All Posts

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.

All Posts

Hi, I have a data with the following dates under the field "Warranty_End_Date" Warranty_End_Date Manufacturer 4/1/2026 Lenovo 4/8/2026 Lenovo 1/9/2026 Acer 4/1... See more...
Hi, I have a data with the following dates under the field "Warranty_End_Date" Warranty_End_Date Manufacturer 4/1/2026 Lenovo 4/8/2026 Lenovo 1/9/2026 Acer 4/1/2025 Apple 19/7/2023 Acer 4/1/2026 Acer 4/4/2026 HP 8/1/2028 Lenovo 10/1/2022 Lenovo 4/1/2026 Apple 4/1/2026 Apple 4/1/2026 Lenovo 4/1/2026 Lenovo 4/1/2026 Lenovo 4/3/2026 Lenovo 4/3/2026 Lenovo I want to create a new field with the similar values wrt Warranty_End_Date Tried the command eval WarEnd = case("Warranty_End_Date" = "*2026", "2026", 1=1, "NA") and similarly for other years but got no proper output
Hi @michaelnorup, about the trendline, if you havedata to create the trendline in the results of the loadjob , you could elaborate them. I cannot see tem because, after a timechart you don't have o... See more...
Hi @michaelnorup, about the trendline, if you havedata to create the trendline in the results of the loadjob , you could elaborate them. I cannot see tem because, after a timechart you don't have other fields, see, removing the timeachart, which fields you have, so you could modify your search. If you would help, please share your search in text mode (using the Insert/Edit Code Sample button), not as a screenshot, eventually with a masked part, to avoid to re-write all the search. Ciao. Giuseppe
Hi @Hemnaath, as I said, it's a Splunk Supported App, so you can open a ticket to Splunk Support. Ciao. Giuseppe
Hi Giuseppe. Thanks makes sense, thanks alot. Do you have any idea about the trendline then?
thanks for response but I was looking for old version of the AWS 6.0.0 documentation.  
Hi @michaelnorup, using loadjob, you display the results of an already executed search, so the Time Picker hasn't any effect on it, you can use the Time Picker on searches, not on loadjob. Ciao. G... See more...
Hi @michaelnorup, using loadjob, you display the results of an already executed search, so the Time Picker hasn't any effect on it, you can use the Time Picker on searches, not on loadjob. Ciao. Giuseppe
i am having a hard time integrating opencti into splunk, not sure if you have done it, can you help me
@priyanshuraj400 - I'm assuming you are using the `rest.simpleRequest` method. In there, you can pass a parameter called timeout. For example rest.simpleRequest(apiPath, sessionKey=mySessionKey, me... See more...
@priyanshuraj400 - I'm assuming you are using the `rest.simpleRequest` method. In there, you can pass a parameter called timeout. For example rest.simpleRequest(apiPath, sessionKey=mySessionKey, method='GET', timeout=None)   I hope this helps!!!
Good day The following problem: I load data into Splunk once a week. However, not always on the same day. I now want to show a trend to last week on a dashboard, but the span option must fit to the... See more...
Good day The following problem: I load data into Splunk once a week. However, not always on the same day. I now want to show a trend to last week on a dashboard, but the span option must fit to the day. Is there a way that the span option automatically adjusts to the next date where there is data? Or do you have another suggestion how I can solve the problem? Currently, if the span does not fit exactly, I have an increase of 100%. My current search query is very basic: index=test CVSS_v3_Severity=$severity_tok$ Operating_System_Generation=$os_dd_tok$ | dedup CVE | timechart span=7d count Thanks in advance and best regards Nico
Hi. i have a search a show a graphchart for 14 months. If i change the timepicker it still shows 14 months for some reason. As you can see  in the picture, the time picker says 30 days, but the gr... See more...
Hi. i have a search a show a graphchart for 14 months. If i change the timepicker it still shows 14 months for some reason. As you can see  in the picture, the time picker says 30 days, but the graph still shows 14 months. What gives? Also, is there a way to display a trendline on the graph? If i use the | trendline sma10(Cores) or the like, it changes the graph instead of just showing a linear line
Please share the complete event which is not working for you (anonymised of course). Please use a code block </> so the formatting and special characters are preserved.
@ITWhisperer @Whatever you provided rex expression is not fetching the values 
Have you tried my suggestion on your actual events? (You don't need to include the lines which attempt to set up sample data based on the example you posted.)
Hi @Thulasinathan_M , good for you, see next time! let me know if I can help you more, or, please, accept one answer for the other people of Community. Ciao and happy splunking Giuseppe P.S.: Ka... See more...
Hi @Thulasinathan_M , good for you, see next time! let me know if I can help you more, or, please, accept one answer for the other people of Community. Ciao and happy splunking Giuseppe P.S.: Karma Points are appreciated
Can someone please help to fetch the other fields like groupByUser?  
@ssharm223 One thing that may be worth trying is adding the app to your connection parameters. I get a different error when I do this and it may simply be that my permissions aren't set up correctly.
@ssharm223 did you ever get an answer to this? Guessing no? I'm having the same issue with accessing a csv lookup that I can access via the web UI, however attempting to access it via API gets me: N... See more...
@ssharm223 did you ever get an answer to this? Guessing no? I'm having the same issue with accessing a csv lookup that I can access via the web UI, however attempting to access it via API gets me: Non-result: ERROR The lookup table 'asset_lookup-by_str' requires a .csv or KV store lookup definition.. However changing the search to "|inputlookup asset_lookup-by_str.csv" still gets me: Non-result: ERROR The lookup table 'asset_lookup-by_str.csv' requires a .csv or KV store lookup definition.. I suspect there is some combination of non-filesystem access and non-default csv locations that means we are SOL, but happy to be proven wrong by the brains trust!
So, we can;t make a regex on search to fetch the fields values ?
After resetting token, it started working. Thanks!!
It needs a longer explanation. I believe long time ago the things were as you tried to set them up - the events were distinguishable by sourcetypes. But since there is no actual need to treat them as... See more...
It needs a longer explanation. I believe long time ago the things were as you tried to set them up - the events were distinguishable by sourcetypes. But since there is no actual need to treat them as separate sourcetypes (sourcetype defines how the data is processed - ingested and parsed) because the data is in the same format regardless of which particular EventLog channel it came from and having separate sourcetypes for each EventLog  channel would mean that you'd need to define settings for each new channel you ingest (and you can pull any of the channels you see in your EventLog!). So there was a shift in the approach to windows events (and it happened looooong time ago). And in order to accomodate all those forwarders installed long time ago and still working with old defaults (configured as you tried to set it up), there are transforms in TA_windows which "normalize" the sources and sourcetypes. This is from default/transforms.conf: ## Setting generic sourcetype and unique source [ta-windows-fix-classic-source] DEST_KEY = MetaData:Source REGEX = (?m)^LogName=(.+?)\s*$ FORMAT = source::WinEventLog:$1 [ta-windows-fix-xml-source] DEST_KEY = MetaData:Source REGEX = <Channel>(.+?)<\/Channel>.* FORMAT = source::XmlWinEventLog:$1 [ta-windows-fix-sourcetype] SOURCE_KEY = MetaData:Sourcetype DEST_KEY = MetaData:Sourcetype REGEX = sourcetype::([^:]*) FORMAT = sourcetype::$1 Even if you explicitly configure your inputs to provide source and sourcetype "old style" the transforms will get invoked during indexing an will overwrite the metadata fields to the "new style". So all windows EventLog-sourced events are of either WinEventLog sourcetype or XmlWinEvenLog one (depending on whether you ingest them as "classic" or XML).