Splunk Search

Splunk Search
Community Activity
neelamsantosh
I want to exclude the (dst="10.0.0.0/8" OR dst="172.16.0.0/12" OR dst="192.168.0.0/16")  IP ranges.  my configuration...
by neelamsantosh Path Finder in Splunk Search 12-21-2020
0 3
0
3
Learner
Hi all, I am having data as follows: REPORT RequestId: xxxx2722-xx0d-xx35-95xx-xxxxxxb6b2e1 i want a field as Correla...
by Learner Path Finder in Splunk Search 12-20-2020
0 11
0
11
worldexplorer81
Hi, I have multiple files being delivered on a daily basis are in the below format:<filename>.<yyyymmdd>.xml - Exampl...
by worldexplorer81 Path Finder in Splunk Search 12-20-2020
0 1
0
1
dkolekar_splunk
The lookup table 'xxxxx_xxxx_xxxx' does not exist. It is referenced by configuration 'snow:change_request'. Add-on v...
by dkolekar_splunk Splunk Employee Splunk Employee in Splunk Search 12-20-2020
0 2
0
2
Gord1020
Hi All,I'm trying to figure out a way to setup a splunk alert to do the following...When the string "GFX_On" is found...
by Gord1020 Loves-to-Learn Lots in Splunk Search 12-19-2020
0 1
0
1
Maycockk
Hello fellow Splunk users,I understand it is possible to default in a single value in the event a lookup is not found...
by Maycockk Explorer in Splunk Search 12-19-2020
0 2
0
2
jrevolorio
Is there a way if I do a search for a username (ex. first_initial.lastname) under a specific index, that i can get a ...
by jrevolorio Explorer in Splunk Search 12-18-2020
0 1
0
1
fdevera
In splunk I have fully qualified sources and destinations. Example:src=host1.mydomain.comWhen I table it out I just w...
by fdevera Path Finder in Splunk Search 12-18-2020
0 2
0
2
jerm1020rq
I am receiving an error of "The expression is malformed. Expected IN." any time we search utilizing the web data mode...
by jerm1020rq Explorer in Splunk Search 12-18-2020
0 3
0
3
lmjoin115
Hello Team , i try to pass value of time token in dbxquery to update current time , it not working. Without it is wor...
by lmjoin115 Explorer in Splunk Search 12-18-2020
0 0
0
0
priyastalin
@dmarling Hi, I've replaced join in the below query and posted that query as well but I'm not getting proper output c...
by priyastalin Explorer in Splunk Search 12-18-2020
0 7
0
7
gozdeyildizz
Hi all,We are trying to calculate SLA from Jira logs in our Splunk. What we want to achieve to calculate the time bet...
by gozdeyildizz Engager in Splunk Search 12-18-2020
0 5
0
5
pgomezji
Hi, I have a lookup table with IP ranges and locations. The problem is in the IP range column there can be several IP...
by pgomezji Engager in Splunk Search 12-18-2020
0 2
0
2
djreschke
Good morning everyone, I have a source type that is showing the event time as 5 hours prior to indextime. I have trie...
by djreschke Communicator in Splunk Search 12-18-2020
0 1
0
1
djreschke
Good afternoon everyone, I am the Splunk admin for our instance of Splunk, and yesterday later in the afternoon, I no...
by djreschke Communicator in Splunk Search 12-18-2020
0 5
0
5
ezmo1982
Hi,I have the below search:| tstats values(Authentication.src_ip) as src_ip values(Authentication.src_host) as src_ho...
by ezmo1982 Path Finder in Splunk Search 12-18-2020
0 1
0
1
harsush
Hi Team,index=AA source=*XXX.log| rex field=_raw "- (?<uc>U(\d{7}|\d{8})) "| rex field=uc "(?<ul5>\d{5})$"| rex "[^\w...
by harsush Path Finder in Splunk Search 12-18-2020
0 4
0
4
bowesmana
I'm struggling with parsing this JSON. This query shows the part of a larger JSON element (response.rules). | makeres...
by SplunkTrust SplunkTrust in Splunk Search 12-17-2020
0 2
0
2
wtaylor149
I have a need to find a user(s) that have multiple infections over a 7 day period.  Example would be user1 has an inf...
by wtaylor149 Explorer in Splunk Search 12-17-2020
0 6
0
6
asukaka
教えてください。STARTとENDの時間範囲のあるCSVを作成し、その範囲内にあるイベントを数えたいのですが、どのようにクエリを書けばよいでしょうか<pre>started,completed2020/10/2 08:00,2020/...
by asukaka Engager in Splunk Search 12-17-2020
0 1
0
1
bsuresh1
Environment: Splunk Cloud I am running the below search with table command. The data which I am searching is very hu...
by bsuresh1 Path Finder in Splunk Search 12-17-2020
2 3
2
3
alancalvitti
This question: How to use IN function with VALUE-LIST as a search or lookup  discusses using IN for a single key and ...
by alancalvitti Path Finder in Splunk Search 12-17-2020
0 2
0
2
mcaulsc
I seem to have tied myself in a knot.I have data similar to:h1  h2   h3    h4a    12  123  231a    32  45    678b   4...
by mcaulsc Path Finder in Splunk Search 12-17-2020
0 5
0
5
binurajps
Below are my log entry DateTime=2020-12-16 14:19:01:888 UTC, Type=Orchestrator Event Log, Environment=prod, Thread=[P...
by binurajps Engager in Splunk Search 12-17-2020
0 4
0
4
anandhalagaras1
Hi Team,I have a logfile in which I have few keywords such as ORA-1 , ORA-212, ORA-609 and similarly we have more tha...
by anandhalagaras1 Contributor in Splunk Search 12-17-2020
0 7
0
7
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors