Splunk Search

Splunk Search
Community Activity
khaghsam
So I have a string of IPs that are input and trying to figure out how to add the location on them which are stated in...
by khaghsam New Member in Splunk Search 02-05-2020
0 4
0
4
niks987
Hi All, Hope you all are doing well. I was trying to setup email alert and event creation using Splunk and it was w...
by niks987 Explorer in Splunk Search 02-05-2020
0 6
0
6
aknsun
Need some suggestion for field extraction. Take this as an example: I have a file path /opt/splunk/var/log/splunk/s...
by aknsun Path Finder in Splunk Search 02-05-2020
0 2
0
2
rain979
I have this search: index=xxx sourcetype="yyy" earliest=01/27/2020:08:00:00 latest=01/27/2020:18:00:00 | timechart ...
by rain979 New Member in Splunk Search 02-05-2020
0 3
0
3
calebwidmer
We're writing Simple XML dashboards that utilize summary indexes for the aggregated data, but that is getting too big...
by calebwidmer Explorer in Splunk Search 02-04-2020
2 6
2
6
Mohsin123
Hi team, say i have a column like this : _time A 11pm 30 10pm 40 I have to subtract 40-30 and store in a new...
by Mohsin123 Path Finder in Splunk Search 02-04-2020
0 3
0
3
hrs2019
Hi All, How i can merge two row value in one field. i am trying with case but i am not getting the output.
by hrs2019 Path Finder in Splunk Search 02-04-2020
0 6
0
6
alpsplunkuser
I have a message that consists of key-value pairs: "status=BLOCKED, identifier=123422dsd13, userId=12344, name=John" ...
by alpsplunkuser Engager in Splunk Search 02-04-2020
0 3
0
3
jdanij
Because of reasons, I need to find a way to find every customized config parameter of an app placed in the local dir....
by jdanij Path Finder in Splunk Search 02-04-2020
0 1
0
1
itsmevic
Does anyone have any SPL that looks at ALL connected network devices? For example, John Doe decides he wants to conn...
by itsmevic Communicator in Splunk Search 02-04-2020
0 0
0
0
chirsf
I hope I explain this well. I have the following tstats search: | tstats max(_time) AS _time WHERE index=_internal s...
by chirsf Explorer in Splunk Search 02-04-2020
0 2
0
2
stephenreece
hi all . I am trying to create a map where I can look at users max duration between logins who register with us betw...
by stephenreece New Member in Splunk Search 02-04-2020
0 3
0
3
yuvarajvelu
How to display what values are missing in my lookup table comparing to actual data? Table.csv SERVER_A,DATA_A SERVER...
by yuvarajvelu New Member in Splunk Search 02-04-2020
0 4
0
4
MonkeyK
Lots of custom commands come with Splunk. 31 in the search app alone. I often see all of those commands and wonder...
by MonkeyK Builder in Splunk Search 02-04-2020
0 6
0
6
d942725
I have a use case where i need to pass the previously performed search query to replace the part of message with empt...
by d942725 New Member in Splunk Search 02-04-2020
0 11
0
11
satya2p
I am trying to pass number from subsearch to main search and find before or after 10 values of number. So if number ...
by satya2p Path Finder in Splunk Search 02-04-2020
0 2
0
2
grundsch
I'm trying to write a new custom search command, more specifically a reporting command. I'm using the Python SDK 1.6....
by grundsch Communicator in Splunk Search 02-04-2020
1 14
1
14
damucka
Hello, I need a help with counting the search results. I cannot use the following: | stats count as Total because...
by damucka Builder in Splunk Search 02-04-2020
0 2
0
2
scottrunyon
I am receiving Syslog data from the firewall and I would like to send a subset of it to the nullQueue. The issue I am...
by scottrunyon Contributor in Splunk Search 02-04-2020
0 3
0
3
D2SI
Hello there, I am trying to dynamically append the content of multiple lookup files but I am not sure it is possible...
by D2SI Communicator in Splunk Search 02-04-2020
0 5
0
5
qbolbk59
Hi, I am trying to list all the events where a user has fired a DNS request to a specific domain mentioned in a look...
by qbolbk59 Path Finder in Splunk Search 02-04-2020
0 6
0
6
dickens8866
Dear All, I'm trying to retrieve and parse windows dns log, the sample looks like this: 1/23/2020 11:59:42 PM 0B50...
by dickens8866 New Member in Splunk Search 02-04-2020
0 1
0
1
thomaap
0
1
anooshac
Hi all I have a json file like this, { "NUM" : "#1", "TIME" : "1/27/2020 12:49:13", "STATUS" : "PASS", "DURATIO...
by anooshac Communicator in Splunk Search 02-03-2020
0 12
0
12
bowesmana
Splunk Cloud We have lookup data that needs to be accessed from Splunk Cloud. This data can either come from an ext...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2020
0 0
0
0
Get Updates on the Splunk Community!

Optimize AI at Scale: Must-Attend Observability Sessions at .conf26

conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help ...

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...