Splunk Search

Splunk Search
Community Activity
bigll
I have two SPL#1  index=index1 service IN (22, 53, 80, 8080) | table src_ip #2 index=index2 dev_ip IN ( value from #1...
by bigll Path Finder in Splunk Search 03-27-2024
0 4
0
4
chandraprathi
I have required where the CEF comes as URL and I need just a part of the URL to pass as input(ARTIFACT.CEF.URL) to ac...
by chandraprathi Explorer in Splunk Search 03-27-2024
0 5
0
5
ms2151077
I'm trying to achieve the following search and hoped others might have some helpful suggestions?I have two events fro...
by ms2151077 Engager in Splunk Search 03-27-2024
0 2
0
2
Mahmoud
this is the query, so i'm still a baby in this world (so I'm sorry if there is a dummy mistakes that might drive you ...
by Mahmoud Engager in Splunk Search 03-27-2024
0 1
0
1
Hemnaath
Hi All, Need a help in regex for doing the host over ride with dvc_host field value from the interesting fields for a...
by Hemnaath Motivator in Splunk Search 03-26-2024
0 31
0
31
Ash1
We have an alert where the cron schedule runs for every 6hours0 */6 * * *but I don’t want to receive the alert at 6pm...
by Ash1 Communicator in Splunk Search 03-26-2024
0 6
0
6
naorbarlev
 Hi, I'm receiving the following error message: Error in 'EvalCommand': Failed to parse the provided arguments. Usage...
by naorbarlev Engager in Splunk Search 03-26-2024
0 13
0
13
theouhuios
Hello I think this should be simple enough but somehow I am not able to understand how to approach it. Here is the s...
by theouhuios Motivator in Splunk Search 03-26-2024
0 5
0
5
jpillai
Hi all,   Im analysing event counts for a specific search criteria and I want to know how the count of values changed...
by jpillai Path Finder in Splunk Search 03-26-2024
0 1
0
1
MrGlass
Here is my search in question, the common field is the SessionID index=eis_lb apm_eis_rdp |fillnull value="-" |search...
by MrGlass Explorer in Splunk Search 03-26-2024
0 3
0
3
abi2023
I want mask some data coming from web server logs particularly only one server out of all my web server logs. Can I a...
by abi2023 Path Finder in Splunk Search 03-26-2024
0 1
0
1
martinhelgegren
Hi! Filtering data from an amount of hosts looking for downtime durations. I get a "forensic" use view with this sear...
by martinhelgegren Explorer in Splunk Search 03-26-2024
0 2
0
2
michaelteck
Hello everyone, I'm coming to you for advice. I am currently working with splunk to create monitor WSO2-APIM instance...
by michaelteck Explorer in Splunk Search 03-26-2024
0 3
0
3
eregon
Good morning fellow Splunkthiasts!I have an index with 100k+ events per minute (all of them having the same sourcetyp...
by eregon Path Finder in Splunk Search 03-26-2024
0 1
0
1
raghubankapur
I have 3 different sources of the same filed. I want to aggregate all the 3 sources and get the distinct count of the...
by raghubankapur Engager in Splunk Search 03-26-2024
0 2
0
2
KellyP
Hi I have two sets of data, one is proxy logs (index=netproxy) and the other is an extract of LTE Logs which is logs ...
by KellyP Splunk Employee Splunk Employee in Splunk Search 03-25-2024
0 4
0
4
slearntrain
We have a use case where we need to calculate the time difference between the maximum infotime (steptype="endNBflow")...
by slearntrain Explorer in Splunk Search 03-25-2024
0 6
0
6
sks
I've two counter streams, I would like to display that as a percentage asB/(B+C)  in the chart but it always gives me...
by sks New Member in Splunk Search 03-25-2024
0 2
0
2
janesh222
Hi Splunk Experts,  I have some data coming into splunk which has the following format:  [{"columns":[{"text":"id","t...
by janesh222 Engager in Splunk Search 03-25-2024
0 2
0
2
pop345
I am trying to compare an IP address field called ex_ip thats stored in a lookup file with an index called activity w...
by pop345 Loves-to-Learn Lots in Splunk Search 03-25-2024
0 7
0
7
tylermonteith
I seem to be close on trying to find the statistics to be able to pull unique users per day but I know I'm missing so...
by tylermonteith Explorer in Splunk Search 03-25-2024
0 5
0
5
selvaraj4u
Hi, am creation a dashboard using dashboard studio, and i want to run a query with subsearch.i want to use the time f...
by selvaraj4u New Member in Splunk Search 03-25-2024
0 1
0
1
matthewob5
I have a lookup table that looks like this (:Column 1Column 2Column 3Column 4Value 1--15Value 1--60Value 2--75Value 2...
by matthewob5 Engager in Splunk Search 03-25-2024
0 1
0
1
psamuel69
Hello Expert Splunk Community ,I am struggling with a JSON extraction .Need help/advice on how to do this operationDa...
by psamuel69 Explorer in Splunk Search 03-25-2024
0 5
0
5
kutsyy
I know that I can combine multiple metrics using mstats as: | mstats avg(_value) AS "Average" WHERE metric_name=metr...
by kutsyy Engager in Splunk Search 03-24-2024
0 3
0
3
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...