Splunk Search

Splunk Search
Community Activity
nehamvinchankar
Hi all,I have one lookup which was having around 1000 entries recently someone has updated the lookup and all entries...
by nehamvinchankar Path Finder in Splunk Search 09-04-2024
0 5
0
5
BJanota29
I am currently working on creating an alert for a possible MFA fatigue attack from our Entra ID sign in logs. The log...
by BJanota29 New Member in Splunk Search 09-04-2024
0 1
0
1
andra_pietraru
My events have a few fields that are of the type: field_Name=failed What query should I write to get all that fields...
by andra_pietraru Path Finder in Splunk Search 09-04-2024
0 8
0
8
Satcom9
ACCU_DILAMZ9884 Failed, cueType=Splicer, SpliceEventID=0x00000BBC, SessionID=0x1A4D3100 SV event=454708529 spot=VAF00...
by Satcom9 Engager in Splunk Search 09-03-2024
0 2
0
2
tengugurl1
I have a standard printed statement that shows something like this:[29/Aug/2024:23:59:48 +0000] "GET /rest/LMNOP[29/A...
by tengugurl1 Engager in Splunk Search 09-03-2024
0 5
0
5
splunkn
Could anyone tell me the difference between outputlookup and outputcsv? If there no differences, is there any specif...
by splunkn Communicator in Splunk Search 09-03-2024
5 5
5
5
TheWiszard
Hi Guys, Has anyone done a search were you can monitor the CPU on the Fortinet Firewalls? Its on the App but doesn't ...
by TheWiszard Engager in Splunk Search 09-03-2024
0 3
0
3
elensare
I try to use lookup to specify span option value in bin command with map | inputlookup mylookupup.csv | fields Index,...
by elensare Engager in Splunk Search 09-03-2024
0 1
0
1
Siddharthnegi
hi i want to extract purple part.[Time:29-08@17:53:05.654] [60569222] 17:53:05.654 10.82.10.245 local3.notice [S=2952...
by Siddharthnegi Contributor in Splunk Search 09-03-2024
0 2
0
2
bwheelerice
The data coming into one of our indexers recently changed. Now the format is different, and the fields are different....
by bwheelerice Engager in Splunk Search 09-02-2024
0 8
0
8
tomjb94
Hi -  We have a requirement to join the below eval statement searches, would it be possible if someone could assist w...
by tomjb94 Observer in Splunk Search 09-02-2024
0 2
0
2
romanpro
 
by romanpro Explorer in Splunk Search 09-02-2024
0 3
0
3
dataisbeautiful
Hi AllI did a look around for a syntax definition for SPL in Notepad++ and didn't find one. Attached is my attempt. F...
by dataisbeautiful Communicator in Splunk Search 09-02-2024
3 0
3
0
user487596
Hello everyone! How can we solve the problem of searching for secrets in all or some splunk indexes so that splunk is...
by user487596 Explorer in Splunk Search 09-02-2024
0 5
0
5
munang
Other than poor speed and performance, is there a reason why the map command is considered dangerous?The official doc...
by munang Path Finder in Splunk Search 09-02-2024
1 2
1
2
Siddharthnegi
Hi , I want to extract this line from an event.RAISE-ALARM:acProxyConnectionLost: [KOREASBC1] Proxy Set Alarm Proxy S...
by Siddharthnegi Contributor in Splunk Search 09-02-2024
0 5
0
5
VijaySrrie
Hi All,I am able to see only 4 status, why am I not able to see status=skipped and status = continued 
by VijaySrrie Builder in Splunk Search 09-02-2024
0 1
0
1
RSS_STT
I want to create one static field by looking status value = Issuehostm_nnamestatusAcpuOkBdiskOkCmemoryIssueDnetwokOkE...
by RSS_STT Explorer in Splunk Search 09-02-2024
0 7
0
7
dinesh001kumar
I would like to calculate the success rate of the Toup transaction via Channel( APP Or Web) in 4 API calls( E.g 4 Lev...
by dinesh001kumar Explorer in Splunk Search 09-02-2024
0 9
0
9
dinesh001kumar
 Hi All,Can anbody help us with the Regex expression to extract the feild of Channel: values will be either APP or We...
by dinesh001kumar Explorer in Splunk Search 09-01-2024
0 4
0
4
Thulasinathan_M
Hi Splunk Experts,I've been trying to group "WARN" logs, but they have a pattern (Dynamic/ Argument values) in them. ...
by Thulasinathan_M Contributor in Splunk Search 09-01-2024
0 2
0
2
thx
I  am trying to use a lookup of "known good" filenames that are within FTP transfer logs, to add extra data to files ...
by thx Explorer in Splunk Search 08-30-2024
0 2
0
2
bcanfiel83
Hi All,I have a somewhat unusual requirement (at least to me) that I'm trying to figure out how to accomplish. In the...
by bcanfiel83 Engager in Splunk Search 08-30-2024
0 2
0
2
guldendraak
When defining a custom modular input in an app, it is possible to design a custom user interface for setting up the p...
by guldendraak Explorer in Splunk Search 08-30-2024
1 1
1
1
vijaynela
I am working Service now logs in Splunk. The tickets data has one field called "sys_created" this field gives the tic...
by vijaynela New Member in Splunk Search 08-30-2024
0 1
0
1
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...