Splunk Search

Splunk Search
Community Activity
qbolbk59
Hi, I am trying to list all the events where a user has fired a DNS request to a specific domain mentioned in a look...
by qbolbk59 Path Finder in Splunk Search 02-04-2020
0 6
0
6
dickens8866
Dear All, I'm trying to retrieve and parse windows dns log, the sample looks like this: 1/23/2020 11:59:42 PM 0B50...
by dickens8866 New Member in Splunk Search 02-04-2020
0 1
0
1
thomaap
0
1
anooshac
Hi all I have a json file like this, { "NUM" : "#1", "TIME" : "1/27/2020 12:49:13", "STATUS" : "PASS", "DURATIO...
by anooshac Communicator in Splunk Search 02-03-2020
0 12
0
12
bowesmana
Splunk Cloud We have lookup data that needs to be accessed from Splunk Cloud. This data can either come from an ext...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2020
0 0
0
0
arun_kant_sharm
Hi Experts, I want to store alert search result and the following token in Lookup file app = $app$ description = $...
by arun_kant_sharm Path Finder in Splunk Search 02-03-2020
0 1
0
1
bolaojewale
I am using SSO and I want to be able to edit the error message you get when SSO authenticates, but the user account y...
by bolaojewale Explorer in Splunk Search 02-03-2020
0 0
0
0
sail4lot
I'm seeing lots of dispatch directory threshold errors. Is there an easy way to see what searches or reports are dri...
by sail4lot Path Finder in Splunk Search 02-03-2020
1 3
1
3
hollybross1219
I'ma beginner with Splunk hoping someone can help me with my syntax around the following query. I have queries with ...
by hollybross1219 Path Finder in Splunk Search 02-03-2020
0 2
0
2
annageorgiou
Hi. I'm new to splunk and trying to code a search for top 30 applications by bandwidth. So far I have the following c...
by annageorgiou New Member in Splunk Search 02-03-2020
0 5
0
5
drezanka
I have several types of metric data going into a metric index. One has 'username' and 'DimA' as dimensions, and 'Valu...
by drezanka Explorer in Splunk Search 02-03-2020
0 1
0
1
chris_barrett
Which of the following (in terms of the REGEX) is the most efficient? I've seen examples of all of them. And is th...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2020
0 4
0
4
brent_weaver
I need to ingest Proofpoint Campaign data and it seems that there is no canned TA/App for this. What have other done ...
by brent_weaver Builder in Splunk Search 02-03-2020
0 0
0
0
venkat0896
HI All i am creating a dashboard in SPLUNK .. i am trying capture the API counts and response time . here is a sampl...
by venkat0896 Path Finder in Splunk Search 02-03-2020
0 10
0
10
dspracklen
While there was a good question related to my problem, the answers aren't solving my problem. I need to constrain da...
by dspracklen Path Finder in Splunk Search 02-03-2020
1 5
1
5
shruthiangadi
Hi , I have a statistics table in which each column contains different value for eg: Application Name Application...
by shruthiangadi Explorer in Splunk Search 02-03-2020
0 4
0
4
damucka
Hello, I need to transform the table I have from: _time avg1 avg2 avg3 t1 v11 v21 v31 t2 v12 v2...
by damucka Builder in Splunk Search 02-03-2020
0 1
0
1
sahil237888
Hi, I have two fields with different values and I want count on both basis. These are events and hosts occured in lo...
by sahil237888 Path Finder in Splunk Search 02-03-2020
0 2
0
2
pdumblet
I have this search which shows the user sessions count by Country for the date range specified. I am trying to filte...
by pdumblet Explorer in Splunk Search 02-03-2020
1 2
1
2
nick405060
It looks like a join will break multivalues. And I thought mvexpand couldn't get any more dangerous or misleading tha...
by nick405060 Motivator in Splunk Search 02-02-2020
0 1
0
1
JonasLind
Hi, We are about to start up a new project where the project manager need to know the carbon footprint of the work d...
by JonasLind New Member in Splunk Search 02-01-2020
0 9
0
9
ylucena
Hello everyone, I am trying to put a table view together with no luck. The view is rather simple in theory but I can...
by ylucena Explorer in Splunk Search 01-31-2020
0 1
0
1
alexrieffel
Query 1: (sourcetype="PAYA:Enterprise:CDE:Web:App:Gateway.Bankcard" OR sourcetype="PAYA:Enterprise:CDE:Web:App:Gate...
by alexrieffel Observer in Splunk Search 01-31-2020
0 3
0
3
rijinc
Currently i am not familiar with REx and replace commands in splunk. Can someone help me here i want to replace to b...
by rijinc Explorer in Splunk Search 01-31-2020
0 9
0
9
petersonjared
Can someone please help me parse the field of FunctionArn for the account id value ( "65123456723" in the example) f...
by petersonjared Explorer in Splunk Search 01-31-2020
0 6
0
6
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors