Splunk Search

Splunk Search
Community Activity
mo_shahin
I am trying to visualize the deviation between a correlation rule's scheduled time and the time it was run. went thr...
by mo_shahin Engager in Splunk Search 12-07-2019
0 1
0
1
sendijsd
Hello, fellow Splunkers. I am currently trying to create a stacked timechart column using a simple search query: tim...
by sendijsd Engager in Splunk Search 12-07-2019
0 2
0
2
Beaker77
Hey there Splunkers! Similar to the question "How is the Size value on the job page calculated and logged in Splunk?...
by Beaker77 Explorer in Splunk Search 12-07-2019
0 3
0
3
sherrysafdar
I have an issue where events are indexed into multiple indexes partially. Now the problem is that Example: - Som...
by sherrysafdar Explorer in Splunk Search 12-07-2019
0 1
0
1
rcastello
Hello, I'm attempting to build a detailed table complete with timestamp, account name, eventcode, and host. We found...
by rcastello Explorer in Splunk Search 12-07-2019
0 1
0
1
kkuminsky
In the following Windows event log message field Account Name appears twice with different values. When I build a rep...
by kkuminsky Path Finder in Splunk Search 12-06-2019
3 12
3
12
landen99
When using NOT TERM, please keep in mind the following bug (see the answer for the workaround): index=myindex NOT TE...
by landen99 Motivator in Splunk Search 12-06-2019
0 5
0
5
kvanwagoner
I'm sure this will be easy for you guys but I"m struggling with it.. I need to modify this query to look for both the...
by kvanwagoner New Member in Splunk Search 12-06-2019
0 3
0
3
lucas4394
I wonder what the difference between last and max in timestamp if I want to return the most recent time from a lookup...
by lucas4394 Path Finder in Splunk Search 12-06-2019
0 2
0
2
unitedmarsupial
We have periodic events of the same kind and I want to count the time (duration) and the number of other events (even...
by unitedmarsupial Path Finder in Splunk Search 12-06-2019
0 3
0
3
Tylerdygert
Hello, I am running into an issue with some spath and mvexpand functions in splunk. I get the following error: "outp...
by Tylerdygert Path Finder in Splunk Search 12-06-2019
0 9
0
9
danielbb
The following works just fine - | makeresults | eval temp="IP-Group={xxxx} {yyyy} {zzz}" | rex field=temp max_...
by danielbb Motivator in Splunk Search 12-06-2019
0 3
0
3
bullbo
I have a search that displays new accounts created over the past 30 days and another that displays accounts deleted o...
by bullbo Engager in Splunk Search 12-06-2019
0 4
0
4
prettysunshinez
Hi, I have lookup file with the columns(fields) Name SubName. Now I wanted to run a query,which looks for the presen...
by prettysunshinez Explorer in Splunk Search 12-06-2019
0 4
0
4
pschildein
Hi, I have a large CSV lookup (~200MB and 6+ million lines). As I need the lookup information for eventtypes I tried...
by pschildein Explorer in Splunk Search 12-06-2019
1 0
1
0
rajeshjlnt
I am building a table query to list down tickets against applications. Where tickets are stored in sourcetype 'a' and...
by rajeshjlnt Path Finder in Splunk Search 12-06-2019
0 10
0
10
essibong1
Can any one help with a search language that could determine full disks and system logins after core hours?
by essibong1 New Member in Splunk Search 12-06-2019
0 1
0
1
arrowecssupport
This is my search I am trying to use in an event type so I can tag my events. index = mail | eval Subject=coalesce(S...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 6
0
6
arrowecssupport
I am running the search "index="os_var_log" | stats count" and getting this error after upgrading to Version 8 From v...
by arrowecssupport Communicator in Splunk Search 12-06-2019
0 0
0
0
gravi
Hi, I have nested json with Payload and the payload values are not consistent . First Format: { Activity: Logger...
by gravi Explorer in Splunk Search 12-06-2019
0 3
0
3
aswin_asok
i, One of my value in table is being passed as an Boolean expression as below (assignment_group = 1213App_Developmen...
by aswin_asok Explorer in Splunk Search 12-06-2019
0 0
0
0
user93
I want to search an exact phrase, but surronded by wildcards. I want to be able to do this with and without specifyin...
by user93 Communicator in Splunk Search 12-06-2019
0 2
0
2
rcastello
Hello, How can I compile a stats list of what servers a user account has logged into within a specific time period? ...
by rcastello Explorer in Splunk Search 12-05-2019
0 1
0
1
curlly88
I'm tasked with searching for all users that have been disabled in the last thirty days, these are employees no longe...
by curlly88 New Member in Splunk Search 12-05-2019
0 1
0
1
wu_weidong
I'm trying to check if the first occurrence of an event is today using the query below. However, I keep getting resul...
by wu_weidong Path Finder in Splunk Search 12-05-2019
0 1
0
1
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...