Splunk Search

Splunk Search
Community Activity
alex_kh
Hello Everybody I have 4 input fields: Username,IP, System,mac The goal: user enters one value(Username,IP, System,ma...
by alex_kh Explorer in Splunk Search 11-05-2018
0 1
0
1
ranjitbrhm1
Good Day all. I am trying to replace a last name using SED command on my props. my data looks like below. asdfa ...
by ranjitbrhm1 Communicator in Splunk Search 11-05-2018
0 3
0
3
responsys_cm
I'm seeing some really weird behavior. If I run | metadata type=sourcetypes index=XYZ, I see the sourcetype I'm look...
by responsys_cm Builder in Splunk Search 11-04-2018
0 1
0
1
ecoquelin
Dear all, I have a suspicious case using Splunk 7.2. I have a data source type with about 15k rows. Each row is abou...
by ecoquelin Explorer in Splunk Search 11-03-2018
0 5
0
5
sravani27
Hi I have data in the following format: 1,20181030154237,XYZ/ABC - Something Anything,2018-10-30 15:42:37,2018-10-3...
by sravani27 Path Finder in Splunk Search 11-02-2018
0 2
0
2
harishnpandey
Hi, I need help with building query which compares value from 2 different search and trigger alert if count from both...
by harishnpandey Explorer in Splunk Search 11-02-2018
0 5
0
5
travis_bear
Here is my query; I'm trying not to have the "Total_Datapoints" column show up in the table since it has the same val...
by travis_bear Explorer in Splunk Search 11-02-2018
1 5
1
5
damucka
Hello, I was wondering if it is possible to have kind of search through the delivered results in the dashboard panel...
by damucka Builder in Splunk Search 11-02-2018
0 0
0
0
AlexeySh
Hello, I am wandering to know if there is a way to apply a field extractor not to a source type but to a search. I’...
by AlexeySh Communicator in Splunk Search 11-02-2018
0 6
0
6
pavanae
I have a query which gives the results as follows April May June July A G ...
by pavanae Builder in Splunk Search 11-02-2018
0 1
0
1
Jvlemmings
I am running Splunk on Windows 10. I start splunk using: C:\Program Files\Splunk\bin\splunk.exe start first I need ...
by Jvlemmings New Member in Splunk Search 11-02-2018
0 4
0
4
awmorris
I have several critical lookup files that I want to monitor to determine if they are altered in ANY capacity (lookup ...
by awmorris Path Finder in Splunk Search 11-01-2018
0 6
0
6
chioverheaddoor
I have a set of event data that contains id numbers instead of names. I have a lookup table created to match those i...
by chioverheaddoor Explorer in Splunk Search 11-01-2018
0 4
0
4
pavanae
Hi, I have a Splunk query as below which does a comparison between this week's hosts and last week's hosts index="s...
by pavanae Builder in Splunk Search 11-01-2018
0 9
0
9
swangertyler
I need to make a table where I have four columns, the group, the current month, the previous month, and the differenc...
by swangertyler Path Finder in Splunk Search 11-01-2018
0 4
0
4
gkrishnat
Hi There, I am new to Splunk. I need to use savedsearch as a base search to append the query from savedsearch to ano...
by gkrishnat New Member in Splunk Search 11-01-2018
0 0
0
0
skelly99
Hi, I have a dataset with single line events that contains a variable number of fields. The number of fields is de...
by skelly99 Explorer in Splunk Search 11-01-2018
0 7
0
7
pavanae
Hi, I have a query as follows index="summary" search_name="ABC" | dedup hostname | table hostname Now I want see ...
by pavanae Builder in Splunk Search 11-01-2018
0 3
0
3
daniel333
All, I am no developer and burned a couple hours on the making custom commands docs and conf sessions and feel like...
by daniel333 Builder in Splunk Search 11-01-2018
1 4
1
4
ani1303
Hi All.. I have a requirement to create a table visualization which is a little complex and I am new to Splunk can a...
by ani1303 Engager in Splunk Search 11-01-2018
0 3
0
3
PanIrosha
Hi All, i have installed and configured "Cisco AMP for Endpoints" in our search head. Currently, it's forwarding all...
by PanIrosha Path Finder in Splunk Search 11-01-2018
0 6
0
6
heat
I asked this question on another support forum recently but didn't find a solution. Hoping for better results here. ...
by heat New Member in Splunk Search 11-01-2018
0 1
0
1
vrmandadi
We are using Splunk 7.1.1 with three search heads in a cluster environment.Each search head has 40 CPU cores.A lot of...
by vrmandadi Builder in Splunk Search 11-01-2018
0 10
0
10
kdelvillar
I have a search that produces a table that contains a field called "http_referer", and I want to compare this field a...
by kdelvillar Engager in Splunk Search 11-01-2018
0 3
0
3
demopro
Hi, I cannot figure out how to find 4 different IPs in one field and sum them from a list of many IP's. Example: In ...
by demopro New Member in Splunk Search 11-01-2018
0 8
0
8
Get Updates on the Splunk Community!

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...