| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hello all, 
  I am attempting to put together a search where I'm taking website status (200=allowed, etc) and breakin...
        
       
         
           by 
           
                
                    
                        BB34
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hi! i've been trying to regex some part of the windows events to save license. Many windows events contains a large p...
        
       
         
           by 
           
                
                    
                        dieguiariel
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-04-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  9
	 
 | |||
| 
      
        I'm trying to get the average time that a case is open in a system.
  To get the latest event per case that's closed ...
        
       
         
           by 
           
                
                    
                        benhooper
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-10-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  13
	 
 | |||
| 
      
        This is my query and I have some challenges in the log. The thing is my daily job will start at 11 PM. If the job run...
        
       
         
           by 
           
                
                    
                        karthi2809
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Search
           
           
              
               08-10-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Hi, 
  I have a lookup tables with user names (ftp_users.csv).
  Every day I'm getting one line from a particular sys...
        
       
         
           by 
           
                
                    
                        yossefn
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Hey Guys,
  I am struggling arround a few days now, but I cant find a good/efficient solution for my problem.
  I wan...
        
       
         
           by 
           
                
                    
                        sarausch
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-08-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I have written a rule that is trying to use a transaction and based on the transaction value to either alert or not. ...
        
       
         
           by 
           
                
                    
                        willadams
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Search
           
           
              
               08-09-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi
  In the search below, I would be able to change the background color following the value of the FreeSpace field
 ...
        
       
         
           by 
           
                
                    
                        jip31
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Search
           
           
              
               07-26-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  9
	 
 | |||
| 
      
        If suppose i have two Phases with first and last datePhase 1=1 JAN 2020, 1 March 2020
  Phase2=1Apr 2020,1jun 2020
  ...
        
       
         
           by 
           
                
                    
                        renuka
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-05-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        Splukers, 
  I want to calculate uptime for my network. By this I mean, I need uptime in hours like time diffrence be...
        
       
         
           by 
           
                
                    
                        amandeepsingh
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-03-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  6
	 
 | |||
| 
      
        Can some one please help me to change the background color of Table fieldname.
  By default I am getting the fieldnam...
        
       
         
           by 
           
                
                    
                        skodak
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-08-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        This is probably a really simple question but I have events coming in every minute.
  I've used  | rex field=_raw ......
        
       
         
           by 
           
                
                    
                        tbrown
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I've created a text form input called 'username' to search for usernames in my dashboard panels and i've set the toke...
        
       
         
           by 
           
                
                    
                        rkris
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-03-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello,
   
  I have json data and I am trying to search a specific field using a dynamic variable. I can properly sea...
        
       
         
           by 
           
                
                    
                        joemarty82
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        I have uploaded the log file containing the backdoor information above into splunk but i'm not sure how to create a s...
        
       
         
           by 
           
                
                    
                        rkris
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-08-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        I've created a dropdown field for New User Accounts Created(Failed Attempts)
  
   
   
  And this is the search quer...
        
       
         
           by 
           
                
                    
                        rkris
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-08-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
         
  
   
   
   
  I have uploaded the log file containing the virus information above into splunk but i'm not sure h...
        
       
         
           by 
           
                
                    
                        rkris
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-08-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi,
  I have several log files that I´m "batch indexing".
  for example:
   
  
   file01.log file02.log file03.log f...
        
       
         
           by 
           
                
                    
                        chrkohm
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I have a very simple search:
  index=logs_glbl sourcetype=kube:container:app-name namespace=prod status=500 | stats c...
        
       
         
           by 
           
                
                    
                        noman377
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have syslogs from our load balancer which has 4 servers on it.
  When one of the servers states changes from UP to ...
        
       
         
           by 
           
                
                    
                        cbwillh
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  9
	 
 | |||
| 
      
        I have got a query like this
   
  index=* request in (request1, request2, request3)
  eval  request&& = request1 + r...
        
       
         
           by 
           
                
                    
                        skodak
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi there, 
   
   
     
   
  
  
   
    
     
      
       I have just started using Splunk and it is quite alie...
        
       
         
           by 
           
                
                    
                        Matthew86
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        HI all,
  I have 2 index, that have same common field together.  I want to join both together.
  Query 1: 
   
   
  ...
        
       
         
           by 
           
                
                    
                        jerinvarghese
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I am having a problem with what i believe is writing a regex to clean up some events before i report on them in dashb...
        
       
         
           by 
           
                
                    
                        ghostdog920
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Search
           
           
              
               08-07-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Hello,
  I'm trying to analyze an A/B test results on access pattern changes for a specific field.
  Simplified query...
        
       
         
           by 
           
                
                    
                        izx
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Search
           
           
              
               08-06-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 |