Splunk Search

Splunk Search
Community Activity
vijaya5
Hi All, I am trying to use below regex in my splunk SPL, which is working fin in rubular but not working as SPL. |rex...
by vijaya5 Engager in Splunk Search 10-05-2020
0 3
0
3
cyberfan
Given free sample http stream data download from splunk website. I got two questions with start time, record time and...
by cyberfan Explorer in Splunk Search 10-05-2020
0 1
0
1
Aps17
Hello. I'm buliding a report where i want byte to be converted into seconds/millisecond.any idea how to do that sourc...
by Aps17 Explorer in Splunk Search 10-05-2020
1 5
1
5
binoy3012
Hello,I'm very new to splunk. I have a task to query an external bug system and display the results in splunk using a...
by binoy3012 Explorer in Splunk Search 10-05-2020
0 4
0
4
user2020dy
Hello, guysHave troubles with the output of lookup command.I know the right syntax of command:...| lookup <lookup-tab...
by user2020dy Path Finder in Splunk Search 10-05-2020
0 4
0
4
JTS911
Is there a heart beat from the HF I can monitor and if not detected, alert on it ? 
by JTS911 Explorer in Splunk Search 10-05-2020
0 2
0
2
unitrium
Hi,I would like to do a search that gives me the number of systems with a vulnerability per month.I've tried this sea...
by unitrium Explorer in Splunk Search 10-05-2020
0 4
0
4
nlisle
Hello, I currently have the below search will calculates on average how much time is being spent on the alerts that S...
by nlisle New Member in Splunk Search 10-05-2020
0 2
0
2
twinkleparmar
output should have result something like below:error       countabc         40xyz          50  
by twinkleparmar Loves-to-Learn in Splunk Search 10-05-2020
0 1
0
1
ormoush
Hi,I'm trying to split this event into anamevalueFieldAfalseFieldB5key-value table org.Data@28c839cfname=FieldA, valu...
by ormoush Engager in Splunk Search 10-05-2020
0 1
0
1
chanson
I am building a kiosk and before updating to 6.2 I was able to use the id and value tags for the web interface login....
by chanson Engager in Splunk Search 10-05-2020
1 5
1
5
cyberfan
we want to check any zero-logon exploit in the environment, is there splunk search available? how to detect malicious...
by cyberfan Explorer in Splunk Search 10-05-2020
0 4
0
4
user2020dy
Hello, guysI`m trying to extract URL field from my log in Data Model (it is not extracted from _raw log and is not se...
by user2020dy Path Finder in Splunk Search 10-05-2020
0 2
0
2
smruti13
Hi Splunk Gurus! I have come across an absurd issue where my eventstats is not recognizing the field value. Sample Pr...
by smruti13 Observer in Splunk Search 10-05-2020
0 1
0
1
Ashwini008
Hi,I have concatenated my DATE & TIME Field as below| eval DATE&TIME=DATE." ".TIMEEXAMPLE:(%m/%d/%Y  %H:%S)12/09/2017...
by Ashwini008 Builder in Splunk Search 10-05-2020
1 2
1
2
esmond
Hi,I am trying to produce a macro with an event summary that would contain both the field name and field value and a ...
by esmond Engager in Splunk Search 10-05-2020
0 2
0
2
tmarlette
I am attempting to search a field, for multiple values. this is the syntax I am using: < mysearch > field=value1,v...
by tmarlette Motivator in Splunk Search 10-04-2020
2 7
2
7
cyberfan
Hi, any one knows the benefits of search command?search src="10.9.165.*"  and src_ip="10.9.165.*" , any difference?
by cyberfan Explorer in Splunk Search 10-04-2020
1 2
1
2
venky10
Hi,  i am relatively newer to SPL, i have a usecase to evaluate time difference bwn two fields in two different logs ...
by venky10 Loves-to-Learn Everything in Splunk Search 10-04-2020
0 13
0
13
flck
Hi everyone,I hope someone can help me with the following situation.I have multiple events generated from Azure Devop...
by flck Path Finder in Splunk Search 10-03-2020
1 3
1
3
jonzatlmi
In events that we extract CID and JID from, I would like to have an output of all JID that interacted with multiple C...
by jonzatlmi Explorer in Splunk Search 10-03-2020
0 5
0
5
joemarty82
Hello, I am having problems approaching this problem. Say we have a KV store that stores asset information from a few...
by joemarty82 Explorer in Splunk Search 10-02-2020
0 0
0
0
shayhibah
Hey,I am trying to work with lookup table where input contains 3 fields (A,B,C) and output is DLookup table structure...
by shayhibah Path Finder in Splunk Search 10-02-2020
0 1
0
1
cyberfan
 any idea to write the query to capture the first packet recorded of the reconnaissance from the vulnerability scanne...
by cyberfan Explorer in Splunk Search 10-02-2020
0 1
0
1
yshen
On a heavy forwarder, I added a new sourcetype in /opt/splunk/etc/apps/<my_app>/local/props.conf, [sensor_data] DATET...
by yshen Communicator in Splunk Search 10-02-2020
0 2
0
2
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Solution Authors