Splunk Search

Splunk Search
Community Activity
john_glasscock
Our Splunk instance is being overhauled and I need to update all of the content that has been built. We have some in...
by john_glasscock Path Finder in Splunk Search 01-30-2024
1 13
1
13
PavelP
Hello,I'm looking of your insights to pinpoint changes in fields over time. Events structured with timestamp, ID, and...
by PavelP Motivator in Splunk Search 01-30-2024
0 11
0
11
jeradb
My current serach is -  | from datamodel:Remote_Access_Authentication.local | append [| inputlookup Domain | rename n...
by jeradb Explorer in Splunk Search 01-30-2024
0 1
0
1
of
Hi,I want to create a search query that looks for users who have received phishing emails, clicked the link, or downl...
by of New Member in Splunk Search 01-30-2024
0 4
0
4
Shihua
Hi everyone,I would want to ask if I can create a field alias for _indextime and _time then set this alias as a defau...
by Shihua Engager in Splunk Search 01-30-2024
0 2
0
2
willadams
I have a very basic dashboard that requires my users to put in text inputs.  These inputs are then outputted to a CSV...
by willadams Contributor in Splunk Search 01-29-2024
0 3
0
3
secphilomath1
Here is my sample data; start=Dec 30 2023 06:07:47 duser=NT AUTHORITY\SYSTEM dvc=10.163.142.37I need to extract the f...
by secphilomath1 Explorer in Splunk Search 01-29-2024
0 9
0
9
bhavesh0124
Hi, I want to get rid of columns which have single unique value. There could be multiple columns showing this behavio...
by bhavesh0124 Explorer in Splunk Search 01-29-2024
0 3
0
3
ghostrider
I am trying to filter my search results where only a particular subset of the results should be shown. Example suppos...
by ghostrider Path Finder in Splunk Search 01-29-2024
0 1
0
1
man03359
I am noob with Splunk.I am trying to join two indexes in one search -index="idx-enterprise-tools" sourcetype="spectru...
by man03359 Communicator in Splunk Search 01-29-2024
0 3
0
3
SleepyGuy
Hi,I'm after some assistance.I am trying to capture the peak number of concurrent users in a single minute block usin...
by SleepyGuy Engager in Splunk Search 01-29-2024
0 3
0
3
ramkyreddy
When I was searching  for the different data ranges in my Splunk dashboard it showed the same,for example, i am selec...
by ramkyreddy Explorer in Splunk Search 01-29-2024
0 5
0
5
paolos
Why oneidentity override dnslookup transform   changing the parameters name ? from clientip to ip , from clienhost to...
by paolos Loves-to-Learn Everything in Splunk Search 01-29-2024
0 2
0
2
clamarkv
Hi, Im trying to create a dashboard that easily presents api endpoint performance metrics I am generating a summary i...
by clamarkv Explorer in Splunk Search 01-28-2024
0 1
0
1
Splunkanator
Lets say i would like to query for message that has a URL field with values other than X,Y,Z added as query parameter...
by Splunkanator New Member in Splunk Search 01-27-2024
0 2
0
2
yuvrajsharma_13
I am joining two splunk query to capture the  values which is not present in subquery. Trying to find the account whi...
by yuvrajsharma_13 Explorer in Splunk Search 01-27-2024
0 2
0
2
LearningGuy
Hello,How to pass data/token from a report to another report?   Thank you for your helpI am trying to run a weekly re...
by LearningGuy Motivator in Splunk Search 01-27-2024
0 3
0
3
zach-keener
We need to extract the value behind "<Computer>" I have underlined it to make it easier.  It would also be beneficial...
by zach-keener Explorer in Splunk Search 01-26-2024
0 2
0
2
jeradb
My current search is -  | tstats count AS event_count WHERE index=* BY host, _time span=1h| append [ | inputlookup Do...
by jeradb Explorer in Splunk Search 01-26-2024
0 1
0
1
LearningGuy
Hello,How do I create bar chart using two fields and keep all fields in the statistical table?The column chart automa...
by LearningGuy Motivator in Splunk Search 01-26-2024
0 8
0
8
nlloyd
Hi all,Very new to Splunk so apologies if this is a very basic question. I've looked around and haven't found a concl...
by nlloyd Engager in Splunk Search 01-26-2024
0 2
0
2
selvam_sekar
Hi, I have below SPL, which return todays count vs yesterday count and difference between them. I want to see, if i r...
by selvam_sekar Path Finder in Splunk Search 01-26-2024
0 3
0
3
LearningGuy
How to correlate index with dbxquery with condition or interation?See the sample below.   Thank you for your help.ind...
by LearningGuy Motivator in Splunk Search 01-25-2024
0 2
0
2
splguy
I have events with an array field named "tags".  The tags array has 2 fields for each array object named "name" and "...
by splguy Engager in Splunk Search 01-25-2024
0 2
0
2
Sunny
HiUsing following query:`mbp_ocp4` kubernetes.container.name =*service* level=NG_SERVICE_PERFORMANCE SERVICE!=DPTDRet...
by Sunny Observer in Splunk Search 01-25-2024
0 3
0
3
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...