Splunk Search

Splunk Search
Community Activity
vrmandadi
Hello I have the below sample events Thu Sep 5 10:00:02 EDT 2019 XDB EXPIRED & LOCKED ...
by vrmandadi Builder in Splunk Search 09-06-2019
0 5
0
5
bapun18
Can Please anyone help me in building the query for my alert so that It takes the index name and its corresponding th...
by bapun18 Communicator in Splunk Search 09-06-2019
0 3
0
3
a123537
So I have a search query which returns registrations for a website called CXI. See below: sourcetype=applog Successf...
by a123537 New Member in Splunk Search 09-06-2019
0 5
0
5
tcalvillo
Hello everyone, I'm a newbie and I did build my own dashboard in Splunk. I was able to create different charts and I...
by tcalvillo Engager in Splunk Search 09-06-2019
0 5
0
5
pratyushd
... |rename General.SetupViews as Modes|eval mode=split(Modes," ")|eval name1=mvindex(mode,0) | eval name2=mvindex(mo...
by pratyushd New Member in Splunk Search 09-06-2019
0 4
0
4
kteng2024
Hi, Whenever log into the splunk , i am getting " app not found" error . can i please know how to keep "searching an...
by kteng2024 Path Finder in Splunk Search 09-06-2019
0 4
0
4
Arpmjdr
Hi Splunkers, I have the events getting ingested as below: timestamp patch_version hostname Now,I want to crea...
by Arpmjdr Explorer in Splunk Search 09-06-2019
0 5
0
5
lsy9891
Hi I have this query that counts the number of errors for two applications but I get the application names from diff...
by lsy9891 Engager in Splunk Search 09-06-2019
0 1
0
1
salmanbpc
for example: dport=86 pattern: 0 tcp && dst port 86 && dst 345 here dport is field and pattern is non field value. i...
by salmanbpc New Member in Splunk Search 09-06-2019
0 1
0
1
jip31
hi In a first lookup (host.csv), I have a field "host" In a second lookup (toto.csv), I have also a field "host" Is ...
by jip31 Motivator in Splunk Search 09-06-2019
0 2
0
2
vasanthi77
can we run a search using the Splunk API to get back a single result(not streaming) without using a saved search or S...
by vasanthi77 Explorer in Splunk Search 09-06-2019
0 4
0
4
faribole
My search calculate the number of events of a field per hour per day. In my chart result I only want to see the max o...
by faribole Path Finder in Splunk Search 09-06-2019
0 2
0
2
jip31
hello I have done a saved search scheduled one time per day from the query below index=toto sourcetype="tutu" h...
by jip31 Motivator in Splunk Search 09-05-2019
0 4
0
4
psychogyiokosta
Hi, Using Splunk on a raw log file I get the total templates (clusters) of logs using something like: host="my_host...
by psychogyiokosta New Member in Splunk Search 09-05-2019
0 1
0
1
balash1979
Trying to parse the following line: newCount 20 OldCount 10 The following is my splunk query: index="server" | re...
by balash1979 Path Finder in Splunk Search 09-05-2019
0 1
0
1
dzejsonborn
Translating Qradar rules to SPL and stocked with setting thresholds 300 events are seen with the same Source IP and ...
by dzejsonborn New Member in Splunk Search 09-05-2019
0 3
0
3
johann2017
Hello. Has anyone built a detection for pass the hash? I have windows local event logs and AD logs at my disposal...
by johann2017 Explorer in Splunk Search 09-05-2019
1 2
1
2
maellebrown
Hi! I am looking for help for, I think, a simple statistic but I can't figure out how to do this simply. Here's an ...
by maellebrown New Member in Splunk Search 09-05-2019
0 7
0
7
jwalzerpitt
Can anyone recommend a way to search for file names based on entropy? I'd like to run a search that looks for funky/a...
by jwalzerpitt Influencer in Splunk Search 09-05-2019
0 0
0
0
snappersdad
All, I am running Splunk 7.2.6 under Debian 9.9. I am searching using index = main and picking the top 5 http stat...
by snappersdad New Member in Splunk Search 09-05-2019
0 3
0
3
rashi83
Hi , We are running apps in docker world and looking at docker log growth - app / engineering team wants to adapt a...
by rashi83 Path Finder in Splunk Search 09-05-2019
0 1
0
1
danielbb
We would like to know whether the event time is within working hours and a developer came up with the following. Does...
by danielbb Motivator in Splunk Search 09-05-2019
0 8
0
8
marktechuk
Hi guys I'm looking to extract a value from a field using regex, the field contain different types of data such as Id...
by marktechuk New Member in Splunk Search 09-05-2019
0 1
0
1
a212830
Hi, Someone was kind enough to help me with this yesterday: link text And it worked fine, until I realized that th...
by a212830 Champion in Splunk Search 09-05-2019
0 3
0
3
d_o_c
It can enhance query readability to separate large queries into their logical components using empty lines: index =...
by d_o_c New Member in Splunk Search 09-05-2019
0 1
0
1
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors