Splunk Search

Splunk Search
Community Activity
yasein
I have logs like msg="some string here method=aaaa" method=bbbb splunk may extract method=aaaa out of the quoted st...
by yasein Engager in Splunk Search 09-04-2019
0 3
0
3
ips_mandar
I am extracting one field at index time from source field using regex and while searching field value sometime I am u...
by ips_mandar Builder in Splunk Search 09-04-2019
0 2
0
2
russell120
Hi, I have a sample CSV called original.csv. Each day, a search is ran and saved to new.csv. What search to do I need...
by russell120 Communicator in Splunk Search 09-04-2019
0 3
0
3
dzejsonborn
Hi Guys, Can you please tell me how to exclude/whitelist multiple ip adresses from the datamodel search here is the...
by dzejsonborn New Member in Splunk Search 09-04-2019
0 6
0
6
pavanae
The following is the regex I am working on and what I'm trying to do is exclude any username events that ends with "Z...
by pavanae Builder in Splunk Search 09-04-2019
0 2
0
2
abhijitd
index=app sourcetype=accesslog uri="some uri" user!="-" (context="display" OR context="pages") earliest=-7d | rex fi...
by abhijitd New Member in Splunk Search 09-04-2019
0 2
0
2
moonyoungjung
Same SPL result is different by user A and admin SPL-> index=xxx when I do search with userA's userid "interestin...
by moonyoungjung New Member in Splunk Search 09-04-2019
0 5
0
5
Arpmjdr
Hello, I am using Splunk enterprise and splunk enterprise security. I have windows IIS TA configured as well.How to ...
by Arpmjdr Explorer in Splunk Search 09-04-2019
0 1
0
1
duyuzhuo
I don't want to modify the pdfgen_chart.py, is there any other way? and when I use 'https://localhost:8089/services/p...
by duyuzhuo Explorer in Splunk Search 09-04-2019
0 0
0
0
adrien_dereumau
I feed my index with many totals and actual use values. Each of those fields are in the following event: { [-] ...
by adrien_dereumau Path Finder in Splunk Search 09-04-2019
0 10
0
10
salmanbpc
Hello Everyone. im trying to make a simple table for the log file which i have uploded in Splunk. i can able to get ...
by salmanbpc New Member in Splunk Search 09-04-2019
0 3
0
3
sandeepmakkena
index=aos_transaction | chart count by payments, geo | addtotals col=t | sort -Total | head 10 I want to display onl...
by sandeepmakkena Contributor in Splunk Search 09-03-2019
0 2
0
2
SanthoshSreshta
Hi when I am trying to get the results from the DB (SQL Server), there are some column names as "Show Room Code". ...
by SanthoshSreshta Contributor in Splunk Search 09-03-2019
0 3
0
3
sandeepmakkena
I am working on website sales data where n number of different services are called like CartService, OrderBuildServic...
by sandeepmakkena Contributor in Splunk Search 09-03-2019
0 3
0
3
d_o_c
I'm using Splunk Enterprise Version: 7.3.0 I'm trying to make a chrome extension that will allow me to toggle line-c...
by d_o_c New Member in Splunk Search 09-03-2019
0 0
0
0
vikram1583
Offense Name: Interactive Login with Service Account Rule: Service accounts typically start with svc* Offense Name: ...
by vikram1583 Explorer in Splunk Search 09-03-2019
0 0
0
0
nick405060
I guess the question is a bit facetious But, I would still like to know what the (flawed) logic is behind this? It's...
by nick405060 Motivator in Splunk Search 09-03-2019
3 5
3
5
nareshkumar1985
Hi All, I am trying to capture line starting with a number, I have created a regex and tested it in regex101 site and...
by nareshkumar1985 Engager in Splunk Search 09-03-2019
0 4
0
4
Anantha123
Hi All, How can I do switch case for below values {"XXX":["ABC"]} == ABC {"XXX":[]} == NULL . | eval Name=ca...
by Anantha123 Communicator in Splunk Search 09-03-2019
0 2
0
2
N92
I have below search criteria so let me know best way for this. base search (which have output in table format) [tabl...
by N92 Path Finder in Splunk Search 09-03-2019
0 5
0
5
lsy9891
Hi, I'm new to Splunk and so far I've managed to get the number of errors but I do not know for which application? I...
by lsy9891 Engager in Splunk Search 09-03-2019
0 7
0
7
dzejsonborn
Hi All, I work with Datamodels, and trying to create search which will alert me about TOR communication. Having som...
by dzejsonborn New Member in Splunk Search 09-03-2019
0 3
0
3
surekhasplunk
Hi I am trying to find an ip from first query and then search that ip if exists in another csv file and show the co...
by surekhasplunk Communicator in Splunk Search 09-03-2019
0 1
0
1
babakkhorshid
Hi People, Is there any efficient way of grouping values? I have like 20 Or statement that I need to match something...
by babakkhorshid New Member in Splunk Search 09-03-2019
0 3
0
3
RobertEttinger8
Hi, I have events indexed in the following format: type=a transactionID=xxxxxxxxxxx status=Created lastUpdateTime=_...
by RobertEttinger8 Explorer in Splunk Search 09-03-2019
0 1
0
1
Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...
Top Solution Authors