Splunk Search

Splunk Search
Community Activity
fahimeh
Hello,As an admin, I deleted a user in Splunk Web, but when I try to add a user during an investigation, I still see ...
by fahimeh Explorer in Splunk Search 09-07-2024
0 3
0
3
Siddharthnegi
hello  I am getting a field port in event .ports="['22', '68', '6556']"how can i display them in separate rows.
by Siddharthnegi Contributor in Splunk Search 09-06-2024
0 2
0
2
woodcock
All 4 things use the $argument$ syntax. I am trying to use sendemail inside of a macro and have tried \$search\$, $$...
by Esteemed Legend in Splunk Search 09-06-2024
1 11
1
11
att35
Need some help in extracting Group Membership details from Windows Event Code 4627.As explained in this answer,https:...
by att35 Builder in Splunk Search 09-05-2024
0 2
0
2
cmiles416
I have an application to analyse phone call data from multiple locations. I want to generate a report that provides ...
by cmiles416 Explorer in Splunk Search 09-05-2024
2 5
2
5
ramuzzini
Hello, working on monitoring if someone has moved a file outside a specific folder inside a preset folder structure o...
by ramuzzini Path Finder in Splunk Search 09-05-2024
0 2
0
2
jgcsco
I have the following event that needs to calculate concurrency: Event, starttime=yyyy-mm-dd hh:mm:ss, duration=, sou...
by jgcsco Path Finder in Splunk Search 09-05-2024
1 14
1
14
wpb162
I am trying to delete users that just use Splunk authentication. I have the admin role. I have tried both the web GUI...
by wpb162 Explorer in Splunk Search 09-05-2024
0 9
0
9
jeck11
I'm missing something and it's probably blatantly obvious....I have a search returning a number but I want to have a ...
by jeck11 Path Finder in Splunk Search 09-05-2024
0 1
0
1
jbrenner
Let's say I have the following SPL query.  Ignore the regexes, thery're not important for the example:index=abc | rex...
by jbrenner Path Finder in Splunk Search 09-05-2024
0 3
0
3
nehamvinchankar
Hi all,I have one lookup which was having around 1000 entries recently someone has updated the lookup and all entries...
by nehamvinchankar Path Finder in Splunk Search 09-04-2024
0 5
0
5
BJanota29
I am currently working on creating an alert for a possible MFA fatigue attack from our Entra ID sign in logs. The log...
by BJanota29 New Member in Splunk Search 09-04-2024
0 1
0
1
andra_pietraru
My events have a few fields that are of the type: field_Name=failed What query should I write to get all that fields...
by andra_pietraru Path Finder in Splunk Search 09-04-2024
0 8
0
8
Satcom9
ACCU_DILAMZ9884 Failed, cueType=Splicer, SpliceEventID=0x00000BBC, SessionID=0x1A4D3100 SV event=454708529 spot=VAF00...
by Satcom9 Engager in Splunk Search 09-03-2024
0 2
0
2
tengugurl1
I have a standard printed statement that shows something like this:[29/Aug/2024:23:59:48 +0000] "GET /rest/LMNOP[29/A...
by tengugurl1 Engager in Splunk Search 09-03-2024
0 5
0
5
splunkn
Could anyone tell me the difference between outputlookup and outputcsv? If there no differences, is there any specif...
by splunkn Communicator in Splunk Search 09-03-2024
5 5
5
5
TheWiszard
Hi Guys, Has anyone done a search were you can monitor the CPU on the Fortinet Firewalls? Its on the App but doesn't ...
by TheWiszard Engager in Splunk Search 09-03-2024
0 3
0
3
elensare
I try to use lookup to specify span option value in bin command with map | inputlookup mylookupup.csv | fields Index,...
by elensare Engager in Splunk Search 09-03-2024
0 1
0
1
Siddharthnegi
hi i want to extract purple part.[Time:29-08@17:53:05.654] [60569222] 17:53:05.654 10.82.10.245 local3.notice [S=2952...
by Siddharthnegi Contributor in Splunk Search 09-03-2024
0 2
0
2
bwheelerice
The data coming into one of our indexers recently changed. Now the format is different, and the fields are different....
by bwheelerice Engager in Splunk Search 09-02-2024
0 8
0
8
tomjb94
Hi -  We have a requirement to join the below eval statement searches, would it be possible if someone could assist w...
by tomjb94 Observer in Splunk Search 09-02-2024
0 2
0
2
romanpro
 
by romanpro Explorer in Splunk Search 09-02-2024
0 3
0
3
dataisbeautiful
Hi AllI did a look around for a syntax definition for SPL in Notepad++ and didn't find one. Attached is my attempt. F...
by dataisbeautiful Communicator in Splunk Search 09-02-2024
3 0
3
0
user487596
Hello everyone! How can we solve the problem of searching for secrets in all or some splunk indexes so that splunk is...
by user487596 Explorer in Splunk Search 09-02-2024
0 5
0
5
munang
Other than poor speed and performance, is there a reason why the map command is considered dangerous?The official doc...
by munang Path Finder in Splunk Search 09-02-2024
1 2
1
2
Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...