Splunk Search

Splunk Search
Community Activity
vn_g
ReconnectedTimeReconnectedDetails2021-02-02T16:46:19.0002021-02-02T08:54:48.000|viceusr|0xA310B|BEK-329999910922|11.1...
by vn_g Path Finder in Splunk Search 02-04-2021
0 3
0
3
CesarCrt
Hello everyone,I have multiple fields and i want to extract an ID from it. (That's the only value that changes in it)...
by CesarCrt Path Finder in Splunk Search 02-04-2021
0 5
0
5
duckware
Using 'delta' I am able to figure this out, but in one time direction.  Now I need the other time direction.In the cu...
by duckware Explorer in Splunk Search 02-04-2021
0 2
0
2
ssaenger
Hi, i have datanamebinarykeynumberSteve110012345Steve10013246Steve 12347Charles 23456 I am trying to count the whethe...
by ssaenger Communicator in Splunk Search 02-04-2021
0 14
0
14
willadams
I have 3 data sets that I need to combine with 1 data set not having a field to perform a compare.  I initially start...
by willadams Contributor in Splunk Search 02-03-2021
0 6
0
6
Ruslan
Query example:   index=eks sourcetype="kube:container" message=log | fields data.user_agent | rex field=data.user_age...
by Ruslan Engager in Splunk Search 02-03-2021
0 2
0
2
vikram1583
i have a date field like this 2021-01-29 00:25:58.913024+00 i want to convert this just date as days field using now(...
by vikram1583 Explorer in Splunk Search 02-03-2021
0 6
0
6
djm229
I've Googled it, but can't find a SOLUTION.  I've got a search that pulls Validators remaining per Subject.  I want t...
by djm229 Engager in Splunk Search 02-03-2021
0 1
0
1
vn_g
Each multi-value field (FiledName: R_time ) which has time value in epoch format should be compared to it previous ev...
by vn_g Path Finder in Splunk Search 02-03-2021
0 10
0
10
fdevera
1st search works (I get all fields in my table including GUID): earliest=-1y index=azuread sourcetype="ms:aad:audit" ...
by fdevera Path Finder in Splunk Search 02-03-2021
0 0
0
0
rkeq0515
I have a dashboard built that views today's events for processes running on systems.  To focus on a single event, I h...
by rkeq0515 Path Finder in Splunk Search 02-03-2021
0 3
0
3
dfraseman
The following search gives me a table that contains the number of lines of code on the first of each month and calcul...
by dfraseman Explorer in Splunk Search 02-03-2021
0 5
0
5
umairnajib
Hi All, How can I see number of hits on a specific destination IP by using the search and reporting tab ? Regards
by umairnajib New Member in Splunk Search 02-03-2021
0 1
0
1
LGP
Hi all,I am struggling with an issue about Splunk Developing. Our target is to freeze a row. Every time that anyone c...
by LGP New Member in Splunk Search 02-03-2021
0 1
0
1
Mrig342
Hi All,I have the below types of logs in in two different hosts in my index:HOST= abclog1: Tue Feb 2 19:07:26 EST 202...
by Mrig342 Contributor in Splunk Search 02-03-2021
0 9
0
9
jmo1
I have a query to find missing forwarders.  It is based on code I received here and it is so very close to working.  ...
by jmo1 Path Finder in Splunk Search 02-03-2021
0 0
0
0
inventsekar
Hi All... As i am trying to find out the the long running search queries using this rest search, its working fine, bu...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2021
0 2
0
2
pcyr
Scenario: I have 10 machines infected with malware. The believed infection source is email, I am attempting to create...
by pcyr Engager in Splunk Search 02-03-2021
0 3
0
3
moayadalghamdi
Hello Splunkers ! i have a problem here, that we're running an infra structure change and for that im getting duplica...
by moayadalghamdi Path Finder in Splunk Search 02-03-2021
0 2
0
2
Mrig342
Hi,I have the below types of logs in in two different hosts in my index:HOST= abclog1: Tue Feb 2 19:07:26 EST 2021 Ho...
by Mrig342 Contributor in Splunk Search 02-03-2021
0 4
0
4
youngso
Here is the regex to extract message_type based on CIM.  Could anyone make this faster than 1387 steps?https://regex1...
by SplunkTrust SplunkTrust in Splunk Search 02-02-2021
0 3
0
3
thiruyadav17
I need help on the query:
by thiruyadav17 Engager in Splunk Search 02-02-2021
0 1
0
1
simpkins1958
Have time-based lookups working well with CSV file. When I try to get it working with KV Store, I CANNOT get it to wo...
by simpkins1958 Contributor in Splunk Search 02-02-2021
2 5
2
5
fsiemonssplunk
Hi, I have simplified my query as much as possible. Basically I am looking at two issues with this:1: I cannot perfor...
by fsiemonssplunk Explorer in Splunk Search 02-02-2021
0 8
0
8
adamsmith47
I was attempting to add a lookup definition in a custom app, but, after visiting the page successfully a few times, n...
by adamsmith47 Communicator in Splunk Search 02-02-2021
0 4
0
4
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors