Splunk Search

Splunk Search
Community Activity
hketer
Hey, I have this event. as you can see there is field named cs1. I need to create new field lets say cs_1 and extract...
by hketer Path Finder in Splunk Search 05-13-2019
0 13
0
13
perryd
Hi, i would match two field, exactly: field1 - field2 1 - Empty 1 - Empty 1 - Empty ...
by perryd Engager in Splunk Search 05-13-2019
0 8
0
8
rrakesh874
HI All, I have scenario where my field value is pipe delimited e.g. Session=PP|OO|GG if in search I do table of Ses...
by rrakesh874 New Member in Splunk Search 05-13-2019
0 4
0
4
mnarmada
Hello, My Situation is different. I have few columns like: code, Week, rfs, decision, new_deecision. In my search,...
by mnarmada Path Finder in Splunk Search 05-13-2019
0 0
0
0
jdhavo
It seems like something that has been answered before but i have been unable to find the answer. Is it possible to ru...
by jdhavo New Member in Splunk Search 05-13-2019
0 3
0
3
jatwell2
Here is the source data: { "contextValues": [ "10.1.1.1", "10", "testhost" ], "contextTypes": [ ...
by jatwell2 New Member in Splunk Search 05-13-2019
0 9
0
9
wlwilliams01
1
2
maryamchar
Hello, I asked this question yesterday but didn't get the right solution. I have two indexes with different fields a...
by maryamchar Explorer in Splunk Search 05-13-2019
0 4
0
4
arunsundarm
index=* [search index=_internal [| rest /services/authentication/current-context splunk_server=local | fields usernam...
by arunsundarm Engager in Splunk Search 05-13-2019
0 3
0
3
brpsingara
May I know what is User Activity as per PCI requirement 10 ? On going SSAE 18 audit, there is one question - please ...
by brpsingara Explorer in Splunk Search 05-13-2019
0 0
0
0
smanganiello_sp
Other than making reports more readable, are there other reasons to use the upper/lower function of eval?
by smanganiello_sp Splunk Employee Splunk Employee in Splunk Search 05-13-2019
0 4
0
4
mschlapfer
I'm trying to write a dbinspect query to calculate the # of days of data that is stored in our hot/warm storage parti...
by mschlapfer Explorer in Splunk Search 05-13-2019
0 2
0
2
D2SI
Hello there, I am stuck with a dynamic field name extraction. The data is partly JSON and sometimes contains nested...
by D2SI Communicator in Splunk Search 05-13-2019
0 2
0
2
afulamba
Hi there, I want to build a query with strings from the lookup table. I have the list of domains in the look up table...
by afulamba Explorer in Splunk Search 05-13-2019
0 19
0
19
BP9906
How can one delete stale lookup files? Sometimes users output their data to a lookup table file to reference in anoth...
by BP9906 Builder in Splunk Search 05-12-2019
1 4
1
4
knalla
Hi, I have the below urls. How can I use the regex to remove the tokens from urls? Looking to remove data between /...
by knalla Path Finder in Splunk Search 05-12-2019
0 3
0
3
chrishow
Hi all, I want to create the correlation search in order to further enhance our current security alert from splunk b...
by chrishow Engager in Splunk Search 05-12-2019
0 3
0
3
SplunkDank
I have a semicolon separated file that is to be used as a lookup file. How do you parse the file within the transform...
by SplunkDank New Member in Splunk Search 05-12-2019
0 5
0
5
christianubeda
Hi team! I want to compare last week with avg last three months. This is my code right now. I need some help pls. ...
by christianubeda Path Finder in Splunk Search 05-12-2019
0 0
0
0
astatrial
Hi all, I am trying to run a map command that will run searches from a lookup one by one as follows : | inputlooku...
by astatrial Contributor in Splunk Search 05-12-2019
0 13
0
13
swaguzari
I'm having a problem creating an alert for following scenario: Data source: index=mail sourcetype=pps_messagelog (in...
by swaguzari Engager in Splunk Search 05-12-2019
0 3
0
3
jip31
hello I am doing the distinct count below in my search | stats dc(host) AS OnlineCount by Code | where Code = "Onl...
by jip31 Motivator in Splunk Search 05-12-2019
0 5
0
5
williamsmew
index=av sourcetype=BobsCutRateAV category="BadStuffHappening" | eval date_hour=strftime(_time, "%H") | eval date_w...
by williamsmew New Member in Splunk Search 05-11-2019
0 7
0
7
russell120
Hello, I have a scheduled search that populates a CSV with data each day, including the current date. Here is an ex...
by russell120 Communicator in Splunk Search 05-11-2019
0 4
0
4
keanhong
Hi All, I have a problem to form the logic for sorting Latest and Previous Data to compare. Looking Field1=Status , ...
by keanhong New Member in Splunk Search 05-11-2019
0 7
0
7
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors