Splunk Search

Splunk Search
Community Activity
marycordova
Problem: search: 1. Search: index=win* EventCode=4624 |userlookup(Account_Name)| table Account_Name name sam eid m...
by SplunkTrust SplunkTrust in Splunk Search 08-12-2024
1 7
1
7
juancarlos_pola
Hello. This is my third of fourth question in this page (I think) so I would like to beg you mercy if this issue/ques...
by juancarlos_pola Explorer in Splunk Search 08-09-2024
1 9
1
9
srivenna
I am trying to extract fields for this custom data but unable to parse the data| extract kv pairdelim="  " kvdelim=" ...
by srivenna Engager in Splunk Search 08-09-2024
0 1
0
1
vijreddy30
 Hi All,Httpevent collector logs in to splunk, not showing the host,source,sourcetype in splunk, please find the belo...
by vijreddy30 Loves-to-Learn Everything in Splunk Search 08-09-2024
0 1
0
1
Alnardo
[serversindex] Configuration initialization for /opt/splunk/var/run/searchpeers/serverhead-1721913866 took longer tha...
by Alnardo Engager in Splunk Search 08-08-2024
0 4
0
4
lemospt
Hi guys,   i have the following query that produces table below   index=core_ct_report_* | eval brand=case(like(repo...
by lemospt Explorer in Splunk Search 08-08-2024
0 1
0
1
Declan123
HI All,I am new to using Splunk. I am uploading a CSV to Splunk that has a column called 'Transaction Date' with the ...
by Declan123 Explorer in Splunk Search 08-08-2024
0 3
0
3
cadm777
We use Splunk, and I do know that our SystemOut logs are forwarded to the Splunk indexer. Does anyone have some examp...
by cadm777 Explorer in Splunk Search 08-08-2024
0 3
0
3
jcsvaldueza
I need to generate a report where it will output table with different timings in columns.Trick part is logs captured ...
by jcsvaldueza New Member in Splunk Search 08-08-2024
0 1
0
1
lorispiana
HI all,I just installed the security essential app on my splunk but i'm having issues retrieving the MITRE matrix.I g...
by lorispiana Loves-to-Learn in Splunk Search 08-08-2024
0 4
0
4
Nraj87
Is it possible to get each day first login event( EventCode=4634)  as "logon" and Last event of   (EventCode=4634) as...
by Nraj87 Explorer in Splunk Search 08-08-2024
0 1
0
1
super_edition
Hello Everyone,I have written the splunk query to remove last 2 character from the string:processingDuration = 102ms ...
by super_edition Path Finder in Splunk Search 08-08-2024
0 1
0
1
jjohn149
|union [ search index=osp source=xxx EVENT_TYPE=xxx EVENT_SUBTYPE=xxx field1=* field3=xxx field4="" | eval DATE = s...
by jjohn149 Observer in Splunk Search 08-07-2024
0 5
0
5
whitecat001
how can i troubleshoot when using a dashboard to export data, the data exported has numerous NULL values where there ...
by whitecat001 Explorer in Splunk Search 08-07-2024
0 1
0
1
mamagreen
Good morning!I am receiving the Error: Could not load lookup=LOOKUP-reply_code on multiple boxes.  Any similar situat...
by mamagreen Engager in Splunk Search 08-07-2024
0 1
0
1
ssuluguri
Hi Splunkers, My requirement is below . I have lookup where 7 hosts defined . when my search is running for both tsta...
by ssuluguri Path Finder in Splunk Search 08-07-2024
0 10
0
10
kmm2
I have a powershell script running get-brokersession which then exports the results to a txt file.   The file is then...
by kmm2 Path Finder in Splunk Search 08-07-2024
0 8
0
8
chimpui
Hi Splunkers!I wish to get data in a specific time range using earliest and latest command .I have checked with time ...
by chimpui New Member in Splunk Search 08-07-2024
0 4
0
4
RanjiRaje
Hi, Can anyone please help me to frame the SPL script.I have to collect the list of devices reporting in splunk along...
by RanjiRaje Explorer in Splunk Search 08-07-2024
0 7
0
7
PickleRick
Hi there.I'm relatively new to searching in Splunk so I can't sometimes get my head wrapped up around some Splunk con...
by SplunkTrust SplunkTrust in Splunk Search 08-07-2024
0 5
0
5
mekamundia
I find on splunkd.log a lot of warnings as: "Corrupt csv header, contains empty value (col #3)" without any other det...
by mekamundia Explorer in Splunk Search 08-06-2024
1 12
1
12
Bart
HI, I'm running a search for two different timeranges, for missing datapoint pair it's creating discrepancy with my c...
by Bart Explorer in Splunk Search 08-06-2024
0 2
0
2
JuanPerez
Hello friends, I am trying to create a heat map where I can see the indexes on the left side and in each cell of the ...
by JuanPerez New Member in Splunk Search 08-06-2024
0 2
0
2
Chirag812
Can we create a new field which contains the group of multiple servers name and that field I can use directly in all ...
by Chirag812 Explorer in Splunk Search 08-06-2024
0 2
0
2
cbiraris
Hi Teami am trying to make below field regex which is coming in every single event. but its not allowing me to use sa...
by cbiraris Path Finder in Splunk Search 08-06-2024
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors