Splunk Search

Splunk Search
Community Activity
Strangertinz
Hi, I created a column chart in Splunk that shows month but will like to also indicate the day of the week for each o...
by Strangertinz Path Finder in Splunk Search 02-13-2024
0 6
0
6
adamsobczykhsbc
I have raw data like:  Error=REQUEST ERROR | request is not valid.|","time":"1707622073040"  and I want to extract "R...
by adamsobczykhsbc Explorer in Splunk Search 02-13-2024
0 5
0
5
iainp
I have a number of devices that send logs to Splunk.I want to know when devices stop logging.For this example search:...
by iainp New Member in Splunk Search 02-13-2024
0 2
0
2
mwcentracomm
I created an alert from the search below, and it emails a pdf - is there a way to add the most recent event from each...
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 5
0
5
EPitch
Hi Everyone,  I am looking for a little advice, I am currently searching splunk against multiple sets of variables to...
by EPitch Observer in Splunk Search 02-12-2024
0 4
0
4
0p3r4t0r8089
I have a report that lists malware received by email that is part of a dashboard. Some months the list for each perso...
by 0p3r4t0r8089 Explorer in Splunk Search 02-12-2024
0 7
0
7
marshalll3302
Splunk sirs, I am trying to add a boolean column to my data called 'new_IP_detected' which will tell me whether an an...
by marshalll3302 Explorer in Splunk Search 02-12-2024
0 4
0
4
mwcentracomm
HelloI would like a search to show the last entry of host="1.1.1.1", and show the full entry. Thank you
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 1
0
1
Roy1
Hello, I have the following data: I want to use this data to setup a dashboard. In this dashboard I want to show the ...
by Roy1 Explorer in Splunk Search 02-12-2024
0 7
0
7
paras
I have this lookup that has a list of searches I want to run.I want to run a search that can run output the "magic" v...
by paras Explorer in Splunk Search 02-11-2024
0 2
0
2
yk010123
I have log entries that have the following format :[<connectorName>|<scope>]<sp>The following are examples of the con...
by yk010123 Path Finder in Splunk Search 02-11-2024
0 1
0
1
mah
Hi,  I wanted to update splunk_security_essentials app (3.2.2 to 3.3.2) : after I did the restart, I have this error ...
by mah Builder in Splunk Search 02-10-2024
3 14
3
14
syk19567
Hi community,I'm using rex to get some strings.The log is like\"submission_id\":337901The regex I'm using is:\"submis...
by syk19567 Explorer in Splunk Search 02-09-2024
0 5
0
5
jmrubio
Hello! I am trying to send syslogs to splunk from network devices using udp. I have one heavy forwarder and two index...
by jmrubio Path Finder in Splunk Search 02-09-2024
0 3
0
3
bobmorning
What is the most elegant way of searching for events where a field is not in a list of values?   For example: index=f...
by bobmorning Engager in Splunk Search 02-09-2024
0 1
0
1
Haleb
I have the following SPL search. index="cloudflare" | top ClientRequestPath by ClientRequestHost | eval percent = rou...
by Haleb Path Finder in Splunk Search 02-09-2024
0 1
0
1
dm2
Hi, I have a connection on Splunk DB Connect on my HF (connected to my SH and I know connection is stable and other s...
by dm2 Explorer in Splunk Search 02-09-2024
0 1
0
1
Raj
Hi All,How we can modify the below search to get to see only the status enabled list of correlation searches which di...
by Raj Builder in Splunk Search 02-09-2024
0 4
0
4
Real_captain
Hi I want to create a search to find all the events for which last row exists but there is atleast 1 row missing. Exa...
by Real_captain Path Finder in Splunk Search 02-09-2024
0 1
0
1
bmanikya
Search Query 1 Search Query 2Would like to join search query 1 and 2 and get the results, but no results found.index=...
by bmanikya Loves-to-Learn Everything in Splunk Search 02-09-2024
0 6
0
6
man03359
Hi All,I have a field called summary in my search -Failed backup of the transaction log for SQL Server database 'mode...
by man03359 Communicator in Splunk Search 02-08-2024
0 4
0
4
sansay
Last week, we had someone run a query in which he had "index=*" over 1 week. This triggered a surge of memory usage t...
by sansay Contributor in Splunk Search 02-08-2024
4 7
4
7
herguzav
Hi frends I have logs like_time=time latitude=1 longitude=-1 other fields ..._time=time latitude=1 longitude=-2 other...
by herguzav Explorer in Splunk Search 02-08-2024
0 1
0
1
Loepp
I have a challenge: When somebody are doing changes to our AD, it is done using a cyberark account. In order to finde...
by Loepp Observer in Splunk Search 02-08-2024
0 4
0
4
lawrence_magpoc
After upgrading our universal forwarder to 9.0.1, it started crashing almost everyday. I looked at the splunkd.log an...
by lawrence_magpoc Path Finder in Splunk Search 02-08-2024
0 3
0
3
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors