Splunk Search

Splunk Search
Community Activity
Sotu
I am able to pull my AD users account information successfully except for their email addresses.  What am I doing wro...
by Sotu Engager in Splunk Search 05-04-2024
0 2
0
2
karthi2809
Hi All,I am using case statement to map values instead of other values. But i am not getting the values.I am getting ...
by karthi2809 Builder in Splunk Search 05-03-2024
0 4
0
4
karthi2809
Hi All,I am trying to get count of enabled and disabled from field. Then i want to show the field values based on lat...
by karthi2809 Builder in Splunk Search 05-03-2024
0 11
0
11
kuul13
Hi, I am new to Splunk. I am trying to figure out how to extract count of errors per api calls made for each client. ...
by kuul13 Explorer in Splunk Search 05-02-2024
0 1
0
1
guru333
_raw=line 1line 2line 3line 4line 5line 6how to define another new field "copyofraw"  to contain just line 5 and line...
by guru333 Engager in Splunk Search 05-02-2024
0 7
0
7
BARNEYRUDD
Hi, I'm testing thawing of some frozen data and it's not working. I have thawed some previously frozen data and am ex...
by BARNEYRUDD Explorer in Splunk Search 05-02-2024
0 12
0
12
SplunkDash
Hello,  I have a use case to get the index name from the field of one of the index/sourcetype and use that index name...
by SplunkDash Motivator in Splunk Search 05-01-2024
0 6
0
6
mjones414
I have a summary index that pulls in normalized data from 2 different sources (entirely different applications that c...
by mjones414 Contributor in Splunk Search 05-01-2024
0 2
0
2
Badger
DescriptionHow can I produce a URL in an alert email that uses field values, either by in-line results or in the body...
by Badger New Member in Splunk Search 05-01-2024
0 1
0
1
LizAndy123
I have a simple search index=xxxxx "User ID" and I need the correct syntax to get the actual username in the results....
by LizAndy123 Path Finder in Splunk Search 05-01-2024
0 1
0
1
Sotu
I wrote a simple query to parse my Windows Event Security logs to look for a user account, however I am looking to ad...
by Sotu Engager in Splunk Search 05-01-2024
0 2
0
2
bhupalbobbadi
Is there any way to search for events which has any special characters? thanks in advance for any help.
by bhupalbobbadi Path Finder in Splunk Search 05-01-2024
0 4
0
4
jwhughes58
I'm working with a field named Match_Details.match.properties.user.  It contains domain\user information that I'm try...
by jwhughes58 Contributor in Splunk Search 04-30-2024
0 2
0
2
Roy_9
Hi,I am facing a executable permission issue for the few scripts for a splunk app and seeing these errors on various ...
by Roy_9 Motivator in Splunk Search 04-30-2024
0 5
0
5
saidAb
Hi all,A query, can calculate http calls, success responses and error response. I need an addition to the  query to g...
by saidAb Explorer in Splunk Search 04-30-2024
0 10
0
10
anissabnk
Hello,  I'm having problems using roles.I use this search, which gives me results via the admin role. [search index="...
by anissabnk Path Finder in Splunk Search 04-30-2024
0 1
0
1
saidAb
Hello everyone,I am looking for a Splunk search query to get the duration time of three sequential response code 200....
by saidAb Explorer in Splunk Search 04-30-2024
0 9
0
9
bigll
in raw data I have portion that I would like to use in report. "changes":{"description":{"before":"<some text or empt...
by bigll Path Finder in Splunk Search 04-30-2024
0 4
0
4
chimuru84
Hello community!I want to extract data from 2 different logs like bellow:Log 1: 2024-04-28 06:38:51 INFO Start auth f...
by chimuru84 Path Finder in Splunk Search 04-30-2024
0 3
0
3
guru333
Hi,How do I extract word "Dev" from below file locationsource=/test1/folder1/scripts/monitor/log/env/dev/Error.logand...
by guru333 Engager in Splunk Search 04-30-2024
0 7
0
7
fredsnertz
This is probably an entry level question.  I have raw data that looks something like this:{"id": 99999, "type": "HOST...
by fredsnertz Observer in Splunk Search 04-29-2024
0 2
0
2
abi2023
In my index I don't see all the logs being forwarder by the Splunk UF. How can monitor when event is drop from event ...
by abi2023 Path Finder in Splunk Search 04-29-2024
0 1
0
1
MVK1
Hello I have the following sample log lines from a splunk search query   line1 line2 line3: field1 : some msg line4 l...
by MVK1 Path Finder in Splunk Search 04-29-2024
0 7
0
7
karthi2809
Hi All,I have a field called File1 and File2  and I combined in coalesce .In the table but the value is not getting i...
by karthi2809 Builder in Splunk Search 04-29-2024
0 7
0
7
dannepannesthlm
Hi,I have a background with T-SQL and reading the forums I start to realize that "join" is not so good to use with Sp...
by dannepannesthlm Explorer in Splunk Search 04-29-2024
0 8
0
8
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors