Splunk Search

Splunk Search
Community Activity
paragvidhi
Hi All, I am new to Splunk, I am looking for dynamic field creation based on a comparison between two fields value. ...
by paragvidhi Engager in Splunk Search 07-01-2019
0 3
0
3
lucasdc
I have this search 1: index=br_activedirectory_microsoft EventCode=4624 Account_Domain=AGBANESPA Account_Name=A* |...
by lucasdc New Member in Splunk Search 07-01-2019
0 4
0
4
ehowardl3
I have three data sources that I need to correlate together, I'll simplify it for sake of example: Index A: _time, f...
by ehowardl3 Path Finder in Splunk Search 07-01-2019
0 3
0
3
imarks004
I am trying to field extraction working for just domains accessed on my Ironport WSAs but am having an issue extracti...
by imarks004 Path Finder in Splunk Search 07-01-2019
2 11
2
11
vvnair
We are on boarding BMC footprint logs in Splunk for one of our client. Looking for some inputs from someone who have ...
by vvnair Engager in Splunk Search 07-01-2019
0 0
0
0
kacel
| inputlookup Obso_Inventory.csv | eval Compo=case(Composant="WAF", "LBWAF", Composant="LOAD BALANCER", "LBWAF", Comp...
by kacel New Member in Splunk Search 07-01-2019
0 1
0
1
KarunK
Hi All, I have stream logs for five channels (currently may be more in future) and I need to calculate the concurren...
by KarunK Contributor in Splunk Search 07-01-2019
3 6
3
6
a212830
Hi, I have a field that already exists, and I want to parse it out into a new field, using props/transforms. The fi...
by a212830 Champion in Splunk Search 07-01-2019
0 4
0
4
Bastelhoff
Hey there! I am currently having some trouble in converting a flattened multivalue field back into a real multivalue...
by Bastelhoff Path Finder in Splunk Search 07-01-2019
0 12
0
12
doubleshifter
Hi, I'm planning to use Jmeter to perform perfromance test on our Splunk Instance. Just want to confirm if there are...
by doubleshifter Engager in Splunk Search 07-01-2019
0 0
0
0
gcharles
I have a search like the following: index="trans" source="logfilename" "ErrorCode=81009" requestid = "*ABC*" | rex fi...
by gcharles Explorer in Splunk Search 07-01-2019
0 4
0
4
geoffmx
I am attempting to extract the share names from the "pluginText" field below. pluginText: <plugin_output> Here are ...
by geoffmx Explorer in Splunk Search 07-01-2019
1 6
1
6
vishwanadhan_mu
"C:\Users\TestUser\AppData\Local\Microsoft\Teams\Update.exe" --processStart "Teams.exe" --process-start-args "--syste...
by vishwanadhan_mu Explorer in Splunk Search 07-01-2019
0 6
0
6
spisiakmi
Hi. I have a table with 3 columns. A B C. A=time, B=run, C=wait Explenation of the table: the process runs from A2 (1...
by spisiakmi Contributor in Splunk Search 06-30-2019
0 2
0
2
corecomputetool
We have to configure the monitoring for added/removed users in certain servers in Splunk ,
by corecomputetool New Member in Splunk Search 06-30-2019
0 0
0
0
tonahoyos
Hello, I want to find the ResultMin that "Pass" or "Fail" depending on the specific PriorityDuration that is classi...
by tonahoyos Explorer in Splunk Search 06-30-2019
0 8
0
8
yko84109
I have the following query: |tstats values(field1) as f1 values(field2) as f2 where index=INDEX1 [|tstats count where...
by yko84109 Loves-to-Learn in Splunk Search 06-30-2019
0 2
0
2
hoytn
Hello, In a timerange (lets say 4 hours) I am trying to find password resets and after that, for the same user, all ...
by hoytn Explorer in Splunk Search 06-30-2019
1 2
1
2
Splunk_rocks
Hello Looking for some help for Geo stats command. I have following fields showing splunk index time - name,host,...
by Splunk_rocks Path Finder in Splunk Search 06-30-2019
1 1
1
1
mammefen
How can i extract the the http_response_time so that i can get the max(HTTP_STATUS_RESPONSE), MIN(HTTP_STATUS_RESPONS...
by mammefen New Member in Splunk Search 06-30-2019
0 4
0
4
pgadhari
I have a field called Rack which has the values as Rack-1 Rack-2 Rack-3....Rack-10. When I do sort on Rack field, it ...
by pgadhari Builder in Splunk Search 06-29-2019
0 6
0
6
rbednark
The following query is not working for me: message.meta.service=foo | stats count(eval(message.meta.route="/foo...
by rbednark Engager in Splunk Search 06-29-2019
1 4
1
4
psyched4splunk
My end goal is to extract the sourcetype and index with a regex from the monitor path at runtime based on a lookup fr...
by psyched4splunk Explorer in Splunk Search 06-29-2019
0 9
0
9
cxr5971
Hello all, I am looking at endpoint data and I want to see if I can make a search query to look at certain commands ...
by cxr5971 Path Finder in Splunk Search 06-29-2019
0 11
0
11
sureshmurgan
This is the requirement. We are collecting a log file that has the following events (along with others)in the same fi...
by sureshmurgan Path Finder in Splunk Search 06-28-2019
0 8
0
8
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...