Splunk Search

Splunk Search
Community Activity
Rgk_Trail
Hi, I have a  few fields in lookup from which I am trying to extract strings. I read that rex is what I should be usi...
by Rgk_Trail Explorer in Splunk Search 01-20-2021
0 2
0
2
arrangineni
Recently we changed the data logging process at source and it changed the event format of the Site minder log source ...
by arrangineni Path Finder in Splunk Search 01-20-2021
0 1
0
1
jacqu3sy
I'm trying to create a chart showing activity from May through until now, knowing that the activity ceased some month...
by jacqu3sy Path Finder in Splunk Search 01-20-2021
0 2
0
2
AzmathShaik
Hello Splunkerswe are trying to restrict users (non admins) from creating knowledge objects (dashboards and reports) ...
by AzmathShaik Path Finder in Splunk Search 01-20-2021
0 4
0
4
jerinvarghese
Hi All,need help in using 2 stats operation in one program.My program: index=opennms "uei.opennms.org/nodes/nodeUp" O...
by jerinvarghese Communicator in Splunk Search 01-20-2021
0 3
0
3
renuka
Hello ALLI want the alternative search  for the following search command|bin span=1W _time aligntime=latest which giv...
by renuka Path Finder in Splunk Search 01-20-2021
0 1
0
1
altink
HelloIn the search as below: index=_audit action=alert_fired ss_app=app_name | eval alert_severity = case (severity=...
by altink Builder in Splunk Search 01-20-2021
0 1
0
1
ajebakumar
Hi, I am building a dashboard for my application being monitored in Splunk. As part of this i am getting the timestam...
by ajebakumar Loves-to-Learn in Splunk Search 01-20-2021
0 1
0
1
ChetanArgekar
I am having index (server_patching) which contain the details like changeNo, patching date etc of server which are pa...
by ChetanArgekar Explorer in Splunk Search 01-20-2021
0 1
0
1
cros
Hi, Here is my raw data : ID, Version, Date, Status 10874381,1,2020-01-15T08:36:00Z,New 10874381,1,2020-01-15T08:46:0...
by cros Engager in Splunk Search 01-20-2021
0 1
0
1
paulalbert
I'm trying to  use Splunk to return a list of records that have been modified in our LDAP since a particular datetime...
by paulalbert Engager in Splunk Search 01-20-2021
0 1
0
1
asingh4177
I have a search like this: index=my_index search=my_search | stats count as no_of_hosts by uptime It gives me uptime...
by asingh4177 Engager in Splunk Search 01-20-2021
0 4
0
4
robertlynch2020
Hi @MuS Sorry for the direct contact, I hope it's ok to ask you a question about "Add-on Debug Refresh".I have used i...
by robertlynch2020 Influencer in Splunk Search 01-19-2021
0 1
0
1
MattibergB
On our search head cluster we are running into the following issue. When searching using the time picker everything w...
by MattibergB Path Finder in Splunk Search 01-19-2021
0 4
0
4
balcv
I currently have a search looking for specific attack_id values. For example: ("attack_id=3040" OR "attack_id=3057"...
by balcv Contributor in Splunk Search 01-19-2021
2 11
2
11
att35
Hi,We have a use-case where responses(host_addr) returned from DNS queries are passed through AbuseIPDB API to check ...
by att35 Builder in Splunk Search 01-19-2021
0 2
0
2
swin88
I have a field named "test" which has the following json. If I do:| fields test{}.data{}{}.metric, test{}.data{}{}.va...
by swin88 Engager in Splunk Search 01-19-2021
0 2
0
2
cros
Hi all, My data is logging of support ticket. i retrieved all the change state of each ticket with the transaction co...
by cros Engager in Splunk Search 01-19-2021
0 4
0
4
atljoer
TLDR:  Goal is to perform an initial search which returns table of time user authenticated, then for each row in the ...
by atljoer Loves-to-Learn in Splunk Search 01-19-2021
0 3
0
3
tarunmalhotra79
Hi Splunker,I would like to lower the string/value present inside the double quotes and then use as it is.Values high...
by tarunmalhotra79 Engager in Splunk Search 01-19-2021
0 1
0
1
Michell_ctba
Hello community. I am not able to perform a sub-search between 2 sourcetypes. The 'drm' sourcetype has 5 million even...
by Michell_ctba Explorer in Splunk Search 01-19-2021
0 2
0
2
riveraj1
I am trying to find the events that are taking place between March 1 2021 and September 1 2021. I was hoping someone ...
by riveraj1 Observer in Splunk Search 01-19-2021
0 1
0
1
ivana27
Hi,please help. I would like to see in table (to extract with rex) value of field paid. Log is:2020-12-23 12:14:42.74...
by ivana27 Path Finder in Splunk Search 01-19-2021
0 1
0
1
mxanareckless
I've checked this, but it hasn't solved the problem for me: https://community.splunk.com/t5/Getting-Data-In/Is-it-pos...
by mxanareckless Path Finder in Splunk Search 01-19-2021
0 2
0
2
renuka
HelloMy question is how to combine the same values into one which are getting differentiate  by another fieldExamplei...
by renuka Path Finder in Splunk Search 01-19-2021
0 4
0
4
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...