Splunk Search

Splunk Search
Community Activity
cku1
We are trying to use the CEF App, to create a new Output App to be deployed to our two indexers. However during the "...
by cku1 Engager in Splunk Search 06-02-2020
0 1
0
1
vmicovic2
Dear, couple hours i am trying to get: i have one log with no similar way of words in one line... because of that i ...
by vmicovic2 Explorer in Splunk Search 06-02-2020
0 17
0
17
thaara
Hi Splunkers, Please guide us on the requirement below: Input: server, env, req no, input field,status host-1,PROD,16...
by thaara Explorer in Splunk Search 06-02-2020
0 6
0
6
thaara
I have below 2 log files with 4 identical columns and in that, status is different: Status1.log host1,PROD,1666680,mo...
by thaara Explorer in Splunk Search 06-02-2020
1 11
1
11
tyleraball
Hey there, I'm trying to do two things and it looks like I can't. I have some fields with ugly names like "Current_Su...
by tyleraball Engager in Splunk Search 06-02-2020
5 9
5
9
manish_singh_77
Hi Team, Link to search on a new tab for raw events when we click on a particular value in the line chart? Is it po...
by manish_singh_77 Builder in Splunk Search 06-02-2020
0 8
0
8
msrama5
Hi All, I have the following query with 5 source types and 2 evals in one query, common field between source types i...
by msrama5 Explorer in Splunk Search 06-02-2020
0 1
0
1
ips_mandar
Hi below is my sample data- Date source State 29-05-20 01:00:00 abc ...
by ips_mandar Builder in Splunk Search 06-02-2020
0 4
0
4
pc1234
I'm requesting help constructing a regular expression for the following: I need to extract two values from the string...
by pc1234 Explorer in Splunk Search 06-02-2020
0 4
0
4
Becherer
When people RDP into a server, the results I am getting into splunk is Account_Name=Sever1$ Account_Name = jdoe. Whe...
by Becherer Explorer in Splunk Search 06-02-2020
0 1
0
1
vasugazula
I have a json structure that contains an object map: { "correlation_id": "f9535d13-f75b-4dd7-8c39-1e77b1559afe", ...
by vasugazula New Member in Splunk Search 06-01-2020
0 1
0
1
venkatachalamvi
My rawdata from log is below METHOD="POST" URI="CALLOUT-LOG" USER_ID_DERIVED="00532000004sefcAAA" EVENT_TYPE="ApexCa...
by venkatachalamvi New Member in Splunk Search 06-01-2020
0 2
0
2
joseftw
I have a index named Events Example events: AccountCreated { "AccountId": 1234, "EventName": "AccountCreated", ...
by joseftw Explorer in Splunk Search 06-01-2020
0 6
0
6
mishutts
Hi, Can someone please help me regex a password field to mask data? I've been trying to figure out how to mask the pa...
by mishutts Explorer in Splunk Search 06-01-2020
0 3
0
3
hrs2019
Hi all, I am not able to extract the below-given value from the JSON file fields are "initiator": test_abce, "re...
by hrs2019 Path Finder in Splunk Search 06-01-2020
0 2
0
2
tarini_r
I have my search query being as such where I am displaying the tickets, flowing in and out. Now, i want to put a line...
by tarini_r New Member in Splunk Search 06-01-2020
0 0
0
0
manan_amin
What if Same input is rescheduled and first one is still running.. option A -> First one stops, Second one Starts op...
by manan_amin Explorer in Splunk Search 06-01-2020
0 0
0
0
sudeep5689
I have a query in splunk index = * STATUS_CODE earliest=-2mon@mon latest=-1mon@mon | fields STATUS_CODE | rex field=_...
by sudeep5689 Explorer in Splunk Search 06-01-2020
0 1
0
1
sudeep5689
I have a query in splunk index = * STATUS_CODE earliest=-2mon@mon latest=-1mon@mon | fields STATUS_CODE | rex field=_...
by sudeep5689 Explorer in Splunk Search 06-01-2020
0 1
0
1
sarit_s
HelloI'm running this query: index=prod eventtype="csm-messages-dhcpd-lpf-eth0-listening" OR eventtype="csm-messages-...
by sarit_s Communicator in Splunk Search 06-01-2020
0 2
0
2
shivareddysompa
ComputerName Events Rank ABC 320 1 BCD 229 2 CDE 120 3 need to create rank Column based on ...
by shivareddysompa Explorer in Splunk Search 06-01-2020
0 5
0
5
surekhasplunk
index=ABC Check!=D | stats count by Device Check I am using this query and getting Device and Related Checks repor...
by surekhasplunk Communicator in Splunk Search 05-31-2020
0 1
0
1
pacifikn
Greetings!! how to create index of the new device data source in Splunk enterprise 7.2.6 in Linux? and how to create ...
by pacifikn Communicator in Splunk Search 05-30-2020
0 2
0
2
ezoteriusz
Hello, I need to query all last two http status for every page (extracted from URI) For example for this log: ip_addr...
by ezoteriusz Engager in Splunk Search 05-30-2020
0 1
0
1
nagar57
I want to apply different colors on different bars according to my Column values.My column values are: A,B,C. These w...
by nagar57 Communicator in Splunk Search 05-30-2020
0 4
0
4
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...