Splunk Search

Splunk Search
Community Activity
mah
Hi,I have a table like that : idnameappenv123test1[app]:my_app[env]:my_env456test2[env]:my_env[app]:my_app My issue i...
by mah Builder in Splunk Search 12-31-2020
0 4
0
4
OiskyPoisky
Morning All,I've setup several internal lookup files and made them part of an Intelligence download. I've added in lo...
by OiskyPoisky Explorer in Splunk Search 12-31-2020
0 0
0
0
OiskyPoisky
Morning Community,Looking at a way to pull multiple columns into an alert Im attempting to build. In the below syntax...
by OiskyPoisky Explorer in Splunk Search 12-31-2020
0 3
0
3
timbilt
Given the following eventsHOSTVALUEHost11Host24Host32Host27Host35Host18 How do I maintain the latest value for each h...
by timbilt Loves-to-Learn Lots in Splunk Search 12-31-2020
0 1
0
1
rkishoreqa
Hi , Based on your suggestion I prepared queries for two different apps as below.  Now I need to combine these two an...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 0
0
0
peetchow
All,I know there are a lot of postings with answers on lookup tables but I am still stuck.  I have not splunked in a ...
by peetchow Loves-to-Learn Lots in Splunk Search 12-30-2020
0 2
0
2
Sam_2020
I want the values of TID_now and TID_7 days ago in my table I tried | eval TID_7days=TID(now(), "-7d@d")it says expre...
by Sam_2020 New Member in Splunk Search 12-30-2020
0 3
0
3
splunkyj
See the example values below. How do I convert the value of the version field, so that they have the same number of d...
by splunkyj Path Finder in Splunk Search 12-30-2020
0 4
0
4
splunkcol
I have been asked to generate a csv with the indexed information of 1 index after 02:00 hours and that the name of th...
by splunkcol Builder in Splunk Search 12-30-2020
0 1
0
1
SabariRajanT
Hi Team,We have designed a dashboard panel where all the azure identity protection center logs has been enabled, We s...
by SabariRajanT Path Finder in Splunk Search 12-30-2020
0 0
0
0
rkishoreqa
I need to fetch the 'sid' value from the below JSON.  For that I prepared the below query, but it is not working. |re...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 1
0
1
ngwodo
I need help on how I  can compare 1 day security metric to another day and also generate a metric report that shows l...
by ngwodo Path Finder in Splunk Search 12-30-2020
0 2
0
2
rkishoreqa
I need to build a query to get count of transactions having multiple 'jId' and time difference greater than 5 mins. W...
by rkishoreqa Communicator in Splunk Search 12-30-2020
0 5
0
5
jaibalaraman
Hi First , I would like to thank everyone in this community who guided and helped me a lot. Now i have a problem exec...
by jaibalaraman Path Finder in Splunk Search 12-30-2020
0 16
0
16
Annna
wed } } }, { "S" : "12:00" } } }, "day" M" : { "close" : { "S" : "23:00" open "S" : "12:00" } } } } }, "email" : { "S...
by Annna Explorer in Splunk Search 12-30-2020
0 3
0
3
Yolan
Hi,I am trying to use a macro inside a macro validation expression. This is because I plan to make a number of simila...
by Yolan Explorer in Splunk Search 12-30-2020
0 0
0
0
gcusello
Hi at all,I developed an app that uses a KV Store to manage a whitelist and it runs without problems.But when I start...
by SplunkTrust SplunkTrust in Splunk Search 12-30-2020
0 1
0
1
efaundez
How can you see the search.log of a bd output?Good evening, it is required to validate the information of a certain d...
by efaundez Path Finder in Splunk Search 12-30-2020
0 1
0
1
Vignesh-107
I have a saved search need to check the each hour the search is being executed based on the cron configuration.Expect...
by Vignesh-107 Path Finder in Splunk Search 12-30-2020
0 2
0
2
ngwodo
The splunk query below is only showing just one line of Metric_ID which starts at 1. I need help with the splunk quer...
by ngwodo Path Finder in Splunk Search 12-29-2020
0 1
0
1
splunkyj
How do I convert the following string value to a numerical value that represents two digits between the dots?version ...
by splunkyj Path Finder in Splunk Search 12-29-2020
0 2
0
2
responsys_cm
I have a search that generates two fields -- host and application. Application is a multivalued field with varying n...
by responsys_cm Builder in Splunk Search 12-29-2020
0 4
0
4
jaciro11
Hello Splunk Forum TEAM, I have a question refered to the integration because right now I receive the information whi...
by jaciro11 Path Finder in Splunk Search 12-29-2020
0 1
0
1
ivana27
 Hi all,i am new to Splunk and i need to create search which will show that event with end didnt occur after 15 min f...
by ivana27 Path Finder in Splunk Search 12-29-2020
0 6
0
6
sugankrish88
index=<<My_index>>  earliest="12/23/2020:10:00:00" latest="12/23/2020:11:00:00" "<<url>>" | eval MyFeild=replace(MyFe...
by sugankrish88 New Member in Splunk Search 12-29-2020
0 1
0
1
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors