Splunk Search

Splunk Search
Community Activity
AKG1_old1
Hello, Currently, we are using multiple datamodels for same data (post filters are different). Now we are trying to...
by AKG1_old1 Builder in Splunk Search 04-06-2020
0 0
0
0
jstillwell
How can I configure Splunk to extract some fields from the source filename. I already specify a host_regex and that...
by jstillwell Explorer in Splunk Search 04-05-2020
4 8
4
8
roukepouw
I tried to do the following in a dashboard: First declare two base searches, the second one using the first one: <s...
by roukepouw Explorer in Splunk Search 04-05-2020
1 7
1
7
Sukisen1981
I have a csv with just 2 columns Time & memory. the events look like this, so this is basically a csv extract of a se...
by Sukisen1981 Champion in Splunk Search 04-05-2020
0 6
0
6
palisetty
Hi @gcusello hope you are doing good, As far as I understand, m@d means, beginning of the day, and -45m@d means, 45 m...
by palisetty Communicator in Splunk Search 04-05-2020
0 2
0
2
petersamueljohn
I have a order data, I need to trend the order for last 15 days, plotting three values high, low and current in a sam...
by petersamueljohn New Member in Splunk Search 04-04-2020
0 2
0
2
arnavzz
I am trying to search on two indices. Both of them have a field which represents time. But in one index, that field i...
by arnavzz New Member in Splunk Search 04-04-2020
0 1
0
1
vrmandadi
I have events with GMT time .I want to convert to EST. Wed, 25 Mar 2020 21:43:31 GMT title="Webex Meetings: Users co...
by vrmandadi Builder in Splunk Search 04-04-2020
0 1
0
1
lsantacana
Hi, As part of my search, I'm building some strings with eval and assigning variable to it. I want to use these buil...
by lsantacana Engager in Splunk Search 04-04-2020
0 1
0
1
lbrhyne
We are attempting to write a report querying multiple indexes, which creates a table using data from each. Our challe...
by lbrhyne Path Finder in Splunk Search 04-04-2020
0 2
0
2
jdlocklin526
Hi Everyone, I have a query that produces table 1 below. | from inputlookup:"incident.csv" | where caused_by >= " "...
by jdlocklin526 Observer in Splunk Search 04-04-2020
0 2
0
2
alexman616
Hello! I am trying to search for multiple malware domains in our logs. I cant figure out how to add multiple domains ...
by alexman616 Engager in Splunk Search 04-03-2020
0 4
0
4
leandromatperei
Hello everyone, I have the attached file that is generated every night via my client's internal system and I need to...
by leandromatperei Path Finder in Splunk Search 04-03-2020
0 15
0
15
joshbeckett
I have some data that is being forwarded to another entity via our heavy forwarders and I am trying to monitor that s...
by joshbeckett Explorer in Splunk Search 04-03-2020
0 5
0
5
hollybross1219
hello! This is probably a simple answer that I'm not understanding. Running the query below will add a column at th...
by hollybross1219 Path Finder in Splunk Search 04-03-2020
0 1
0
1
dwibedi03
My index is getting refreshed every 15 mins and new data gets populated every 15 mins. I need to count the events fo...
by dwibedi03 Explorer in Splunk Search 04-03-2020
0 3
0
3
balash1979
Here is the message in splunk and I am trying to extract customer and channel {"line":"2020-04-03T12:24:54.589Z LCS...
by balash1979 Path Finder in Splunk Search 04-03-2020
0 4
0
4
mike000
I tried: index=_nix_xxxx sourcetype=df host=abdhw003 MountedOn="/doc" |eval source="/doc*" and that seems to show the...
by mike000 New Member in Splunk Search 04-03-2020
0 3
0
3
koocies
or do I have to run a whole new query?
by koocies Path Finder in Splunk Search 04-03-2020
0 3
0
3
zacksoft
I have a field serv_time = 44432 in miliseconds. and the default field _time. I want to be able to subtract _tim...
by zacksoft Contributor in Splunk Search 04-03-2020
0 3
0
3
briansarmiento
Hi everyone, I have found this search for GlobalProtect on PaloAlto Networks App, The information showed its really ...
by briansarmiento Explorer in Splunk Search 04-03-2020
0 0
0
0
andrewwjc
I'm using rangemap (mapped with field colors respectively) in chloropeth maps to sort the legend accordingly. However...
by andrewwjc Engager in Splunk Search 04-03-2020
0 0
0
0
canyin
Hi, I have a CSV file as lookup table which contains IP address and timestamp as fields. I need to perform a search ...
by canyin New Member in Splunk Search 04-03-2020
0 4
0
4
packland
I have a kvstore collection with two columns: "_key", and "last_online". The idea is that a search to update the valu...
by packland Path Finder in Splunk Search 04-03-2020
0 1
0
1
garciatdg
I am doing an experiment at home to capture Internet traffic for all of my devices in my house connected to my home w...
by garciatdg New Member in Splunk Search 04-03-2020
0 1
0
1
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors