Splunk Search

Splunk Search
Community Activity
cyber_castle
For one of the Security usecase, we need to extract Group Memberships from the Domain. The trickier part is some of ...
by cyber_castle Path Finder in Splunk Search 09-04-2019
0 5
0
5
sandeepmakkena
Here is the sample log I want a timechart. {"dtm":"2019-09-04 07:17:39.129 PDT", "logger":".WEB_ORDER_RELEASE", "app...
by sandeepmakkena Contributor in Splunk Search 09-04-2019
0 3
0
3
jaxjohnny2000
Just to be sure, does the admin password need to be the same for each component in the Search Head or Index Cluster?
by jaxjohnny2000 Builder in Splunk Search 09-04-2019
0 5
0
5
bapun18
I have an inputlookup which have 2 fields index and count, I need to create an alert so that alert will trigger when ...
by bapun18 Communicator in Splunk Search 09-04-2019
0 1
0
1
yasein
I have logs like msg="some string here method=aaaa" method=bbbb splunk may extract method=aaaa out of the quoted st...
by yasein Engager in Splunk Search 09-04-2019
0 3
0
3
ips_mandar
I am extracting one field at index time from source field using regex and while searching field value sometime I am u...
by ips_mandar Builder in Splunk Search 09-04-2019
0 2
0
2
russell120
Hi, I have a sample CSV called original.csv. Each day, a search is ran and saved to new.csv. What search to do I need...
by russell120 Communicator in Splunk Search 09-04-2019
0 3
0
3
dzejsonborn
Hi Guys, Can you please tell me how to exclude/whitelist multiple ip adresses from the datamodel search here is the...
by dzejsonborn New Member in Splunk Search 09-04-2019
0 6
0
6
pavanae
The following is the regex I am working on and what I'm trying to do is exclude any username events that ends with "Z...
by pavanae Builder in Splunk Search 09-04-2019
0 2
0
2
abhijitd
index=app sourcetype=accesslog uri="some uri" user!="-" (context="display" OR context="pages") earliest=-7d | rex fi...
by abhijitd New Member in Splunk Search 09-04-2019
0 2
0
2
moonyoungjung
Same SPL result is different by user A and admin SPL-> index=xxx when I do search with userA's userid "interestin...
by moonyoungjung New Member in Splunk Search 09-04-2019
0 5
0
5
Arpmjdr
Hello, I am using Splunk enterprise and splunk enterprise security. I have windows IIS TA configured as well.How to ...
by Arpmjdr Explorer in Splunk Search 09-04-2019
0 1
0
1
duyuzhuo
I don't want to modify the pdfgen_chart.py, is there any other way? and when I use 'https://localhost:8089/services/p...
by duyuzhuo Explorer in Splunk Search 09-04-2019
0 0
0
0
adrien_dereumau
I feed my index with many totals and actual use values. Each of those fields are in the following event: { [-] ...
by adrien_dereumau Path Finder in Splunk Search 09-04-2019
0 10
0
10
salmanbpc
Hello Everyone. im trying to make a simple table for the log file which i have uploded in Splunk. i can able to get ...
by salmanbpc New Member in Splunk Search 09-04-2019
0 3
0
3
sandeepmakkena
index=aos_transaction | chart count by payments, geo | addtotals col=t | sort -Total | head 10 I want to display onl...
by sandeepmakkena Contributor in Splunk Search 09-03-2019
0 2
0
2
SanthoshSreshta
Hi when I am trying to get the results from the DB (SQL Server), there are some column names as "Show Room Code". ...
by SanthoshSreshta Contributor in Splunk Search 09-03-2019
0 3
0
3
sandeepmakkena
I am working on website sales data where n number of different services are called like CartService, OrderBuildServic...
by sandeepmakkena Contributor in Splunk Search 09-03-2019
0 3
0
3
d_o_c
I'm using Splunk Enterprise Version: 7.3.0 I'm trying to make a chrome extension that will allow me to toggle line-c...
by d_o_c New Member in Splunk Search 09-03-2019
0 0
0
0
vikram1583
Offense Name: Interactive Login with Service Account Rule: Service accounts typically start with svc* Offense Name: ...
by vikram1583 Explorer in Splunk Search 09-03-2019
0 0
0
0
nick405060
I guess the question is a bit facetious But, I would still like to know what the (flawed) logic is behind this? It's...
by nick405060 Motivator in Splunk Search 09-03-2019
3 5
3
5
nareshkumar1985
Hi All, I am trying to capture line starting with a number, I have created a regex and tested it in regex101 site and...
by nareshkumar1985 Engager in Splunk Search 09-03-2019
0 4
0
4
Anantha123
Hi All, How can I do switch case for below values {"XXX":["ABC"]} == ABC {"XXX":[]} == NULL . | eval Name=ca...
by Anantha123 Communicator in Splunk Search 09-03-2019
0 2
0
2
N92
I have below search criteria so let me know best way for this. base search (which have output in table format) [tabl...
by N92 Path Finder in Splunk Search 09-03-2019
0 5
0
5
lsy9891
Hi, I'm new to Splunk and so far I've managed to get the number of errors but I do not know for which application? I...
by lsy9891 Engager in Splunk Search 09-03-2019
0 7
0
7
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...