Splunk Search

Splunk Search
Community Activity
becksyboy
HiI have a field name called report_name, it can have a number of status values associated with it, i.e. status=a or ...
by becksyboy Contributor in Splunk Search 11-10-2020
0 2
0
2
jboustead
I am looking to count the number of events that occur before and after a specified time (8am) each day to give a tabl...
by jboustead Explorer in Splunk Search 11-10-2020
0 1
0
1
kvnpichon
Hello Splunkers,I'm actually trying to extract the "flags" field in the DNS logs.Meanwhile, the TA provided by Splunk...
by kvnpichon Path Finder in Splunk Search 11-10-2020
0 2
0
2
ivan123357
Hello! I am new in Splunk Search.  I am using this query to find all hosts to which a specific update was installed:s...
by ivan123357 Explorer in Splunk Search 11-10-2020
0 6
0
6
splunker1981
Hello experts - I'm scratching my head trying to figure out if there's something at the low level configuration side ...
by splunker1981 Path Finder in Splunk Search 11-09-2020
0 1
0
1
jaibalaraman
Hi I am trying to extract field from the user agent details like ( Operating system, Software, Software version, Soft...
by jaibalaraman Path Finder in Splunk Search 11-09-2020
0 5
0
5
verifi81
Is there a way to tell which method a sourcetype is using to get data into splunk? For example, suppose I look at the...
by verifi81 Path Finder in Splunk Search 11-09-2020
0 2
0
2
ufotech
HiFor a given index with retention of 91 days configured, we find some hosts having events for the full 91 days.Some ...
by ufotech Explorer in Splunk Search 11-09-2020
0 3
0
3
jcleary47
We discovered that in early April, around the 7th, we had a HUGE increase in forwarders reporting this error: ERROR E...
by jcleary47 Path Finder in Splunk Search 11-09-2020
3 4
3
4
astackpole
I have a blacklist.csv file that looks like the following,namedescription*vpn*VPN was found.*putty*Putty was found. I...
by astackpole Path Finder in Splunk Search 11-09-2020
0 2
0
2
Fury
Hi there, I have a requirement where i need time duration between two events in ms.Events look like this Event A: Pro...
by Fury Loves-to-Learn Lots in Splunk Search 11-09-2020
0 10
0
10
bmacias84
Hello, I am trying to write a simple SPA using JS on the Search Head. I have a page where objects are generated dyn...
by bmacias84 Champion in Splunk Search 11-09-2020
0 2
0
2
mmccaugh9472
OK I have been reading most of the morning and I have to just be missing something very simple.To explain what I am t...
by mmccaugh9472 Observer in Splunk Search 11-09-2020
0 4
0
4
jacortijo
I am querying Nessus imported data and I would like to find old vulnerabilities still present today.More precisely, e...
by jacortijo Explorer in Splunk Search 11-09-2020
0 3
0
3
havatz
HiThere is any option to get a list of acceleration data model and what rules / reports / queries) using each of the ...
by havatz Explorer in Splunk Search 11-09-2020
0 1
0
1
gburtz
I want to be able to see the host name in search results rather than IP. In this case, the "host" I am looking for is...
by gburtz New Member in Splunk Search 11-09-2020
0 1
0
1
locobiker
Hello,  I am trying to do a search query using JSON.  It works if I use the normal form format, but not JSON.Working ...
by locobiker Loves-to-Learn in Splunk Search 11-09-2020
0 0
0
0
basics
Hi,This is the case scenario:when I run this search query:index = "global" productIDI get the following result:{ "pro...
by basics Explorer in Splunk Search 11-09-2020
0 3
0
3
pzhou07920
Hi, I currently have a query that returns the a chart of API's whose calls average over a specific time limit (uniqu...
by pzhou07920 Explorer in Splunk Search 11-09-2020
0 4
0
4
akarivaratharaj
We have a requirement to show the data growth of each index on a monthly basis. I tried with the below query from _in...
by akarivaratharaj Communicator in Splunk Search 11-09-2020
0 10
0
10
light_of_sirius
Hello, i have objects with names that all carry a unique and constant "Software-Signature" with them.This signature i...
by light_of_sirius Explorer in Splunk Search 11-09-2020
0 2
0
2
uagraw01
  As Per below screenshot, i getting results the difference between last week host and this week host count. But i wa...
by uagraw01 Motivator in Splunk Search 11-08-2020
0 2
0
2
jadengoho
Hi , Is it possible to get the search result from a specific app to my own application?Example:The result of the APP_...
by jadengoho Builder in Splunk Search 11-08-2020
0 2
0
2
ebs
I'm trying to extract multiple values for a single field. I've got the beginnings of the regex sorted to extract it, ...
by ebs Communicator in Splunk Search 11-08-2020
0 3
0
3
rtadams89
I have some firewall session state logs which get sent to Splunk every minute. The session state events contain a uni...
by rtadams89 Contributor in Splunk Search 11-08-2020
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...