Splunk Search

Splunk Search
Community Activity
papa
Hello Cam someone assist on how to do a search like below for multiple samaccountnames ? ideally from a txt file or C...
by papa Explorer in Splunk Search 10-02-2020
1 2
1
2
anikeshp7
Hi I want to create a report to display  time spent by user in a consoleBeing beginner doesnt know how to query .Any ...
by anikeshp7 Path Finder in Splunk Search 10-02-2020
1 19
1
19
mcaulsc
Hi,I have data that contains a field in binary that i can use a lookup table to map the various binary values to a va...
by mcaulsc Path Finder in Splunk Search 10-01-2020
1 4
1
4
Kaand
Hello Everyone,I am new to the splunk and this community. I have searched everyone for my problem but i could not fig...
by Kaand Explorer in Splunk Search 10-01-2020
1 2
1
2
ips_mandar
HiI have created below dummy sample data- |makeresults|eval a="1328,1345" |append[|makeresults| eval state="added", a...
by ips_mandar Builder in Splunk Search 10-01-2020
1 3
1
3
stevelfc
Hi, I'm trying this search and it seems to be working as i'm not getting anything outside the range.  The issue is I'...
by stevelfc Loves-to-Learn in Splunk Search 10-01-2020
0 2
0
2
irshtnak
{"line":{"log_type":"testlog","log_version":"1.0.0","service":"test","version":"1.0.0","timestamp":"2021-10-01T22:24:...
by irshtnak New Member in Splunk Search 10-01-2020
0 1
0
1
hpendela
I have a query that returns the following result. StatusCount200800404344002050012 And I would like to transform it t...
by hpendela New Member in Splunk Search 10-01-2020
0 1
0
1
cmahoney
I have a service that is 1 to many microservice so I am aggregating the backend calls into a single entry.    { "ti...
by cmahoney Loves-to-Learn in Splunk Search 10-01-2020
0 1
0
1
bowesmana
I have two Splunk servers and run the following command| makeresults | fields - _time | collect index=temp addtime=f ...
by SplunkTrust SplunkTrust in Splunk Search 10-01-2020
0 2
0
2
bjarnedein
Hi @gljiva   (and others),I'm situated in Scandinavia, where we no one uses the US way of showing numbers ie: "1,234,...
by bjarnedein Explorer in Splunk Search 10-01-2020
0 3
0
3
dsdeepak
Hi All,I am looking for splunk query to detect vertical and horizontal port scan in the Infra. Any help in this regar...
by dsdeepak Explorer in Splunk Search 10-01-2020
0 2
0
2
ellstream44
I use the following querysource="/opt/apps/spring-boot/abc/log/communication.log"| rex "\"correlation\" : \"(?P<corre...
by ellstream44 Explorer in Splunk Search 10-01-2020
0 5
0
5
Aps17
e.gQUERY 1: host=jtcstcxbsswb* source="/usr/IBM/HTTPServer/logs/access*" httpmethod="GET" statuscode="200" loaninfo="...
by Aps17 Explorer in Splunk Search 10-01-2020
0 1
0
1
rajkskumar
We are working on/ developing 4-5 Dashboards with around 10 Charts in each Dashboard. When we work on multiple Dashbo...
by rajkskumar Explorer in Splunk Search 10-01-2020
0 1
0
1
p3rf3ctst4r
Hello guys,I'm having issues solving this one. I have a generated datamodel of our network traffic (internal) and I n...
by p3rf3ctst4r Engager in Splunk Search 10-01-2020
0 2
0
2
cyberfan
we want to detect the multiple events together, for example, we want to find out those events which have event 4741 a...
by cyberfan Explorer in Splunk Search 09-30-2020
0 2
0
2
avanijjain16
Hi, I am new to splunk, I am trying to extract specific message from my log event. The pattern I am looking from belo...
by avanijjain16 Explorer in Splunk Search 09-30-2020
0 4
0
4
msplunk33
SPL query to get the ADHOC search or saved search (with user info) which consumed maximum memory and CPU for the past...
by msplunk33 Path Finder in Splunk Search 09-30-2020
0 2
0
2
SausagePizzza
Hello,Using the o365:management:activity logs, I'm trying to create a search where I:Get a list of users and their IP...
by SausagePizzza Engager in Splunk Search 09-30-2020
0 1
0
1
olivne
HiI have this table: customer | city A | NY B | NY A | LA and I want to replace the value in `cu...
by olivne Engager in Splunk Search 09-30-2020
0 1
0
1
help_me_pls
Hey,I have a splunk instance digesting nmap results. Each host that is found on the network generates an event that h...
by help_me_pls New Member in Splunk Search 09-30-2020
0 1
0
1
dglass0215
I have a csv lookup that has a column with numerical data (specifically integers).  When I do the lookup, splunk is t...
by dglass0215 Path Finder in Splunk Search 09-30-2020
0 1
0
1
rajkskumar
I have the following query used to build a chart. Sometimes, the incoming events do not have the fields set. How coul...
by rajkskumar Explorer in Splunk Search 09-30-2020
0 4
0
4
andrewcg
We recently upgraded to from 7.1.2 to 8.0.3 on on-prem Splunk Enterprise. A previously working saved search is no lo...
by andrewcg Path Finder in Splunk Search 09-30-2020
0 4
0
4
Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors