Splunk Search

Splunk Search
Community Activity
sumarri
So, I have one source (transactions) with userNumber and another source (users) with number. I want to join both of t...
by sumarri Path Finder in Splunk Search 03-05-2024
0 3
0
3
Nagalakshmi
Hi, I have created the dashboard with multiple panels. I have created the time range panel to be reflected as last 4 ...
by Nagalakshmi Path Finder in Splunk Search 03-05-2024
0 2
0
2
handosplunk2
Hello all,I'm trying to get a duration between the first "started" event, and the first "connected" event following s...
by handosplunk2 Observer in Splunk Search 03-05-2024
0 4
0
4
dtccsundar
i have 2 requirements 1) From different events in need to extract the word after Interface  and Comma. After Interfac...
by dtccsundar Path Finder in Splunk Search 03-05-2024
0 1
0
1
Taylor323
I'm looking to run a |rest command to return a list of apps, and app versions sent from the management node (i.e.  ma...
by Taylor323 New Member in Splunk Search 03-05-2024
0 0
0
0
PavelP
any ideas on TERM and PREFIX limitations with double dashes?  cat /tmp/test.txt abc//xyz abc::xyz abc==xyz abc@@xyz a...
by PavelP Motivator in Splunk Search 03-04-2024
1 17
1
17
raysonjoberts
I am having a random issue where it seems characters are present in a field which cannot be seen.If you look in the r...
by raysonjoberts Path Finder in Splunk Search 03-04-2024
0 2
0
2
karthi2809
Hi ,How to extract the fields from below json logs.Here we have fields like content.jobname and content.region .But i...
by karthi2809 Builder in Splunk Search 03-04-2024
0 4
0
4
parthiban
Hi Team,I want to extract the below field value, here the challenge is the error code 403 sometimes it will change."p...
by parthiban Path Finder in Splunk Search 03-04-2024
0 3
0
3
Fo
I have two very simple searches and I need to be able to get the difference. This is insanely hard for something that...
by Fo Engager in Splunk Search 03-04-2024
0 3
0
3
ptrsnk
Hello,I am running a search that is returning IP addresses that are being sent to a waf (web access firewall).  The w...
by ptrsnk Explorer in Splunk Search 03-03-2024
0 4
0
4
bryhoffman
Hi,I have an search that is used on a dashboard that I would like tweaked.Currently this search/panel displays the va...
by bryhoffman Explorer in Splunk Search 03-03-2024
1 6
1
6
Jay2024
We have logs in two different indexes. There is no common field other than the _time . The  timestamp of the events i...
by Jay2024 New Member in Splunk Search 03-03-2024
0 2
0
2
Muthu_Vinith
Hi Experts, I need to compare server lists from two different csv lookups and create a flag based on the comparison r...
by Muthu_Vinith Path Finder in Splunk Search 03-03-2024
0 1
0
1
splunkreal
Hello,I would like to know the aim of this default constraint :(`cim_Authentication_indexes`) tag=authentication NOT ...
by splunkreal Influencer in Splunk Search 03-02-2024
0 2
0
2
Ash1
We want to provide few capabilities to the teamPresently team has a capability to create email alert.What capabilitie...
by Ash1 Communicator in Splunk Search 03-01-2024
0 2
0
2
syazwani
Hi,Why my CIDR matching in not following the lookup content?Query i used is as below:| makeresults| eval ip="10.10.10...
by syazwani Path Finder in Splunk Search 03-01-2024
0 2
0
2
YuriSpirin
Hi,I have a KV time-based lookup generated from DHCP logs with content like this:time,ip,hostname,mac 1709093697,10.2...
by YuriSpirin Explorer in Splunk Search 03-01-2024
0 4
0
4
mhdzabi
Hi,  I have multiple events with the following JSON object. { "timeStamp": "2024-02-29T10:00:00.673Z", "collectionI...
by mhdzabi New Member in Splunk Search 03-01-2024
0 3
0
3
TaraAshley
I am working on a query that lists hosts and their corresponding instances. My results look like the example below. I...
by TaraAshley Engager in Splunk Search 03-01-2024
0 1
0
1
egonstep
Hello all, how do I retrieve the values from my search and insert in the same row, extracting the values from the fie...
by egonstep Path Finder in Splunk Search 03-01-2024
0 9
0
9
secphilomath1
I am getting an error when using the following regex(?<=on\s)(.*)(?=\sby Firewall Settings)The error is "Error in 're...
by secphilomath1 Explorer in Splunk Search 03-01-2024
0 2
0
2
ALXWBR
Really struggling with this one, so looking for a hero to come along with a solution!I have an index of flight data. ...
by ALXWBR Path Finder in Splunk Search 03-01-2024
0 7
0
7
AKG11
Hi,In a table, I am looking to get a field value from previous available value in case its null.In below screenshot, ...
by AKG11 Path Finder in Splunk Search 03-01-2024
0 1
0
1
yoshileigh66
I have a query that gets a list of destination ips per source ip. I also want to add a column for the associated doma...
by yoshileigh66 Explorer in Splunk Search 03-01-2024
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...