Splunk Search

Splunk Search
Community Activity
Memphis
Hi all - I am trying to create what I would think is a relatively simple conditional statement in Splunk. Use Case: I...
by Memphis Explorer in Splunk Search 06-20-2024
0 4
0
4
jrowland1230
I want to exact a string 'GUID" from the log right after "customers". This regex expression works in https://regex101...
by jrowland1230 Explorer in Splunk Search 06-20-2024
0 4
0
4
avikc100
this is the log data i want a report like this:  my current query is :index="webmethods_prd" source="/apps/WebMethods...
by avikc100 Path Finder in Splunk Search 06-20-2024
0 2
0
2
EricMonkeyKing
Hi community, can anyone help me figure out the log which Get incorrect data after Update(both get and update will lo...
by EricMonkeyKing Explorer in Splunk Search 06-20-2024
0 2
0
2
illuminatedaxis
My application is a backend web service. All events in a request contain the same value for a "req_id" field.I have a...
by illuminatedaxis Engager in Splunk Search 06-19-2024
0 2
0
2
akgmail
How to find difference of the time in days and hours respectively between Event time of the data and current time?For...
by akgmail Explorer in Splunk Search 06-19-2024
0 5
0
5
RonWonkers
Lets say we have the following data set:   Fruit_ID Fruit_1 Fruit_2 1 Apple NULL 2 Apple NULL 3 Apple NULL 4 Oran...
by RonWonkers Path Finder in Splunk Search 06-19-2024
0 4
0
4
KulvinderSingh
Hi All,Need some help with SPL query to compare the data from same host on 2 different dates and give me a status as ...
by KulvinderSingh Path Finder in Splunk Search 06-19-2024
0 1
0
1
cjoelly
Coming from SQL, I want to do stuff like GROUP BY and HAVING ...The data is available with a transaction identifier.G...
by cjoelly Loves-to-Learn in Splunk Search 06-18-2024
0 3
0
3
jsven7
| dedup _raw | where NOT MsgId=="AUT22673" OR MsgId=="AUT23574" OR MsgId=="AUT20915" OR MsgId=="AUT22886" What am I...
by jsven7 Communicator in Splunk Search 06-18-2024
1 9
1
9
jose_sepulveda
I need to filter a part of a log using regex, I have the following loglog: {dx.trace_id=xxxxx, dx.span_id=yyyyy, dx.t...
by jose_sepulveda Loves-to-Learn in Splunk Search 06-18-2024
0 6
0
6
sgtwolf1
Thank you everyone for taking the time to ready this. I am new in Splunk and interested in learning more. I have a pr...
by sgtwolf1 Explorer in Splunk Search 06-18-2024
0 1
0
1
Cmiddleton-oppd
Hello, my current search is  index=winsec source=WinEventLog:Security EventCode=6272 | eval date_hour = strftime(_ti...
by Cmiddleton-oppd Explorer in Splunk Search 06-18-2024
0 4
0
4
Silah
I asked in a previous thread for help to get response time based on time differential between two events connected by...
by Silah Path Finder in Splunk Search 06-18-2024
0 2
0
2
Woodpecker
Hi,I have a search as below. I want to find count of recipients by action where how many users received the email vs ...
by Woodpecker Path Finder in Splunk Search 06-18-2024
0 1
0
1
abhinav_go
Hello team ,I am trying to create macro and than use in my splunk dashboard . The purpose is to get time of entered i...
by abhinav_go Explorer in Splunk Search 06-18-2024
0 3
0
3
quadrant8
I've seen the documentation which says "by default subsearches return a maximum of 10,000 results and have a maximum ...
by quadrant8 New Member in Splunk Search 06-18-2024
0 1
0
1
Anushuba
Hi Team I have this requirement .Could you please help me on it .Here is my question I wanted to get result for Pa...
by Anushuba New Member in Splunk Search 06-18-2024
0 1
0
1
shashankk
Hello Team,I need assistance with joining 2 SPL queries to get the desired output. Refer the below log snippet:As per...
by shashankk Communicator in Splunk Search 06-17-2024
0 4
0
4
RahulMisra1
How i update the test_MID_IP.csv  with the output IP, so that next time it runs with updated listindex=abc IP!="10.*"...
by RahulMisra1 Explorer in Splunk Search 06-17-2024
0 3
0
3
heskez
Hi there,I am trying to get some data from MS Defender into a Splunk query. My original KQL query in azure contains |...
by heskez Engager in Splunk Search 06-17-2024
0 1
0
1
leykmekoo
Hello,  I have a lookup table where a list of MAC addresses are listed with the associated Vendors; basically an iden...
by leykmekoo Explorer in Splunk Search 06-17-2024
0 6
0
6
Sphere991
My logs output two consecutive lines in the case of a connection timeout: ... CONNECTION-x.x.x.x:y: connect() timeou...
by Sphere991 New Member in Splunk Search 06-17-2024
0 1
0
1
Ron1999
Hello,How can I get all the pod names with a query where the value will be in between 1.5 - 2.5. I can share a sample...
by Ron1999 New Member in Splunk Search 06-17-2024
0 1
0
1
Marmar
In the indexer, the search for data returns a timeline and details.The timeline is always green: This is fine for que...
by Marmar Observer in Splunk Search 06-16-2024
0 5
0
5
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors