Splunk Search

Splunk Search
Community Activity
cyberfan
we want to check any zero-logon exploit in the environment, is there splunk search available? how to detect malicious...
by cyberfan Explorer in Splunk Search 10-05-2020
0 4
0
4
user2020dy
Hello, guysI`m trying to extract URL field from my log in Data Model (it is not extracted from _raw log and is not se...
by user2020dy Path Finder in Splunk Search 10-05-2020
0 2
0
2
smruti13
Hi Splunk Gurus! I have come across an absurd issue where my eventstats is not recognizing the field value. Sample Pr...
by smruti13 Observer in Splunk Search 10-05-2020
0 1
0
1
Ashwini008
Hi,I have concatenated my DATE & TIME Field as below| eval DATE&TIME=DATE." ".TIMEEXAMPLE:(%m/%d/%Y  %H:%S)12/09/2017...
by Ashwini008 Builder in Splunk Search 10-05-2020
1 2
1
2
esmond
Hi,I am trying to produce a macro with an event summary that would contain both the field name and field value and a ...
by esmond Engager in Splunk Search 10-05-2020
0 2
0
2
tmarlette
I am attempting to search a field, for multiple values. this is the syntax I am using: < mysearch > field=value1,v...
by tmarlette Motivator in Splunk Search 10-04-2020
2 7
2
7
cyberfan
Hi, any one knows the benefits of search command?search src="10.9.165.*"  and src_ip="10.9.165.*" , any difference?
by cyberfan Explorer in Splunk Search 10-04-2020
1 2
1
2
venky10
Hi,  i am relatively newer to SPL, i have a usecase to evaluate time difference bwn two fields in two different logs ...
by venky10 Loves-to-Learn Everything in Splunk Search 10-04-2020
0 13
0
13
flck
Hi everyone,I hope someone can help me with the following situation.I have multiple events generated from Azure Devop...
by flck Path Finder in Splunk Search 10-03-2020
1 3
1
3
jonzatlmi
In events that we extract CID and JID from, I would like to have an output of all JID that interacted with multiple C...
by jonzatlmi Explorer in Splunk Search 10-03-2020
0 5
0
5
joemarty82
Hello, I am having problems approaching this problem. Say we have a KV store that stores asset information from a few...
by joemarty82 Explorer in Splunk Search 10-02-2020
0 0
0
0
shayhibah
Hey,I am trying to work with lookup table where input contains 3 fields (A,B,C) and output is DLookup table structure...
by shayhibah Path Finder in Splunk Search 10-02-2020
0 1
0
1
cyberfan
 any idea to write the query to capture the first packet recorded of the reconnaissance from the vulnerability scanne...
by cyberfan Explorer in Splunk Search 10-02-2020
0 1
0
1
yshen
On a heavy forwarder, I added a new sourcetype in /opt/splunk/etc/apps/<my_app>/local/props.conf, [sensor_data] DATET...
by yshen Communicator in Splunk Search 10-02-2020
0 2
0
2
BrianAyala
I have a searchindex=foobar flashSteamName=foo/bar-moves/12adw320-df21-dasd-124d-12eda234 \displays 0 results. index=...
by BrianAyala Loves-to-Learn in Splunk Search 10-02-2020
0 2
0
2
rajnish1202
I am showing list of stopped services by host on a dashboard panel. I have 3 servers to show to show stopped services...
by rajnish1202 Explorer in Splunk Search 10-02-2020
0 13
0
13
venky10
Hi, i am relatively newer to splunk, looking for a solution to get time difference is a splunk sample log like this "...
by venky10 Loves-to-Learn Everything in Splunk Search 10-02-2020
0 1
0
1
cyberfan
For example, My ip is 202.101.53.4, I want to identify what are the domains sent me the most number of packets (most ...
by cyberfan Explorer in Splunk Search 10-02-2020
0 1
0
1
tcmarquesi
I'm wondering if somebody had faced this freaking behavior. I wanna extract both key, the field name, and its value ...
by tcmarquesi Explorer in Splunk Search 10-02-2020
0 16
0
16
pcnitk
Hi Team,We are currently extracting logs from Splunk via Splunk SDK based on index time. We have been seeing issues w...
by pcnitk New Member in Splunk Search 10-02-2020
0 1
0
1
sureshwalmart
Query: index=summary_estore_error_cust report=DelPassError userType=LoyalElite | rex field=raw "(UserId\W*(?\d+))" ...
by sureshwalmart Explorer in Splunk Search 10-02-2020
3 13
3
13
mah
Hi,I have a search which I want to optimise by replace the join command : index="AAA" sourcetype=BBB| stats count(OK)...
by mah Builder in Splunk Search 10-02-2020
0 4
0
4
papa
Hello Cam someone assist on how to do a search like below for multiple samaccountnames ? ideally from a txt file or C...
by papa Explorer in Splunk Search 10-02-2020
1 2
1
2
anikeshp7
Hi I want to create a report to display  time spent by user in a consoleBeing beginner doesnt know how to query .Any ...
by anikeshp7 Path Finder in Splunk Search 10-02-2020
1 19
1
19
mcaulsc
Hi,I have data that contains a field in binary that i can use a lookup table to map the various binary values to a va...
by mcaulsc Path Finder in Splunk Search 10-01-2020
1 4
1
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...