Splunk Search

Splunk Search
Community Activity
sahil237888
Hi, I need help in creating one query. There is one field "Operator" having multiple values like airphone,bphone,vsph...
by sahil237888 Path Finder in Splunk Search 03-25-2019
0 4
0
4
jpreis
Is there a way to search a cidr notation without using "src_ip OR dest_ip"? I have a bunch of ips i want to search f...
by jpreis New Member in Splunk Search 03-25-2019
0 1
0
1
dbashyam
Hi, I am trying to get a table type of alerting but I am not getting the output index = ops host = Sr*xxxx* sourcet...
by dbashyam Explorer in Splunk Search 03-25-2019
0 2
0
2
awmorris
I am super stoked about the potential of Schema Accelerated Event Searches- might be one of the best improvements i'v...
by awmorris Path Finder in Splunk Search 03-25-2019
1 8
1
8
swangertyler
In my data, events can have children. There is data in those events that I would want to associate with the parent ev...
by swangertyler Path Finder in Splunk Search 03-25-2019
0 4
0
4
ramesh12345
Hi, index=os sourcetype=Service status=* (Group="Data" OR Group="Secur") AND (Section="Local" OR Section="data heal...
by ramesh12345 Explorer in Splunk Search 03-25-2019
0 1
0
1
jwiley_splunk
Currently having a hard time figuring out how to create a column chart where the field values show up in the side, so...
by jwiley_splunk Splunk Employee Splunk Employee in Splunk Search 03-25-2019
0 4
0
4
saulverde
I am having trouble with field extraction. I have a regex which works in a pcre regex tester but when I attempt to us...
by saulverde Path Finder in Splunk Search 03-25-2019
0 2
0
2
javanue
I am trying to compare multivalue fields, but I cannot figure out how to do it correctly? Here is the original query...
by javanue New Member in Splunk Search 03-25-2019
0 1
0
1
seva98
Hi, does anyone know how can I change fieldColors after chart was rendered? Thing is that we have two different visu...
by seva98 Path Finder in Splunk Search 03-25-2019
0 2
0
2
jimmymccauley
Hi All This is my second SOS this week as I get acquainted with Splunk. I've exhausted all possibilities trying to s...
by jimmymccauley Explorer in Splunk Search 03-25-2019
0 4
0
4
gimbil
Hi, I am trying to do a search which basically generates measures based on the value of a field such as X: search ...
by gimbil Explorer in Splunk Search 03-25-2019
0 4
0
4
veerendra_modi
I have a field FQ with the value as "ServerName.domain.com" I want to get only the server name in another field. Pl...
by veerendra_modi Loves-to-Learn in Splunk Search 03-25-2019
0 2
0
2
jip31
hello I use the search below in order to do a total count by OS and by build It mean that it counts only events whic...
by jip31 Motivator in Splunk Search 03-25-2019
0 2
0
2
henrysoon80
Recently i create a transaction search, command and result a per below Search command: search | transaction Session...
by henrysoon80 New Member in Splunk Search 03-25-2019
0 5
0
5
su_kumar
Hi, I am facing an issue in writing a query. Example: Let's assume I have 2 groups such as : 1)Group 1 has user...
by su_kumar New Member in Splunk Search 03-24-2019
0 1
0
1
rashid47010
I have a list of subnets that I want to exlude from search. below isthe search | search NOT cidrmatch("xx.xx....
by rashid47010 Communicator in Splunk Search 03-24-2019
0 1
0
1
ddrillic
Sorry, but I don't understand how ttl is used and the reason for this design paradigm. Any ideas?
by ddrillic Ultra Champion in Splunk Search 03-23-2019
0 10
0
10
masakatsu
I would like to send search result from my report schedule to my API via webhook. We were able to retrieve one search...
by masakatsu Engager in Splunk Search 03-23-2019
1 1
1
1
cpboothe
Hi, I want to get a count on tickets with the latest status of "In Progress". An example of the data set is below: ...
by cpboothe New Member in Splunk Search 03-23-2019
0 2
0
2
mpasha
Hi, i am running a search that will look for failed authentication attempts of a user within a 1 minute window and ge...
by mpasha Path Finder in Splunk Search 03-22-2019
0 0
0
0
ankithreddy777
I need to create a scripted input in inputs.conf that runs scripts by passing arguments at an interval of 60 secs. B...
by ankithreddy777 Contributor in Splunk Search 03-22-2019
0 3
0
3
jwhughes58
Hi, I have this data {"quarantineFolder": null, "spamScore": 100, "threatsInfoMap": [{"campaignID": null, "threat":...
by jwhughes58 Contributor in Splunk Search 03-22-2019
0 1
0
1
braicu
Hello, Can anybody help me extracting from this table with 3 regular expression: I got a column in Splunk like this...
by braicu New Member in Splunk Search 03-22-2019
0 2
0
2
ddecker03
Looking for assistance to search Bro/Zeek for peaks/dips in traffic (what is the best sourcetype to go by). Also ...
by ddecker03 Loves-to-Learn Everything in Splunk Search 03-22-2019
0 0
0
0
Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...
Top Solution Authors