Splunk Search

Splunk Search
Community Activity
brpsingara
Below is my code and I want to display only "Druv" Failed logins. But, I see the user name 'None' , 'Karla' and other...
by brpsingara Explorer in Splunk Search 02-25-2020
0 2
0
2
niks987
Hi All, Hope you all are doing good. I have to check 2 table from different sources and get a new table where its s...
by niks987 Explorer in Splunk Search 02-25-2020
0 2
0
2
sarit_s
Hello i have this configuration in transforms.conf: [adjust_flight_fields] INGEST_EVAL = flight_id=Designato...
by sarit_s Communicator in Splunk Search 02-24-2020
0 13
0
13
luck123813
Hello Everyone I am trying to see if i can pass an event field over to a lookup attached with a wildcard (reverse l...
by luck123813 Explorer in Splunk Search 02-24-2020
0 0
0
0
cglowjr
I am having trouble getting a result to appear for the below query. I am trying to produce a column showing time_dif...
by cglowjr New Member in Splunk Search 02-24-2020
0 4
0
4
sideview
Example: Say I have two lookups A and B. Let's say they're both file-based lookups (even though I don't think it act...
by SplunkTrust SplunkTrust in Splunk Search 02-24-2020
2 1
2
1
UMDTERPS
| inputlookup scanner_visibility.csv | lookup visibility_blue.csv Acronym AS application local=t OUTPUTNEW "Risk Scor...
by UMDTERPS Communicator in Splunk Search 02-24-2020
0 2
0
2
tomscott21
I am trying to create a search that gets the top value of a search and saves it to a variable: | eval top=[| eval MB...
by tomscott21 Engager in Splunk Search 02-24-2020
0 6
0
6
erinmichaud
I have ldap logs that give me events that look like this: Feb 21 13:13:22 ldap.foo.com slapd[28026]: conn=15306 fd=1...
by erinmichaud New Member in Splunk Search 02-24-2020
0 10
0
10
pench2k19
Hi Ninjas, I have following sample events in splunk. [02/18/2020 10:47:15.1318] CAUAJM_I_40245 EVENT: CHANGE_STATUS...
by pench2k19 Explorer in Splunk Search 02-24-2020
0 20
0
20
aknsun
Hi, I have events in the following format. It would either be a "Successful log in" or a "Unsuccessful login". I'm t...
by aknsun Path Finder in Splunk Search 02-24-2020
0 5
0
5
tomscott21
I am trying to save the top 1 value of a field from a search to a variable. I then want to use this value to input in...
by tomscott21 Engager in Splunk Search 02-24-2020
0 1
0
1
shubhamkanugo
I am new to splunk. I have a DB connection from where I am fetching a table. I want to create a dashboard for with x-...
by shubhamkanugo New Member in Splunk Search 02-24-2020
0 9
0
9
asabatini85
Hi all, I have a weird error on my splunk instance 7.3.0. I created a tag called application_web, if I try to use th...
by asabatini85 Path Finder in Splunk Search 02-24-2020
0 6
0
6
kredrm
Hi, status count ERROR 9346 PROCESSED 148066 PROCESSING 149571 I want to do the subtr...
by kredrm New Member in Splunk Search 02-24-2020
0 3
0
3
cblanton
I have a lookup table that shows all the next-level managers of a particular manager as UserManager UserManagerx1 Use...
by cblanton Communicator in Splunk Search 02-23-2020
1 14
1
14
kotig
I have something like below logged in as a message. How can i replace "This is my logfile ** ->" with empty and then...
by kotig Path Finder in Splunk Search 02-23-2020
0 6
0
6
jianyu75074
I have records have 2 fields: phone number result 1111 success 2222 success 2222...
by jianyu75074 New Member in Splunk Search 02-23-2020
0 3
0
3
dfurtaw
Inconsistency with file names coming from Microsoft AV hashes is causing alerts to populate null results when firing ...
by dfurtaw Path Finder in Splunk Search 02-23-2020
0 5
0
5
ericrenfro
I'm trying to get a blacklisted log entry that works on Universal Forwarders to filter out specific event codes with ...
by ericrenfro New Member in Splunk Search 02-23-2020
0 1
0
1
gaurav_ramteke
Hi, I want to use REGEX and FORMAT strings for an xml sample as given without using KV_MODE=xml So i am trying to us...
by gaurav_ramteke Explorer in Splunk Search 02-22-2020
0 14
0
14
jiaqya
I have 2 situations to address.. 1. if no data in index for timeframe , create a blank row with "no data" and come ou...
by jiaqya Builder in Splunk Search 02-22-2020
0 3
0
3
indeed_2000
How can I find most delay transactions? Here is the log file like below, I want to find which transaction delay and s...
by indeed_2000 Motivator in Splunk Search 02-22-2020
0 12
0
12
praddasg
So my below query gives the result of Rejection % but I need to also filter this one step more where it should not sh...
by praddasg Path Finder in Splunk Search 02-22-2020
0 15
0
15
mitag
(Apologies in advance since I am not even sure what question to ask and how to ask it. I'll rewrite it once I get a b...
by mitag Contributor in Splunk Search 02-21-2020
0 4
0
4
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Solution Authors