Splunk Search

Splunk Search
Community Activity
wpb162
I am trying to delete users that just use Splunk authentication. I have the admin role. I have tried both the web GUI...
by wpb162 Explorer in Splunk Search 09-05-2024
0 9
0
9
jeck11
I'm missing something and it's probably blatantly obvious....I have a search returning a number but I want to have a ...
by jeck11 Path Finder in Splunk Search 09-05-2024
0 1
0
1
jbrenner
Let's say I have the following SPL query.  Ignore the regexes, thery're not important for the example:index=abc | rex...
by jbrenner Path Finder in Splunk Search 09-05-2024
0 3
0
3
nehamvinchankar
Hi all,I have one lookup which was having around 1000 entries recently someone has updated the lookup and all entries...
by nehamvinchankar Path Finder in Splunk Search 09-04-2024
0 5
0
5
BJanota29
I am currently working on creating an alert for a possible MFA fatigue attack from our Entra ID sign in logs. The log...
by BJanota29 New Member in Splunk Search 09-04-2024
0 1
0
1
andra_pietraru
My events have a few fields that are of the type: field_Name=failed What query should I write to get all that fields...
by andra_pietraru Path Finder in Splunk Search 09-04-2024
0 8
0
8
Satcom9
ACCU_DILAMZ9884 Failed, cueType=Splicer, SpliceEventID=0x00000BBC, SessionID=0x1A4D3100 SV event=454708529 spot=VAF00...
by Satcom9 Engager in Splunk Search 09-03-2024
0 2
0
2
tengugurl1
I have a standard printed statement that shows something like this:[29/Aug/2024:23:59:48 +0000] "GET /rest/LMNOP[29/A...
by tengugurl1 Engager in Splunk Search 09-03-2024
0 5
0
5
splunkn
Could anyone tell me the difference between outputlookup and outputcsv? If there no differences, is there any specif...
by splunkn Communicator in Splunk Search 09-03-2024
5 5
5
5
TheWiszard
Hi Guys, Has anyone done a search were you can monitor the CPU on the Fortinet Firewalls? Its on the App but doesn't ...
by TheWiszard Engager in Splunk Search 09-03-2024
0 3
0
3
elensare
I try to use lookup to specify span option value in bin command with map | inputlookup mylookupup.csv | fields Index,...
by elensare Engager in Splunk Search 09-03-2024
0 1
0
1
Siddharthnegi
hi i want to extract purple part.[Time:29-08@17:53:05.654] [60569222] 17:53:05.654 10.82.10.245 local3.notice [S=2952...
by Siddharthnegi Contributor in Splunk Search 09-03-2024
0 2
0
2
bwheelerice
The data coming into one of our indexers recently changed. Now the format is different, and the fields are different....
by bwheelerice Engager in Splunk Search 09-02-2024
0 8
0
8
tomjb94
Hi -  We have a requirement to join the below eval statement searches, would it be possible if someone could assist w...
by tomjb94 Observer in Splunk Search 09-02-2024
0 2
0
2
romanpro
 
by romanpro Explorer in Splunk Search 09-02-2024
0 3
0
3
dataisbeautiful
Hi AllI did a look around for a syntax definition for SPL in Notepad++ and didn't find one. Attached is my attempt. F...
by dataisbeautiful Communicator in Splunk Search 09-02-2024
3 0
3
0
user487596
Hello everyone! How can we solve the problem of searching for secrets in all or some splunk indexes so that splunk is...
by user487596 Explorer in Splunk Search 09-02-2024
0 5
0
5
munang
Other than poor speed and performance, is there a reason why the map command is considered dangerous?The official doc...
by munang Path Finder in Splunk Search 09-02-2024
1 2
1
2
Siddharthnegi
Hi , I want to extract this line from an event.RAISE-ALARM:acProxyConnectionLost: [KOREASBC1] Proxy Set Alarm Proxy S...
by Siddharthnegi Contributor in Splunk Search 09-02-2024
0 5
0
5
VijaySrrie
Hi All,I am able to see only 4 status, why am I not able to see status=skipped and status = continued 
by VijaySrrie Builder in Splunk Search 09-02-2024
0 1
0
1
RSS_STT
I want to create one static field by looking status value = Issuehostm_nnamestatusAcpuOkBdiskOkCmemoryIssueDnetwokOkE...
by RSS_STT Explorer in Splunk Search 09-02-2024
0 7
0
7
dinesh001kumar
I would like to calculate the success rate of the Toup transaction via Channel( APP Or Web) in 4 API calls( E.g 4 Lev...
by dinesh001kumar Explorer in Splunk Search 09-02-2024
0 9
0
9
dinesh001kumar
 Hi All,Can anbody help us with the Regex expression to extract the feild of Channel: values will be either APP or We...
by dinesh001kumar Explorer in Splunk Search 09-01-2024
0 4
0
4
Thulasinathan_M
Hi Splunk Experts,I've been trying to group "WARN" logs, but they have a pattern (Dynamic/ Argument values) in them. ...
by Thulasinathan_M Contributor in Splunk Search 09-01-2024
0 2
0
2
thx
I  am trying to use a lookup of "known good" filenames that are within FTP transfer logs, to add extra data to files ...
by thx Explorer in Splunk Search 08-30-2024
0 2
0
2
Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...
Top Solution Authors