Splunk Search

Splunk Search
Community Activity
balcv
I have created a search including sparkline: index=_* type="threat" severity="medium" | stats sparkline count | ta...
by balcv Contributor in Splunk Search 03-06-2019
0 3
0
3
mdmaala
Is there any way that I can customize the color of column or bar chart? since I wanted to represent green, yellow and...
by mdmaala Communicator in Splunk Search 03-06-2019
0 2
0
2
dbturner
Trying to pull more than one column from an inputlookup. One of the columns maps to a field in the index I am search...
by dbturner New Member in Splunk Search 03-06-2019
0 1
0
1
moizmmz
Hello, So here's my Query: index=video-eng-live | rename message.timestamp as time | eval time=strftime(time/1000...
by moizmmz Path Finder in Splunk Search 03-06-2019
0 6
0
6
williamcharlton
I have an index with events in it that, among others, have the fields shown at the bottom of this post When I execut...
by williamcharlton Path Finder in Splunk Search 03-06-2019
0 5
0
5
ericl42
I'm working on an antivirus correlation rule, and I'm running into a few issues. I want to make sure dest, signature,...
by ericl42 Path Finder in Splunk Search 03-06-2019
0 9
0
9
ajith_sukumaran
Hello, I have the below query trying to produce the event and host count for the last hour. The index & sourcetype ...
by ajith_sukumaran Explorer in Splunk Search 03-06-2019
0 6
0
6
VanyBerg
Greetings everyone! I have a question concerning a CSV lookup table with domains in it, which sadly does not work. ...
by VanyBerg Engager in Splunk Search 03-06-2019
0 1
0
1
Zakary_n
In order to remove weekend days completly from my timechart, I created a request : My Base Search | eval date_wday...
by Zakary_n Path Finder in Splunk Search 03-06-2019
0 7
0
7
harshal_chakran
Hi, Is there any way to list the methods used for onboarding of data (Forwaders, DBconnect, Syslog, Http EventCollec...
by harshal_chakran Builder in Splunk Search 03-06-2019
0 1
0
1
ssaenger
Hi All, i am trying to use Curl to return a search as my result will be >6million to a csv file. using the command: ...
by ssaenger Communicator in Splunk Search 03-06-2019
0 5
0
5
rashid47010
I have one correlation rule trigged against IP reputation. Now we have different network devices, like cisco, f5. I...
by rashid47010 Communicator in Splunk Search 03-06-2019
0 0
0
0
sanjds
i have look table with known errors and planning to create job which runs on cron schedule and provide me list of er...
by sanjds New Member in Splunk Search 03-06-2019
0 1
0
1
jip31
Hi, With the code below, I count the event number by source for a sourcetype. But different sources use the same so...
by jip31 Motivator in Splunk Search 03-06-2019
0 10
0
10
mishaaaaaaaaaa
Hi splunk comunity! How can i get specific value from latest event and earliest event during the period i set? I ne...
by mishaaaaaaaaaa Explorer in Splunk Search 03-06-2019
0 0
0
0
mdmaala
hi! Under the field Username, I have two lists, Machine1 and Machine2 I want to split this into two separate column...
by mdmaala Communicator in Splunk Search 03-06-2019
0 3
0
3
johann2017
Hello. How would I write a search to show a computer that has been authenticating to multiple machines. For example, ...
by johann2017 Explorer in Splunk Search 03-06-2019
0 3
0
3
mkarimi17
I have a path (and a variable file_path) that looks like this: C:\\\\Program Files\\\\theapp\\\\the app\\\\Tools\\\\...
by mkarimi17 Path Finder in Splunk Search 03-06-2019
0 8
0
8
JakeInfoSec
So I have a search that runs hourly over a lookup table which I have created that includes IP, ticket number, date_ad...
by JakeInfoSec Explorer in Splunk Search 03-06-2019
0 4
0
4
ryangrobbel
Hi All, I currently am pulling in data from an application and we are looking extract a single line that the event o...
by ryangrobbel Explorer in Splunk Search 03-05-2019
0 3
0
3
gkumarashanmuga
How do you check the number of users who are currently using the system(Splunk web UI login) over the last month?
by gkumarashanmuga Explorer in Splunk Search 03-05-2019
0 4
0
4
rpradeep
We use Splunk for many of our project dashboards & want to see if I can use the same setup to host a Vacation Tracker...
by rpradeep Path Finder in Splunk Search 03-05-2019
1 18
1
18
ramesh12345
Hi, index="os" sourcetype="Service" CaseNumber=* status=* assignment_group=* |dedup _time,CaseNumber,assignment_gr...
by ramesh12345 Explorer in Splunk Search 03-05-2019
0 1
0
1
jwhughes58
I have this search that I'm trying to break down | tstats `summariesonly` values(Web.url) as url values(Web.src) as ...
by jwhughes58 Contributor in Splunk Search 03-05-2019
0 3
0
3
veerendra_modi
I have a stats result with the count field. I want to compare if this count is greater than another field. I.e., a th...
by veerendra_modi Loves-to-Learn in Splunk Search 03-05-2019
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...