Splunk Search

Splunk Search
Community Activity
cthulhucalling
I have a small CSV file with common attack signatures in them that I have uploaded as a lookup called web_attack_sign...
by cthulhucalling Engager in Splunk Search 06-12-2019
0 11
0
11
amat
I am trying to figure out how the Size value in the Job page is calculated and where that is logged in splunk. I che...
by amat Explorer in Splunk Search 06-12-2019
1 0
1
0
bryceweb22
I would like to get the percentage of each HTTP status code. I have the count of each status code that appears and I ...
by bryceweb22 Path Finder in Splunk Search 06-12-2019
0 3
0
3
reverse
There are multiple ip addresses in a raw event line and I only need the first one How can I achieve that? 192.168.0...
by reverse Contributor in Splunk Search 06-12-2019
0 4
0
4
nick405060
Hi guys. Can someone please post working js code for a button that toggles a token from "true" to "false" and back. ...
by nick405060 Motivator in Splunk Search 06-12-2019
1 3
1
3
summitsplunk
Let's say I'm doing a stats count by x,y How would I formulate a WHERE that compares the string value of x and y an...
by summitsplunk Communicator in Splunk Search 06-12-2019
0 2
0
2
90509
Hi Team, I would like to find out user failed login attempts which are greater than 6 times and those 6 failed login ...
by 90509 Engager in Splunk Search 06-12-2019
0 9
0
9
jwalzerpitt
I created the following regex to extract the fields for our shibboleth:audit sourcetype events: ^(?:[^\|\n]*\|){2}(?...
by jwalzerpitt Influencer in Splunk Search 06-12-2019
0 1
0
1
dpickett
I have been working on the Fundamentals 1 Certification using the free Cloud Trail instance of Splunk. My instance ha...
by dpickett New Member in Splunk Search 06-12-2019
0 0
0
0
bryceweb22
I need help with extracting and graphing the HTTP status code which is always the end of every log formatted as; `20...
by bryceweb22 Path Finder in Splunk Search 06-12-2019
0 3
0
3
rahulkawadkar26
Hi, I needed help with using field extracted in the search(ORG) to be used as input for another search where a simil...
by rahulkawadkar26 New Member in Splunk Search 06-12-2019
0 5
0
5
a_naoum
Hello, I'm trying to use calculated field on data with url field. Simple doesn't work. Even a very simple 'upper(url...
by a_naoum Path Finder in Splunk Search 06-12-2019
0 10
0
10
jkumarr2
I am trying to filter out all URLs which are for file downloads and those URLs will end with the file extension. Eg -...
by jkumarr2 New Member in Splunk Search 06-12-2019
0 1
0
1
davidch12
I always understood the search command's expressions be connected by a logical AND by default: search customer=123 it...
by davidch12 Explorer in Splunk Search 06-12-2019
0 1
0
1
sarit_s
Hello in my organisation we have few kinds of log format one of them does not have the year in the time stamp so the ...
by sarit_s Communicator in Splunk Search 06-12-2019
0 6
0
6
anasamer
Can anyone here help with breaking this sample into multiple events each should start with { "resourceId": ? I have t...
by anasamer New Member in Splunk Search 06-12-2019
0 9
0
9
jip31
hi I use the search below and I filter the data with 2 token | inputlookup tablet_host.csv | lookup PanaBatterySta...
by jip31 Motivator in Splunk Search 06-12-2019
0 19
0
19
jip31
Hello I use the stats command below but some process_name have no process_cpu_used_percent value So how to do for di...
by jip31 Motivator in Splunk Search 06-12-2019
0 11
0
11
rchittip
Dears, My Splunk Indexer is in CDT time zone and my forwarder logs are in UTC time zone and there is time differenc...
by rchittip Path Finder in Splunk Search 06-12-2019
0 9
0
9
tomgc
Hello everyone, I am trying to combine the following: - The query 1 looks for recent events (earliest=-10m@m latest...
by tomgc Engager in Splunk Search 06-12-2019
0 0
0
0
AshimaE
I have to extract the same features from two sets of logs with very different formats and need to take the additional...
by AshimaE Explorer in Splunk Search 06-12-2019
0 5
0
5
kavyadekkata
Hi I currently have a search which returns a list of users with employee id from a user lookup eg: user lookup has ...
by kavyadekkata Explorer in Splunk Search 06-11-2019
0 1
0
1
dowdag
I have a log file that has the timestamp for each line as: Jun 10, 11:07:59.305475 Note that the year is missing -...
by dowdag Engager in Splunk Search 06-11-2019
0 6
0
6
lsanthoshbe
In my Application there are logs statements which are repetitive and how to avoid them sending to Indexer so that i w...
by lsanthoshbe New Member in Splunk Search 06-11-2019
0 1
0
1
ankurtaunk
I want to write a search where the events are in one column and the related counts are in each column corresponding t...
by ankurtaunk Explorer in Splunk Search 06-11-2019
0 9
0
9
Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...