Splunk Search

Splunk Search
Community Activity
eliwasserman92
I am interested in quantifying inbound/outbound traffic traversing an IPsec tunnel on a Palo Alto firewall and visua...
by eliwasserman92 New Member in Splunk Search 06-06-2019
0 2
0
2
sfatnass
Hi everybody I want to know how I can color the all the lines in my table by clicking on a cell. I tried this code a...
by sfatnass Contributor in Splunk Search 06-06-2019
1 4
1
4
ltranarris
I'm using DELIM to extract colon separated KV pairs separated by a comma. DELIMS = ",", ":" This is somewhat worki...
by ltranarris New Member in Splunk Search 06-06-2019
0 0
0
0
YuliyaVassilyev
I am developing a map and would like to add certain labels to it, such as percentage or location name. When i hover o...
by YuliyaVassilyev Explorer in Splunk Search 06-06-2019
0 4
0
4
braicu
Hello all , Please help me to extract all values from this field : arn:aws:iam::aws:policy/AmazonEC2FullAccess,Amaz...
by braicu New Member in Splunk Search 06-06-2019
0 3
0
3
Rhin0Crash
Good morning everyone, having a bit of a tough time with this, as my blacklists and whitelists aren't working properl...
by Rhin0Crash Path Finder in Splunk Search 06-06-2019
0 6
0
6
aohls
I am using the transaction command to identify if a report runs over a certain time. Below is my search: | transacti...
by aohls Contributor in Splunk Search 06-06-2019
0 1
0
1
jip31
Hello I use the search below : [| inputlookup host.csv | table host] index="x" sourcetype="PerfmonMk:Process" ...
by jip31 Motivator in Splunk Search 06-06-2019
0 2
0
2
ahmadsaadwarrai
I am bit new to splunk. I want to search top 4 destinations downloads and total ‘Other’ traffic for each source ip. ...
by ahmadsaadwarrai Explorer in Splunk Search 06-06-2019
0 4
0
4
setiad
I added the data into Splunk after changing the configuration in props.conf for breaking the event as per the need...
by setiad Loves-to-Learn in Splunk Search 06-06-2019
0 0
0
0
splunklearner12
I have a list of CIDR ranges in a single column with name Prefix in a csv file. I only want to show events with sourc...
by splunklearner12 Path Finder in Splunk Search 06-06-2019
0 1
0
1
singh3and12
Hi , I am trying to predict cpu load for 10 days ahead for that I am using LLP algorithm in my query, so in visualiz...
by singh3and12 Path Finder in Splunk Search 06-06-2019
0 2
0
2
abhishekdubey00
Now 6/1/19 12:31:03.763 AM 2019-06-01 00:31:03.763, wanted 6/1/19 12:31:03.763 AM 2019-06-01 00:31:03.763
by abhishekdubey00 Engager in Splunk Search 06-06-2019
0 1
0
1
jip31
HI I use the search below which works fine [| inputlookup host.csv | table host] index="x" sourcetype="winhost...
by jip31 Motivator in Splunk Search 06-06-2019
0 7
0
7
pstamati
I have a metric that want to trend on a timechart but I need to span every 2 weeks, starting the 1 monday of each mon...
by pstamati Path Finder in Splunk Search 06-05-2019
0 11
0
11
spamphile
I'm trying to display a pie chart like so: chart count by transaction.inputSource | lookup transaction_input_sources...
by spamphile Engager in Splunk Search 06-05-2019
0 2
0
2
kkovanis
0400 ERROR DispatchProcess - String not found in literals.conf: DISPATCHCOMM:FAILED_TO_START_PROCESS I need help fi...
by kkovanis New Member in Splunk Search 06-05-2019
0 2
0
2
perlish
Hi all, I want to print results excluding the last line. In Linux, I can use head -n -1 but in Splunk, the head comm...
by perlish Communicator in Splunk Search 06-05-2019
1 7
1
7
jip31
hello I need to do a line breaking after "%" and after " on a total of " | eval Perc=round((NbTOUCHNGOCrashByHost/...
by jip31 Motivator in Splunk Search 06-05-2019
0 15
0
15
benjaminlin1019
I use one of the S.O.S. queries to get top 20 memory usage queries every 5 minutes, however, it might be easier for u...
by benjaminlin1019 Explorer in Splunk Search 06-05-2019
2 4
2
4
Shashank_87
Hi, I am trying to plot the Crash rate over _time on a graph and that has to be distributed by app_name. On a high l...
by Shashank_87 Explorer in Splunk Search 06-05-2019
0 2
0
2
kvanwagoner
I've got 2 search queries that are working for me (Thanks to @harshpatel) Query #1 returns the average # of successe...
by kvanwagoner New Member in Splunk Search 06-05-2019
0 5
0
5
vatsalyay
I am writing a code to simply match a regex in my search to match index field which matches app1_, app2_, etc Howeve...
by vatsalyay New Member in Splunk Search 06-05-2019
0 2
0
2
pfabrizi
We have a identities_expanded.csv file in our SA_IdentityManagement app under lookups. It contains our AD data but I ...
by pfabrizi Path Finder in Splunk Search 06-05-2019
0 1
0
1
jip31
hello I use the search below in order to calculate a last logon date and a last reboot date by host now I need to add...
by jip31 Motivator in Splunk Search 06-05-2019
0 7
0
7
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors