Splunk Search

Splunk Search
Community Activity
FC50
Hello,I'm pretty new to SPLUNK and I'm looking for help trying to find ASA open connections between two endpoints.Mos...
by FC50 Path Finder in Splunk Search 12-07-2020
0 4
0
4
rrovers
With this searchindex=useradmin sourcetype=role_capabilities| eval capabilities=replace(capabilities,"\s",",")| makem...
by rrovers Contributor in Splunk Search 12-07-2020
0 3
0
3
pck_npluyaud
Hello.It is not a question, it is a use case that I don't arrive to resolve.The situation :a log file on remote serve...
by pck_npluyaud Explorer in Splunk Search 12-07-2020
0 0
0
0
JMFrank215
I have the following search:index=aa sourcetype="bb" Service="/abc" OR Service="/mno" OR Service="/xyz" | chart count...
by JMFrank215 Explorer in Splunk Search 12-06-2020
0 8
0
8
pstalin_
index=105261-cli sourcetype=show_system_resources| dedup deviceId| eval nexus_percent_used=round(100*memory_used/memo...
by pstalin_ Engager in Splunk Search 12-06-2020
0 4
0
4
aking76
I have a search that runs with no issues-ComputerName=CompName* (event_simpleName=*written* OR event_simpleName=Direc...
by aking76 Path Finder in Splunk Search 12-06-2020
0 3
0
3
insatiableavi
Hi everyone,I have a data set such as:Log1:  EventId + EventType1Log 2: EventId + EventType2Log 3: EventId + EventTyp...
by insatiableavi Observer in Splunk Search 12-06-2020
0 3
0
3
Snehaan
Hello team,My search string is as below: index=qrp STAGE IN ("*_RAW", T_FEED_MESSAGES) | stats sum(TRADES) as "TradeC...
by Snehaan Explorer in Splunk Search 12-04-2020
0 1
0
1
jacortijo
Hi, I am getting crazy with a simply JOIN statement to use Tenable data in Splunk.The goal is to enrich the KV store ...
by jacortijo Explorer in Splunk Search 12-04-2020
0 1
0
1
Saikat001
I have  kv lookup table named bingo_kv_table. There are multiple rows having same hosts along with other hosts. I wan...
by Saikat001 Explorer in Splunk Search 12-04-2020
0 1
0
1
LegalPrime
I am trying to monitor for higher than threshold number of events per user. Alert is run once in an hour and I need t...
by LegalPrime Path Finder in Splunk Search 12-04-2020
0 2
0
2
Rody333
Hello,I want to search AD for all users in my organization. But as the list is huge, there is memory error occurring ...
by Rody333 New Member in Splunk Search 12-04-2020
0 0
0
0
leandromatperei
Hello everyone,I have the following pattern of logs and I'm trying to use rex to filter the values.I started doing it...
by leandromatperei Path Finder in Splunk Search 12-04-2020
0 1
0
1
Ephrem32
my field aliases are set like this:browser = BROWSERreferrer = REFERRERreq=REQreq_id=REQ=IDsrc=SRCDuring my search in...
by Ephrem32 Explorer in Splunk Search 12-04-2020
0 3
0
3
pacifikn
Hi All!I need your help !After checking that we're receiving logs into splunk mgt, I wanted to do Configuration in sp...
by pacifikn Communicator in Splunk Search 12-04-2020
0 2
0
2
kirrusk
i'm trying to convert values in column to fields names, But not able to achieve.table is like ENV       LABEL        ...
by kirrusk Communicator in Splunk Search 12-04-2020
0 5
0
5
akil8295
Hi All,I am trying to replace values which are already fields present in another field using rex and mode = sed. Exam...
by akil8295 New Member in Splunk Search 12-04-2020
0 1
0
1
cheriemilk
Hi team, I have created a dashboard with 8 panels, but it is running extremely extremely slow. how to improve the per...
by cheriemilk Path Finder in Splunk Search 12-03-2020
0 6
0
6
christianubeda
Hello team!I would like to ask you a question since I have been thinking about it for a while and I am not getting it...
by christianubeda Path Finder in Splunk Search 12-03-2020
1 2
1
2
johnward4
I'm looking for help to filter my mstats data using eventtype OR tag I've created for groups of hosts..Here's an exam...
by johnward4 Communicator in Splunk Search 12-03-2020
0 0
0
0
georgear7
I have below 3 different set of events coming from same source. So i have extracted the field using rex command for e...
by georgear7 Communicator in Splunk Search 12-03-2020
0 6
0
6
poisar
i have a field with several strings likefieldname = AT-field2-field3fieldname = DE-field2fieldname = DE-field2-field3...
by poisar Explorer in Splunk Search 12-03-2020
0 2
0
2
loocayak
Hi there, I am not sure if I am missing out the obvious but I would pretty much like to be able to run stats count of...
by loocayak Observer in Splunk Search 12-03-2020
0 1
0
1
Glasses
Hi,I am looking for a bit guidance  breaking out multi-kv pairs in json logs.For example, I have json email logs wher...
by Glasses Builder in Splunk Search 12-03-2020
0 2
0
2
roderick001
Hi, I have this error message and it is stopping any data being shown in data summary, I can't add any data as .zip o...
by roderick001 Explorer in Splunk Search 12-03-2020
0 6
0
6
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...