Splunk Search

Splunk Search
Community Activity
BRFZ
Hello,While parsing the logs, I'm trying to extract fields, but at some point, I receive the following message "The e...
by BRFZ Communicator in Splunk Search 07-29-2024
0 17
0
17
Gauri
I want to display total transactions without where condition in result with other fields which has specific where con...
by Gauri Engager in Splunk Search 07-29-2024
0 6
0
6
Real_captain
HI  Can you please let me know how we can combine the outputs of multiple searches into a single field??  For example...
by Real_captain Path Finder in Splunk Search 07-29-2024
0 1
0
1
rajendar381
If I run the below code I am getting events in output json file , if I want to get statistics , is there any api avai...
by rajendar381 Loves-to-Learn Lots in Splunk Search 07-29-2024
0 0
0
0
kc_prane
My Raw log says "message: (c4328dd3-d16e-4df8-a8e6-b2ebcab9d8bc)" I wanted to extract everything  inside the  Parenth...
by kc_prane Communicator in Splunk Search 07-29-2024
0 2
0
2
bmanikya
I have two searches, one search will produce icinga problem alerts and other search will produce icinga recovery aler...
by bmanikya Loves-to-Learn Everything in Splunk Search 07-29-2024
0 18
0
18
thebhattman
I was wondering if there was a query to track flows through multiple firewallsFor example I want to track the flowsou...
by thebhattman New Member in Splunk Search 07-27-2024
0 1
0
1
ikoth
Hi,complete Splunk beginner here, so sorry it this is a stupid question.I'm trying to chart some data that I'm pullin...
by ikoth Explorer in Splunk Search 07-27-2024
0 4
0
4
CuriousSplunky
Hello,My Splunk query returns the marks of students in the below format. User                Subject                 ...
by CuriousSplunky Loves-to-Learn Lots in Splunk Search 07-27-2024
0 4
0
4
antoniolamonica
My org has millions of events coming in through firewalls.I had a 24 hour timeframe search take 12.5 hours to run. I ...
by SplunkTrust SplunkTrust in Splunk Search 07-26-2024
0 4
0
4
rangarbus
I have 3 separate queries. I need to run them one after the other. 1. First query returns a field from each event tha...
by rangarbus Path Finder in Splunk Search 07-26-2024
0 3
0
3
sumarri
So I have the fields that I want to subtract.  One is SequenceNumber_Comment (ex 211) and SequenceNumber_Withdrawal (...
by sumarri Path Finder in Splunk Search 07-26-2024
0 2
0
2
marco_massari11
Hello, I have to create a new correlation search looking for failed authentication to VPN. The rule should trigger if...
by marco_massari11 Communicator in Splunk Search 07-26-2024
0 2
0
2
rajendar381
Hi All , I am getting  the logs  from this query , But I need a query to get deviation of error count in two time per...
by rajendar381 Loves-to-Learn Lots in Splunk Search 07-26-2024
0 8
0
8
sintjm
I extracted 2 fields called 'Resp_time' and 'Req_time'...Both these fields are integers.I also changed the values to ...
by sintjm Path Finder in Splunk Search 07-26-2024
0 6
0
6
tjones130
Has anyone been able to figure out how to search indexed XmlWinEventLog sourcetype sample logs in the Ingest Action G...
by tjones130 Engager in Splunk Search 07-25-2024
1 3
1
3
kp_pl
My target is not only show proper percentiles but also count elements in every precentile . So the first step I did i...
by kp_pl Path Finder in Splunk Search 07-25-2024
0 3
0
3
Shahnoor
I have a number of events in 2 category (CAT A and CAT B). There are successful events and failed events with differe...
by Shahnoor Explorer in Splunk Search 07-25-2024
0 4
0
4
skoelpin
I extracted 2 fields called 'Request' and 'Response'...Both these fields are integers. How do I display the differe...
by SplunkTrust SplunkTrust in Splunk Search 07-25-2024
0 18
0
18
elend
I created a splunk dashboard that has a lot of filters (multiple dropdowns), and text input with different tokens, an...
by elend Communicator in Splunk Search 07-25-2024
0 3
0
3
RonWonkers
Hi, I have a field called "Employee_Email". This field contains the value: ["firstname.lastname@gmail.com"] How do I ...
by RonWonkers Path Finder in Splunk Search 07-25-2024
0 5
0
5
Bracha
  This is a line of code that takes the fields from the CSV file     |lookup xxx.csv id OUTPUTNEW system time_range  ...
by Bracha Path Finder in Splunk Search 07-24-2024
0 13
0
13
3litx
Hello, I'm so please to find this burgeoning community of professionals here.Please I can't do any search whatsoever ...
by 3litx Loves-to-Learn in Splunk Search 07-24-2024
0 1
0
1
scout29
I am trying to create a bar chart that shows the total daily splunk ingestion (in TB) by day for the past month. I am...
by scout29 Path Finder in Splunk Search 07-24-2024
0 4
0
4
Anud
How i can display the data sum of 2 fields like Last month same date data (example: 24 june and 24 may)I have tried t...
by Anud Path Finder in Splunk Search 07-24-2024
0 2
0
2
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors