Splunk Search

Splunk Search
Community Activity
khaghsam
So I have a string of IPs that are input and trying to figure out how to add the location on them which are stated in...
by khaghsam New Member in Splunk Search 02-05-2020
0 4
0
4
niks987
Hi All, Hope you all are doing well. I was trying to setup email alert and event creation using Splunk and it was w...
by niks987 Explorer in Splunk Search 02-05-2020
0 6
0
6
aknsun
Need some suggestion for field extraction. Take this as an example: I have a file path /opt/splunk/var/log/splunk/s...
by aknsun Path Finder in Splunk Search 02-05-2020
0 2
0
2
rain979
I have this search: index=xxx sourcetype="yyy" earliest=01/27/2020:08:00:00 latest=01/27/2020:18:00:00 | timechart ...
by rain979 New Member in Splunk Search 02-05-2020
0 3
0
3
calebwidmer
We're writing Simple XML dashboards that utilize summary indexes for the aggregated data, but that is getting too big...
by calebwidmer Explorer in Splunk Search 02-04-2020
2 6
2
6
Mohsin123
Hi team, say i have a column like this : _time A 11pm 30 10pm 40 I have to subtract 40-30 and store in a new...
by Mohsin123 Path Finder in Splunk Search 02-04-2020
0 3
0
3
hrs2019
Hi All, How i can merge two row value in one field. i am trying with case but i am not getting the output.
by hrs2019 Path Finder in Splunk Search 02-04-2020
0 6
0
6
alpsplunkuser
I have a message that consists of key-value pairs: "status=BLOCKED, identifier=123422dsd13, userId=12344, name=John" ...
by alpsplunkuser Engager in Splunk Search 02-04-2020
0 3
0
3
jdanij
Because of reasons, I need to find a way to find every customized config parameter of an app placed in the local dir....
by jdanij Path Finder in Splunk Search 02-04-2020
0 1
0
1
itsmevic
Does anyone have any SPL that looks at ALL connected network devices? For example, John Doe decides he wants to conn...
by itsmevic Communicator in Splunk Search 02-04-2020
0 0
0
0
chirsf
I hope I explain this well. I have the following tstats search: | tstats max(_time) AS _time WHERE index=_internal s...
by chirsf Explorer in Splunk Search 02-04-2020
0 2
0
2
stephenreece
hi all . I am trying to create a map where I can look at users max duration between logins who register with us betw...
by stephenreece New Member in Splunk Search 02-04-2020
0 3
0
3
yuvarajvelu
How to display what values are missing in my lookup table comparing to actual data? Table.csv SERVER_A,DATA_A SERVER...
by yuvarajvelu New Member in Splunk Search 02-04-2020
0 4
0
4
MonkeyK
Lots of custom commands come with Splunk. 31 in the search app alone. I often see all of those commands and wonder...
by MonkeyK Builder in Splunk Search 02-04-2020
0 6
0
6
d942725
I have a use case where i need to pass the previously performed search query to replace the part of message with empt...
by d942725 New Member in Splunk Search 02-04-2020
0 11
0
11
satya2p
I am trying to pass number from subsearch to main search and find before or after 10 values of number. So if number ...
by satya2p Path Finder in Splunk Search 02-04-2020
0 2
0
2
grundsch
I'm trying to write a new custom search command, more specifically a reporting command. I'm using the Python SDK 1.6....
by grundsch Communicator in Splunk Search 02-04-2020
1 14
1
14
damucka
Hello, I need a help with counting the search results. I cannot use the following: | stats count as Total because...
by damucka Builder in Splunk Search 02-04-2020
0 2
0
2
scottrunyon
I am receiving Syslog data from the firewall and I would like to send a subset of it to the nullQueue. The issue I am...
by scottrunyon Contributor in Splunk Search 02-04-2020
0 3
0
3
D2SI
Hello there, I am trying to dynamically append the content of multiple lookup files but I am not sure it is possible...
by D2SI Communicator in Splunk Search 02-04-2020
0 5
0
5
qbolbk59
Hi, I am trying to list all the events where a user has fired a DNS request to a specific domain mentioned in a look...
by qbolbk59 Path Finder in Splunk Search 02-04-2020
0 6
0
6
dickens8866
Dear All, I'm trying to retrieve and parse windows dns log, the sample looks like this: 1/23/2020 11:59:42 PM 0B50...
by dickens8866 New Member in Splunk Search 02-04-2020
0 1
0
1
thomaap
0
1
anooshac
Hi all I have a json file like this, { "NUM" : "#1", "TIME" : "1/27/2020 12:49:13", "STATUS" : "PASS", "DURATIO...
by anooshac Communicator in Splunk Search 02-03-2020
0 12
0
12
bowesmana
Splunk Cloud We have lookup data that needs to be accessed from Splunk Cloud. This data can either come from an ext...
by SplunkTrust SplunkTrust in Splunk Search 02-03-2020
0 0
0
0
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...