Splunk Search

Splunk Search
Community Activity
Taruchit
Hello All,I have the below SPL to compare hourly event data and indexed data to find if they follow similar pattern a...
by Taruchit Contributor in Splunk Search 02-15-2024
0 8
0
8
Branden
Quick question: how can I view a user's search history?
by Branden Builder in Splunk Search 02-15-2024
14 24
14
24
guywood13
  index=myindex source="/var/log/nginx/access.log" | eval status_group=case(status!=200, "fail", status=200, "succe...
by guywood13 Path Finder in Splunk Search 02-15-2024
0 2
0
2
HPACHPANDE
Hello Team,Required help regarding below points :1] how to add entry of  the ran search with the fields Host, SourceI...
by HPACHPANDE Explorer in Splunk Search 02-14-2024
0 1
0
1
Ho_Wai_Yung
I am relatively new to the Splunk coding space so bare with me in regards to my inquiry.Currently I am trying to crea...
by Ho_Wai_Yung Explorer in Splunk Search 02-14-2024
0 10
0
10
LHumberto
I'm new to REX and trying to extract strings from _raw (which is actually a malformed JSON, so SPATH is not a good op...
by LHumberto Explorer in Splunk Search 02-14-2024
0 4
0
4
ilhwan
I have a distributed environment with 2 independent search heads.  I run the same search on both, and one shows a fie...
by ilhwan Path Finder in Splunk Search 02-14-2024
0 4
0
4
splunktrainingu
Hello,   I am trying to count how many days out of the last 12 months our users logged into two of our servers.  And ...
by splunktrainingu Communicator in Splunk Search 02-14-2024
0 6
0
6
smanojkumar
Hi Splunkers,   I would like to pass the label value to the macro based on some condition, when a single value is sel...
by smanojkumar Contributor in Splunk Search 02-14-2024
0 1
0
1
Abass42
I need some help updating the mmdb file for the iplocation command. Ive read the other forum questions regarding this...
by Abass42 Communicator in Splunk Search 02-13-2024
0 0
0
0
sfghjkl
Hi,I am working my way through some of the splunk courses. I am currently on "working with time".In one of the videos...
by sfghjkl New Member in Splunk Search 02-13-2024
0 1
0
1
NishantKrishna
I am using the below query to merge 2 queries using append. However, I am unable to get the value of the field named ...
by NishantKrishna Loves-to-Learn in Splunk Search 02-13-2024
0 7
0
7
thaghost99
hi i would like some help on how to extract the next 5 lines after a keyword where it extracts the full line where th...
by thaghost99 Path Finder in Splunk Search 02-13-2024
0 5
0
5
Arani_Hari
How to extract alphanumeric and numeric values from aline,  both are dynamic values<Alphanumeric>_ETC_RFG: play this ...
by Arani_Hari Loves-to-Learn Lots in Splunk Search 02-13-2024
0 7
0
7
martinmasif
I have a "cost" for two different indexes that I want to calculate in one and the same SPL. As the "price" is differe...
by martinmasif Explorer in Splunk Search 02-13-2024
0 2
0
2
Strangertinz
Hi, I created a column chart in Splunk that shows month but will like to also indicate the day of the week for each o...
by Strangertinz Path Finder in Splunk Search 02-13-2024
0 6
0
6
adamsobczykhsbc
I have raw data like:  Error=REQUEST ERROR | request is not valid.|","time":"1707622073040"  and I want to extract "R...
by adamsobczykhsbc Explorer in Splunk Search 02-13-2024
0 5
0
5
iainp
I have a number of devices that send logs to Splunk.I want to know when devices stop logging.For this example search:...
by iainp New Member in Splunk Search 02-13-2024
0 2
0
2
mwcentracomm
I created an alert from the search below, and it emails a pdf - is there a way to add the most recent event from each...
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 5
0
5
EPitch
Hi Everyone,  I am looking for a little advice, I am currently searching splunk against multiple sets of variables to...
by EPitch Observer in Splunk Search 02-12-2024
0 4
0
4
0p3r4t0r8089
I have a report that lists malware received by email that is part of a dashboard. Some months the list for each perso...
by 0p3r4t0r8089 Explorer in Splunk Search 02-12-2024
0 7
0
7
marshalll3302
Splunk sirs, I am trying to add a boolean column to my data called 'new_IP_detected' which will tell me whether an an...
by marshalll3302 Explorer in Splunk Search 02-12-2024
0 4
0
4
mwcentracomm
HelloI would like a search to show the last entry of host="1.1.1.1", and show the full entry. Thank you
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 1
0
1
Roy1
Hello, I have the following data: I want to use this data to setup a dashboard. In this dashboard I want to show the ...
by Roy1 Explorer in Splunk Search 02-12-2024
0 7
0
7
paras
I have this lookup that has a list of searches I want to run.I want to run a search that can run output the "magic" v...
by paras Explorer in Splunk Search 02-11-2024
0 2
0
2
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...