish to analyse.I am looking...
by trapper_dave Engager in Splunk Search 02-23-2021
0 3
0
3
ank15july96
I'm trying to extract this field that has colon, backslash and quotes around it and its not yielding any result.Field...
by ank15july96 Engager in Splunk Search 02-22-2021
0 5
0
5
bp32795
I am trying to create an alert that will utilize a search with data from two lookups. Basically, I want to:Take/retur...
by bp32795 New Member in Splunk Search 02-22-2021
0 1
0
1
Murlivelage
I need a query to find Memory usage more than 90 percent by hostnameis it a good idea to do in splunk vs app dynamics
by Murlivelage New Member in Splunk Search 02-22-2021
0 1
0
1
dwibedi03
I have two query that is exact same except the use of the lookup for each search. The one query includes data from a ...
by dwibedi03 Explorer in Splunk Search 02-22-2021
0 2
0
2
mxanareckless
Need to run a dbxquery command via the REST API, and having trouble defining the search's time range in that context....
by mxanareckless Path Finder in Splunk Search 02-22-2021
0 3
0
3
tod_s
Hi Splunk community,I am trying to determine the impact of removing Adobe Flash from our environment.I have done basi...
by tod_s New Member in Splunk Search 02-22-2021
0 3
0
3
splunk_new1
I am using a table of results  a | b | c | search | d | e ======================================...
by splunk_new1 Explorer in Splunk Search 02-22-2021
0 2
0
2
jparrenas26
I'm looking to create a bandwidth chart showing the bandwidth traffic our firewall over a time period and converting ...
by jparrenas26 Engager in Splunk Search 02-22-2021
0 6
0
6
avshabanov
Context: existing Splunk installation I'm working with is not very robust when handling search requests due to sheer ...
by avshabanov New Member in Splunk Search 02-22-2021
0 1
0
1
steeleverint
Hi,I have an event json similar to:{"stages":[{"duration":12,"status":"Success","children":[{"test":"integration","re...
by steeleverint Engager in Splunk Search 02-22-2021
0 2
0
2
kelie
So here is my existing query as it runs nowsourcetype=snort[search sourcetype=snort |top limit=20 src| table src]| st...
by kelie Path Finder in Splunk Search 02-22-2021
0 4
0
4
nagpalga
I wanted to create multiple timecharts in a single search. The scenario i am stuck in is something like this :index =...
by nagpalga Engager in Splunk Search 02-22-2021
1 5
1
5
deaseec
I am looking to catalog which reports/alerts utilize which notification actions. I have a search currently that keys ...
by deaseec Engager in Splunk Search 02-22-2021
0 2
0
2
tonymaibox
Hi all, hope all is well!I'm unsetting a token in the <change> block of a <query>. However, I'm finding that the <uns...
by tonymaibox New Member in Splunk Search 02-22-2021
0 2
0
2
saeko18
By upgrading to splunk v8.0.5, I can no longer use the lookup updater that was previously possible with Sideview Admi...
by saeko18 New Member in Splunk Search 02-22-2021
0 0
0
0
ppatkar
I have multiple events in Splunk like below :Exception:100 : *** Error 3006 Logons are disabled., Job=ABCException:XY...
by ppatkar Path Finder in Splunk Search 02-22-2021
0 4
0
4
LegalPrime
Hello, I am extracting a lot of values during search (using eval & split as recommended here), one of them being `use...
by LegalPrime Path Finder in Splunk Search 02-22-2021
0 1
0
1
DataOrg
I have around 15 columns in table , where i want to have fixed column width for 3columns with 30px and other remainin...
by DataOrg Builder in Splunk Search 02-22-2021
0 2
0
2
Get Updates on the Splunk Community!

Optimize AI at Scale: Must-Attend Observability Sessions at .conf26

conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help ...

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...