Splunk Search

Splunk Search
Community Activity
redfan9
I am a newbie to Splunk and am trying to find out what query I can use to find a specific users browsing history for ...
by redfan9 New Member in Splunk Search 01-30-2021
0 1
0
1
AzmathShaik
Hello All,i have a default app which gets installed on the UF during the installation (part of our install script). t...
by AzmathShaik Path Finder in Splunk Search 01-29-2021
0 4
0
4
shazbot79
Hi, can anyone make any suggestions as to how I can make this search more efficient?  index=prod_service_now sourcety...
by shazbot79 Path Finder in Splunk Search 01-29-2021
0 4
0
4
gn694
I have a search created, and want to get a count of the events returned by date. I know the date and time is stored ...
by gn694 Communicator in Splunk Search 01-29-2021
3 5
3
5
AshChakor
I want to display counts latest two weeks (last two weeks), two weeks before and everything else before 4 weeks start...
by AshChakor Path Finder in Splunk Search 01-29-2021
0 1
0
1
viswatejabolla
Hi All,I have field called stepName which will have below three values.TextResource.getFirstLineTextResource.getSecon...
by viswatejabolla New Member in Splunk Search 01-29-2021
0 3
0
3
marceloalejandr
Greetings,I've 2 Lookup (csv) files, one generated from index _internal (approx 15k events) and another generated fro...
by marceloalejandr Path Finder in Splunk Search 01-29-2021
0 6
0
6
dnsGuy314
I have a current alert that is working as expected to capture a log event that states a service is down. We have sta...
by dnsGuy314 New Member in Splunk Search 01-29-2021
0 10
0
10
dpwtheitguy
All, I have this search here and it's pretty slow. Any recommendations to speed it up? Currently 250.249 seconds and ...
by dpwtheitguy Loves-to-Learn Lots in Splunk Search 01-28-2021
0 2
0
2
deepuhassan
Hi,I have the below query which does the search on two different sources in the same index and join the results based...
by deepuhassan Explorer in Splunk Search 01-28-2021
0 6
0
6
EStallcup
I'm having a bit of trouble trying to backfill a couple days in my summary index from a query using the collect comma...
by EStallcup Path Finder in Splunk Search 01-28-2021
2 14
2
14
fdevera
How would I take the results from this search:| rex field=initiatedBy.user.userPrincipalName "ex(?<GUID>\d+)z\@"And p...
by fdevera Path Finder in Splunk Search 01-28-2021
0 3
0
3
TheBravoSierra
I'm trying to look for senders where they don't contain values from the lookup mimics.csv. Examples of values in the ...
by TheBravoSierra Path Finder in Splunk Search 01-28-2021
0 3
0
3
redrobish1
Been testing to get a ISE-Splunk successful authentication report and trying this but the "Calling-Station-ID" is not...
by redrobish1 Engager in Splunk Search 01-28-2021
0 2
0
2
youngso
Here is what I've done.  How to break out the results into individual software correctly in Splunk.  Any tips could b...
by SplunkTrust SplunkTrust in Splunk Search 01-28-2021
0 3
0
3
alexspunkshell
Hi All,Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
by alexspunkshell Contributor in Splunk Search 01-28-2021
0 3
0
3
shazbot79
Hi,I have used the Service Now add on to pull in the incident table. We have a custom SNow field called "dv_u_configu...
by shazbot79 Path Finder in Splunk Search 01-28-2021
0 2
0
2
gcue
i am trying to figure out what the output values are not showing up in my pie chart.  i would eventually like to grap...
by gcue Loves-to-Learn in Splunk Search 01-28-2021
0 2
0
2
prettysunshinez
I have a search query that outputs the count of the event for all the host (i.e., | stats count by host)Now if the co...
by prettysunshinez Explorer in Splunk Search 01-28-2021
0 4
0
4
Abha11
I am having an issue with one of my monitor stanza in inputs.conf. The stanza is as below:  [monitor://E:Speech\Tomca...
by Abha11 Explorer in Splunk Search 01-28-2021
0 3
0
3
sweiland
Hello Everyone, We are currently working on exchange logs (IIS), and trying to detect abnormal traffic from different...
by sweiland Path Finder in Splunk Search 01-28-2021
0 10
0
10
DanielAmlung
Hi,iam stuck with a problem where i need help from you guys. I have a search that runs IDs against a lookup to determ...
by DanielAmlung Path Finder in Splunk Search 01-28-2021
0 3
0
3
renSplunk
Hi,I have a query that gives a table of records satisfying certain condition. Have another query that gives the same ...
by renSplunk New Member in Splunk Search 01-28-2021
0 3
0
3
moayadalghamdi
Hello Splunkers ! i want to write a command that shows a timeline of authentication activities as following:index=MyI...
by moayadalghamdi Path Finder in Splunk Search 01-27-2021
0 2
0
2
arielpconsolaci
Hi Splunkers,Good day. I am trying to perform search time masking using a Calculated Field to replace _raw with the r...
by arielpconsolaci Path Finder in Splunk Search 01-27-2021
0 6
0
6
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors