Splunk Search

Splunk Search
Community Activity
nc-mvw
I'm using Splunk for the first time, and I have an sql query giving the following output:2020-08-31 00:17:34.608, EMP...
by nc-mvw Engager in Splunk Search 09-01-2020
0 2
0
2
UnivLyon2
Hello,I've have an alert that returns by email suspicious login attempts in the form of a table with client_ip, numbe...
by UnivLyon2 Explorer in Splunk Search 09-01-2020
0 3
0
3
net1993
HelloI have the following regex from cisco asa add-on default transforms.conf:[cisco_source_ipv4]REGEX = \s+(?:from|f...
by net1993 Path Finder in Splunk Search 08-31-2020
0 2
0
2
ShagVT
I have a query trying to compare two different time periods, which I do with an inner search ( | append [search <iden...
by ShagVT Path Finder in Splunk Search 08-31-2020
0 9
0
9
willadams
I have a CSV that I am monitoring.  The CSV has lots of fields and my extraction works appropriately.  What I have no...
by willadams Contributor in Splunk Search 08-31-2020
0 1
0
1
rajyah
Hi, I have asked this question since we have forwarders that, for some reason, will not be able to upgrade to Win10 o...
by rajyah Communicator in Splunk Search 08-31-2020
0 1
0
1
rajyah
Hi,The screenshot presented below shows that there are 2 pairs that negates each other which should equal to 0 on col...
by rajyah Communicator in Splunk Search 08-31-2020
0 2
0
2
howyagoin
Been looking for a replacement for the GeoASN app that used to exist on Splunkbase for a while, and the TA-asngen (ht...
by howyagoin Contributor in Splunk Search 08-31-2020
0 2
0
2
lucas4394
According to Splunk document in "tstats" command, the optional argument, fillnull_value, is available for my Splunk v...
by lucas4394 Path Finder in Splunk Search 08-31-2020
0 2
0
2
VS0909
I am looking to trigger an alert in splunk if a new error is there in server logs. New error is an error/s that was n...
by VS0909 Communicator in Splunk Search 08-31-2020
0 9
0
9
obularajud16
With the below query I am able to get data as below(first one) and I need to convert it as second box For the time fi...
by obularajud16 Explorer in Splunk Search 08-31-2020
0 2
0
2
amoulkaf
Hello, Each event represents a user state and every user has rank. data look as follow : timerankusertime1302time1501...
by amoulkaf Engager in Splunk Search 08-31-2020
0 3
0
3
macd0170
I appologize if this has been asked and answered.  I tried searching the forum but couldn't find the answer (if might...
by macd0170 New Member in Splunk Search 08-31-2020
0 6
0
6
pavanmishra0102
(Item Id: 45) Container Name: Abc Admin Accounts (Container Id: 19) suid=1 need to extract Container name & Container...
by pavanmishra0102 Engager in Splunk Search 08-31-2020
0 2
0
2
thampton
Hello all,I have two search strings that pull information - one pulls all the blocked emails and the second pulls the...
by thampton New Member in Splunk Search 08-31-2020
0 1
0
1
reinoheinanen
Hello I'm trying t run the following search: Using subsearch I collect from DNS logs the source IP address and the d...
by reinoheinanen Explorer in Splunk Search 08-31-2020
0 4
0
4
VS0909
Need help with Splunk query to identify an anomaly for increase in frequency of errors in logs. Historic data to comp...
by VS0909 Communicator in Splunk Search 08-31-2020
0 3
0
3
AK007
Hi, Want to find universal forwarders and to which index they are sending data to ?We have cmd to list all the UF. Ne...
by AK007 Engager in Splunk Search 08-31-2020
0 2
0
2
iamlucky92
Hi Team,I am having a logging with double pipe separator (||)  and need to get the key values from logs. Log pattern:...
by iamlucky92 Observer in Splunk Search 08-31-2020
0 1
0
1
Samiksha1008
I have below command in Linux -grep "login?" access.log access.log.1 | grep https | cut -d, -f3 | sed 's/"wafip"://g'...
by Samiksha1008 Observer in Splunk Search 08-31-2020
0 3
0
3
Stephen11
To all:Still learning about REGEX ...  I looked at RUBULAR.COM and REFEX101.com to figure out how to pull out the Use...
by Stephen11 Explorer in Splunk Search 08-30-2020
0 2
0
2
Cstone1
I've got tons and tons of logs.What I want is login durations from the wineventlogs by usernames. Each event has the ...
by Cstone1 Engager in Splunk Search 08-30-2020
0 2
0
2
venkatsm
I would like to get the errors by class/exception/ExceptionMessage field (java based application errors) by week over...
by venkatsm New Member in Splunk Search 08-30-2020
0 4
0
4
mahe90
Hi, My CSV(test_csv_lookup) looks like this: ---index; value1, 1.1.1.1---- here is my automatic lookup LOOKUP-field_e...
by mahe90 Explorer in Splunk Search 08-30-2020
0 1
0
1
obularajud16
  Ghjsourcetype=access_combined | eval action = if(isnull(action) OR action="", "Unknown", action) | timechart span=4...
by obularajud16 Explorer in Splunk Search 08-29-2020
0 5
0
5
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...