Splunk Search

Splunk Search
Community Activity
pacifikn
Greetings!! I have created a new lookup table xyz.csv that contain host and hostname(as description) and the name of...
by pacifikn Communicator in Splunk Search 12-11-2019
0 4
0
4
hsuparta
We are currently facing Single Sign-On issues - getting the following error. IDP failed to authneticate request. Sta...
by hsuparta New Member in Splunk Search 12-11-2019
0 3
0
3
matoulas
Why am I getting difference result from two search type This is the correct result as expected This is incorrect ...
by matoulas Path Finder in Splunk Search 12-11-2019
0 0
0
0
HattrickNZ
I have the below very simple dashboard for illustration. (assume a chart would be in row 2 and row 3) My question is,...
by HattrickNZ Motivator in Splunk Search 12-11-2019
1 7
1
7
alancalvitti
I'd like to (1) use a subquery to extract a list of deviceId's then (2) search the same index for all events containi...
by alancalvitti Path Finder in Splunk Search 12-11-2019
0 4
0
4
rvalley
I am searching for AD accounts that are created and deleted in a short period, but we have a multiple forest environm...
by rvalley New Member in Splunk Search 12-11-2019
0 5
0
5
satyenshah
Edit 2019-11-28: Splunk has released a better fix-it app than the one below. Edit 2019-11-25: I didn't notice the mo...
by satyenshah Path Finder in Splunk Search 12-11-2019
2 9
2
9
clintla
trying to calculate groupings of VMs capacity growth over time but a chart or table looks to be the best answer if yo...
by clintla Contributor in Splunk Search 12-11-2019
0 23
0
23
essibong1
Hello, I had requested for anyone to provide me with a good search to monitor after hour employee login and I was pro...
by essibong1 New Member in Splunk Search 12-11-2019
0 1
0
1
essibong1
Hello, I had requested help with a "search language that could determine system logins after core hours" and one of t...
by essibong1 New Member in Splunk Search 12-11-2019
0 3
0
3
gtidd
I know I am missing something simple here, but I cannot seem to figure this out. I am trying to search my logs for t...
by gtidd Explorer in Splunk Search 12-11-2019
0 5
0
5
indeed_2000
I have log file like this: A[1020/09/09] B[1013/09/09] C[05-07-00000000-000-A-B-C] want to extract field of A, B, ...
by indeed_2000 Motivator in Splunk Search 12-11-2019
0 5
0
5
spluzer
hello all, I have a lookup with two fields sourcetype and interval ( like below) ..some of the intervals are in seco...
by spluzer Communicator in Splunk Search 12-11-2019
0 4
0
4
woodcock
I get asked some form of this question often and I know what my answer is but I am curious about others. What is you...
by Esteemed Legend in Splunk Search 12-11-2019
1 8
1
8
jospina2
Hello, I am trying to use transforms/props to filter a service from being indexed This is what I have: /etc/system...
by jospina2 Explorer in Splunk Search 12-11-2019
1 2
1
2
pacifikn
How to download existing lookup file? and how to add new row and modify existing lookup file table?
by pacifikn Communicator in Splunk Search 12-11-2019
1 2
1
2
sheikhazad
Hello, My following search results records for Account: index="X" AND (sourcetype="A:Proxy" OR sourcetype="A:orderpu...
by sheikhazad New Member in Splunk Search 12-11-2019
0 13
0
13
idzjuba
Hi, I need to group events where the first event begins with "Receive message" and grouped by thread id. But then nee...
by idzjuba Engager in Splunk Search 12-11-2019
0 4
0
4
niks987
Hi All, Hope you all are doing good. I am stuck with 2 questions may be due to my Splunk query knowledge, hope you ...
by niks987 Explorer in Splunk Search 12-11-2019
0 0
0
0
whitewolf332512
When I run the below search I can see 94 indexes available. | eventcount summarize=false index=* index=_*| dedup ind...
by whitewolf332512 New Member in Splunk Search 12-10-2019
0 3
0
3
Nadhiya_Dubai
/data/scripts/esx/output_crc/dc1-ch1-esxi05.dca.com-vmnic0-20191211-10:40:40.txt I need to extract the field "dc1-ch...
by Nadhiya_Dubai Explorer in Splunk Search 12-10-2019
0 1
0
1
Nadhiya_Dubai
/data/scripts/esx/outfile/dc1-ch1-esxi05.dca.com-vmnic0.txt I need to extract the dc1-ch1-esxi05.dca.com-vmnic0 fro...
by Nadhiya_Dubai Explorer in Splunk Search 12-10-2019
0 3
0
3
matoulas
How do I change a bar chart color base on the syslog severity level. Example: Informational to blue color, warning to...
by matoulas Path Finder in Splunk Search 12-10-2019
0 4
0
4
wti
Hello, I have a timechart search (search code snippet below), everything works great. The chart shows up and the le...
by wti Engager in Splunk Search 12-10-2019
0 1
0
1
rhugo
From the screenshot, i would like to achieve the below; LCU04 = 500 x 00000 LCU03 = 500 x 01985 LCU02 = 500 x 01985 ...
by rhugo Observer in Splunk Search 12-10-2019
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors