Splunk Search

Splunk Search
Community Activity
scknogas
Okay, I think I'm losing my mind with trying to work with the formatting of multivalue outputs... Let's say I have a...
by scknogas Path Finder in Splunk Search 04-22-2018
0 5
0
5
slander00
I am having an issue trying to get the group name for windows security event ID 4765. I am a little new to using reg...
by slander00 Explorer in Splunk Search 04-22-2018
0 3
0
3
IRHM73
Hi, I'm wondering whether someone may be able to help me please. I'm using the following to extract metrics for a nu...
by IRHM73 Motivator in Splunk Search 04-22-2018
0 8
0
8
daniel333
All, I have a log file which produces a MD5sum every hour or so. I'd like to compare the most recent event, with th...
by daniel333 Builder in Splunk Search 04-22-2018
0 2
0
2
pswalia06
{"runDate":"2018-04-18T00:31:46 EDT","dataDate":"20180319","jobName":"experianCounters","counterList":[{"counterName"...
by pswalia06 Explorer in Splunk Search 04-22-2018
0 6
0
6
BrandonKeep
I have a search that returns correct results. However, the join subsearch portion is constantly hitting the max 50000...
by BrandonKeep Explorer in Splunk Search 04-22-2018
0 4
0
4
n4niyaz
how to remove start and last character from field value please find the example below Example test=road-car test=a_...
by n4niyaz Explorer in Splunk Search 04-22-2018
0 4
0
4
amuralisundaram
I had 3 columns initially in the csv file. I added two more and added the same in the inputlookup command. But no tab...
by amuralisundaram Engager in Splunk Search 04-22-2018
0 3
0
3
erichard
Hello, I receive message like this : topic="Sniffer" message=""timestamp"="1524387631351","process"="com.x.android...
by erichard Explorer in Splunk Search 04-22-2018
0 2
0
2
Chandras11
HI All, I need to search two sourcetypes and multiple fields at the same time. Following query is working correctly...
by Chandras11 Communicator in Splunk Search 04-22-2018
0 2
0
2
dannyzen
What is the best way to use fillnull for multiple fields? What is the best way to avoid it working for only the first...
by dannyzen Explorer in Splunk Search 04-22-2018
0 4
0
4
alangularte
How can I get all the float values that are between the strings "totalElapsedTime^" and "^" from the log sample bello...
by alangularte New Member in Splunk Search 04-22-2018
0 3
0
3
splunkrocks2014
Hi. How to use Splunk query to compare to the "count" field from previous day from a lookup table? For instance, t...
by splunkrocks2014 Communicator in Splunk Search 04-21-2018
0 3
0
3
n4niyaz
following are the output of a filed file=a.csv file=a1.csv file=a2.csv file=b.csv file=b1.csv What i required is w...
by n4niyaz Explorer in Splunk Search 04-21-2018
0 4
0
4
baoamin
hello guys I have a problem at work index=mailog relay=10.204.0.0 I timechart span=1h count I timechart span=1d m...
by baoamin New Member in Splunk Search 04-21-2018
0 12
0
12
logloganathan
Could you please explain the difference between dedup and unique
by logloganathan Motivator in Splunk Search 04-20-2018
0 4
0
4
nqjpm
Description field parsing data from has some unnecessary survey data that I would like to ignore and NOT count. That ...
by nqjpm Path Finder in Splunk Search 04-20-2018
0 4
0
4
Athildjax64
I have a custom action alert based on an App The search is looking for a file, event, and file type. it then pipes th...
by Athildjax64 New Member in Splunk Search 04-20-2018
0 2
0
2
mcbradford
Need help with key value extraction for the following: Apr 20 10:38:59 10.1.8.25 {"adf": 1, "virtualservice": "virtu...
by mcbradford Contributor in Splunk Search 04-20-2018
0 2
0
2
sh254087
I am applying few conditions and logic to come up with values for different fields. I'm then displaying them using te...
by sh254087 Communicator in Splunk Search 04-20-2018
0 10
0
10
jerrythoms
I have two types of logs in an index. Both can have multiple entries for a ip address. What i need to do is find all...
by jerrythoms Explorer in Splunk Search 04-20-2018
0 5
0
5
kmaron
I've figured out how to use the match condition to use a wildcard in my eval, however now I need to put at NOT with i...
by kmaron Motivator in Splunk Search 04-20-2018
0 6
0
6
oustinov
trying to extract a fields from logfile's text (have both examples in logfile): search sourcetype=apache "/apps/publ...
by oustinov New Member in Splunk Search 04-20-2018
0 11
0
11
Splunk_rocks
Hello Splunkers, Im constructing Eval field " user1" actually user field contain 5 digit number so i have to const...
by Splunk_rocks Path Finder in Splunk Search 04-19-2018
0 4
0
4
Kwip
Hi All, I want to compare three fields value(may be) to arrive at new field. (mentioned 3 as it may require to compar...
by Kwip Contributor in Splunk Search 04-19-2018
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...