Splunk Search

Splunk Search
Community Activity
bryansocito
Hi Everyone, I have the query below and it works, however I would like to add the time spend on each website/domain ...
by bryansocito New Member in Splunk Search 04-09-2018
0 1
0
1
mauricio2354
I have the following query: index=source sourcetype=type_example | bin _time span=5m| eval TIME=strftime(_time,"%D:...
by mauricio2354 Explorer in Splunk Search 04-09-2018
0 2
0
2
AlexeySh
Hello, I use a dbxquery to import asset’s tags which includes information about asset’s category, business unit and ...
by AlexeySh Communicator in Splunk Search 04-09-2018
0 4
0
4
dannestor
I am running the following search: "authentication failed" | stats count by user, sourceip | sort -count | head 10 ...
by dannestor Explorer in Splunk Search 04-09-2018
0 4
0
4
aqudoos
I have two different fields in logs coming from the same device. I want to count that stats for both fields by using ...
by aqudoos Explorer in Splunk Search 04-09-2018
0 6
0
6
surekhasplunk
Hi, I want to extract below fields First 5 fields are automatically extracted by splunk witihout any issues. But la...
by surekhasplunk Communicator in Splunk Search 04-09-2018
0 10
0
10
payal23
Want to add the below logic in the datamodel and use with tstats | eval _raw=replace(_raw,"\","null") |rex "Network...
by payal23 Path Finder in Splunk Search 04-08-2018
0 2
0
2
johnsasikumar
Am running the calling the query from and SDK. Splunk returns results in Verbose mode. But it does not return results...
by johnsasikumar Path Finder in Splunk Search 04-08-2018
0 1
0
1
vshakur
Hello, Is it possible to set a drill-down condition only for the cells of a specific column but to exclude one cell....
by vshakur Path Finder in Splunk Search 04-08-2018
0 9
0
9
vshakur
Hello, In my Splunk dashboard I have a table that contains the following: <table> <search> <query> ...
by vshakur Path Finder in Splunk Search 04-07-2018
0 2
0
2
EricLloyd79
I have a Python script that runs Splunk queries. Another team at my company changed their fields to have many, many p...
by EricLloyd79 Builder in Splunk Search 04-06-2018
0 9
0
9
faol
When running a search which takes longer than a couple of seconds to complete, I suddenly see the following error mes...
by faol Explorer in Splunk Search 04-06-2018
1 1
1
1
OldManEd
I inherited a search that contains he following line; [| inputlookup <lookup table name> | format ] and I can't fi...
by OldManEd Builder in Splunk Search 04-06-2018
0 3
0
3
king2jd
Hello, Here is what my dns queries are being indexed as. I am looking for a search time regex that will extract the ...
by king2jd Path Finder in Splunk Search 04-06-2018
0 5
0
5
bgill0123
I currently have two searches that produce two different numbers: |metadata type=hosts |search host=abc1* or host=abc...
by bgill0123 Loves-to-Learn in Splunk Search 04-06-2018
0 4
0
4
apezuela
Hi, Is there any limit for field value for transaction command? I am executing transaction command over Security_ID...
by apezuela Explorer in Splunk Search 04-06-2018
0 3
0
3
bgill0123
I am currently running this search: index=events host=hig1* or host=hig2* | timechart span-1d dc(host) the search ...
by bgill0123 Loves-to-Learn in Splunk Search 04-06-2018
0 2
0
2
christopheducha
Hello I'm a splunk newbie, be gentle please. I'm try to monitoring my VPNs status with splunk, unfortunately my fire...
by christopheducha Explorer in Splunk Search 04-06-2018
0 5
0
5
cyler
I would like to know how to search for all computers that are reporting to Splunk in the last 30 day. Thank you
by cyler New Member in Splunk Search 04-06-2018
0 7
0
7
manapuna
basic search | timechart span = 5m count by host | where count > 3 for today 10% of the time,the count is greater th...
by manapuna New Member in Splunk Search 04-06-2018
0 3
0
3
brettcave
Is there any way possible to restrict searches based on source IP of splunk user? Current environment is Splunk Ente...
by brettcave Builder in Splunk Search 04-06-2018
0 7
0
7
Hemnaath
Hi All, We are facing an data parsing issue with the check point firewall logs. Problem Details : index=firewall...
by Hemnaath Motivator in Splunk Search 04-06-2018
0 6
0
6
msarro
Hey everyone. I am working with telephone records, and am trying to work around Splunk's inability to search for lite...
by msarro Builder in Splunk Search 04-06-2018
0 2
0
2
krishnab
Hi , I have a macro which gets values including host,now i do a left join .Once i do a left join in the subsearch on...
by krishnab Path Finder in Splunk Search 04-05-2018
0 2
0
2
bntdumas
Hello, I'm trying to get the sum of days where no events occurred by a city name. I found the following answer (htt...
by bntdumas Engager in Splunk Search 04-05-2018
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...