Splunk Search

Splunk Search
Community Activity
sgrierson
Hello community. I'm struggling to find emails that have a word in the subject which also have the word in an attach...
by sgrierson New Member in Splunk Search 09-08-2019
0 4
0
4
angersleek
I have the following query which gives me per second average results for the events. Is there a way I can modify it ...
by angersleek Path Finder in Splunk Search 09-08-2019
0 2
0
2
scott_sackrider
Rather than use 3rd party websites, we'd like to use Splunk to geolocate an address that may not yet be indexed. Sim...
by scott_sackrider Explorer in Splunk Search 09-08-2019
1 2
1
2
aalhabbash1
Hi Splunker; I have the below search: index=winevents host=prdaddc02 OR host=PRDADDC01 OR host=DZITHQ-DC3 sourcetyp...
by aalhabbash1 Path Finder in Splunk Search 09-07-2019
0 2
0
2
collinrice
I am getting an inconsistent number of events in a transaction, relative to the value specified for maxevents=x: | ...
by collinrice Explorer in Splunk Search 09-06-2019
0 0
0
0
AbubakarShahid
Hello All, I am trying to find the difference between first time and last time in epoch time. and i want the differ...
by AbubakarShahid New Member in Splunk Search 09-06-2019
0 2
0
2
vrmandadi
Hello I have the below sample events Thu Sep 5 10:00:02 EDT 2019 XDB EXPIRED & LOCKED ...
by vrmandadi Builder in Splunk Search 09-06-2019
0 5
0
5
bapun18
Can Please anyone help me in building the query for my alert so that It takes the index name and its corresponding th...
by bapun18 Communicator in Splunk Search 09-06-2019
0 3
0
3
a123537
So I have a search query which returns registrations for a website called CXI. See below: sourcetype=applog Successf...
by a123537 New Member in Splunk Search 09-06-2019
0 5
0
5
tcalvillo
Hello everyone, I'm a newbie and I did build my own dashboard in Splunk. I was able to create different charts and I...
by tcalvillo Engager in Splunk Search 09-06-2019
0 5
0
5
pratyushd
... |rename General.SetupViews as Modes|eval mode=split(Modes," ")|eval name1=mvindex(mode,0) | eval name2=mvindex(mo...
by pratyushd New Member in Splunk Search 09-06-2019
0 4
0
4
kteng2024
Hi, Whenever log into the splunk , i am getting " app not found" error . can i please know how to keep "searching an...
by kteng2024 Path Finder in Splunk Search 09-06-2019
0 4
0
4
Arpmjdr
Hi Splunkers, I have the events getting ingested as below: timestamp patch_version hostname Now,I want to crea...
by Arpmjdr Explorer in Splunk Search 09-06-2019
0 5
0
5
lsy9891
Hi I have this query that counts the number of errors for two applications but I get the application names from diff...
by lsy9891 Engager in Splunk Search 09-06-2019
0 1
0
1
salmanbpc
for example: dport=86 pattern: 0 tcp && dst port 86 && dst 345 here dport is field and pattern is non field value. i...
by salmanbpc New Member in Splunk Search 09-06-2019
0 1
0
1
jip31
hi In a first lookup (host.csv), I have a field "host" In a second lookup (toto.csv), I have also a field "host" Is ...
by jip31 Motivator in Splunk Search 09-06-2019
0 2
0
2
vasanthi77
can we run a search using the Splunk API to get back a single result(not streaming) without using a saved search or S...
by vasanthi77 Explorer in Splunk Search 09-06-2019
0 4
0
4
faribole
My search calculate the number of events of a field per hour per day. In my chart result I only want to see the max o...
by faribole Path Finder in Splunk Search 09-06-2019
0 2
0
2
jip31
hello I have done a saved search scheduled one time per day from the query below index=toto sourcetype="tutu" h...
by jip31 Motivator in Splunk Search 09-05-2019
0 4
0
4
psychogyiokosta
Hi, Using Splunk on a raw log file I get the total templates (clusters) of logs using something like: host="my_host...
by psychogyiokosta New Member in Splunk Search 09-05-2019
0 1
0
1
balash1979
Trying to parse the following line: newCount 20 OldCount 10 The following is my splunk query: index="server" | re...
by balash1979 Path Finder in Splunk Search 09-05-2019
0 1
0
1
dzejsonborn
Translating Qradar rules to SPL and stocked with setting thresholds 300 events are seen with the same Source IP and ...
by dzejsonborn New Member in Splunk Search 09-05-2019
0 3
0
3
johann2017
Hello. Has anyone built a detection for pass the hash? I have windows local event logs and AD logs at my disposal...
by johann2017 Explorer in Splunk Search 09-05-2019
1 2
1
2
maellebrown
Hi! I am looking for help for, I think, a simple statistic but I can't figure out how to do this simply. Here's an ...
by maellebrown New Member in Splunk Search 09-05-2019
0 7
0
7
jwalzerpitt
Can anyone recommend a way to search for file names based on entropy? I'd like to run a search that looks for funky/a...
by jwalzerpitt Influencer in Splunk Search 09-05-2019
0 0
0
0
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...
Top Solution Authors