Splunk Search

Splunk Search
Community Activity
klim
Is it possible to store regex patterns in a lookup table so that it can be used in a search?For example lets say I ha...
by klim Path Finder in Splunk Search 01-02-2024
0 4
0
4
Poojitha
Hi All,I have a multivalue field that contains nested key value pair with key named as "Key" and Value named as "Valu...
by Poojitha Communicator in Splunk Search 01-02-2024
0 4
0
4
Naveen_4025
Hello Everyone,I'm attempting to search for queries in Splunk Free Edition. However, it worked well for some time, an...
by Naveen_4025 New Member in Splunk Search 01-02-2024
0 3
0
3
svodela
We are trying to create a dashboard to understand the usage of our application version something like shown belowAppl...
by svodela Explorer in Splunk Search 01-02-2024
0 6
0
6
krutika_ag
Hi All, There are 50 zip files in a folder in those zip folders there are many other files- log/txt/png, out of which...
by krutika_ag Path Finder in Splunk Search 01-01-2024
0 4
0
4
p0r049z
I am new to splunk queries and was trying to combine results from multiple queries without using subsearches due to i...
by p0r049z Engager in Splunk Search 01-01-2024
0 5
0
5
bhava2704
Namepercdatexxx9028-Dec-23yyy9128-Dec-23zzz9228-Dec-23xxx9629-Dec-23yyy9729-Dec-23zzz9829-Dec-23 i want to calculate ...
by bhava2704 New Member in Splunk Search 12-31-2023
0 4
0
4
jhooper33
Hi Team/Community,I'm having an issue with a lookup file. I have a csv with two columns, 1st is named ioc and second ...
by jhooper33 Explorer in Splunk Search 12-31-2023
0 14
0
14
AC1
Hi all,I am trying to put together a search and stats table for users in our environment who have uploaded data to a ...
by AC1 Engager in Splunk Search 12-29-2023
0 4
0
4
bcanfield83
Hi All,This may be a bit of a peculiar question, but I'm trying to figure out if there's a way to use a certain expre...
by bcanfield83 Engager in Splunk Search 12-29-2023
0 2
0
2
xxxxxxxxxxxxxx
I am trying to generate a list of the percentages of response codes by resultCode by app.  A simplified version of ev...
by xxxxxxxxxxxxxx Explorer in Splunk Search 12-29-2023
0 8
0
8
beepbop
hi, how can I change the scheduled index time of a data source?
by beepbop Explorer in Splunk Search 12-28-2023
0 1
0
1
SplunkDash
Hello, Line breaker in my props configuration for the json formatted file is not working, it's not breaking the json ...
by SplunkDash Motivator in Splunk Search 12-28-2023
0 2
0
2
HPACHPANDE
Lookup 1  : Contains fields such as  AssetName  FQDN and IP AddressLookup 2 :  Contains fields such as Host Index and...
by HPACHPANDE Explorer in Splunk Search 12-28-2023
0 1
0
1
akselsoeb
Hello guysI need some help with making a table/dashboard that shows me changes to incidents in our Defender platform....
by akselsoeb Engager in Splunk Search 12-28-2023
0 2
0
2
Pat
I have tried to use the following eval to pretty up the return of a field but the result is always test.  I have trie...
by Pat Path Finder in Splunk Search 12-27-2023
0 11
0
11
Dipti
Hi,I have a botsv1 dataset uploaded in Splunk simulated environment. But when I search "index=botsv1" , it returns 0 ...
by Dipti Explorer in Splunk Search 12-27-2023
0 4
0
4
jason_hotchkiss
I have the follow time:EPOCH HUMAN READABLE170363091912/26/2023 19:48:39I would like to convert the EPOCH to CST time...
by jason_hotchkiss Communicator in Splunk Search 12-27-2023
0 3
0
3
Nagalakshmi
Hi Team,Need your assistant for below  We have created new csv lookup and we are using the below query but we are get...
by Nagalakshmi Path Finder in Splunk Search 12-27-2023
0 2
0
2
quangnm21
Hello everyone, I'm a beginner in using Splunk. I'm facing an issue in finding a search solution for the following id...
by quangnm21 Explorer in Splunk Search 12-27-2023
0 4
0
4
Assaf_Katz
Hi, I have the following transforms.conf: [REPLACEMENT_COST] CLEAN_KEYS = 0 FORMAT = $1"REPLACEMENT_COST2":"$2$s"$3 R...
by Assaf_Katz Loves-to-Learn in Splunk Search 12-27-2023
0 2
0
2
of
Hi,I need help generating search queries using SPL, especially in my new role as a SOC Analyst. I would like to know ...
by of New Member in Splunk Search 12-27-2023
0 1
0
1
yolk
Hi,I have data like these entrieslink          id                     parent     name----          ---               ...
by yolk Observer in Splunk Search 12-26-2023
0 3
0
3
HPACHPANDE
(index=123) sourcetype=XYZ AND type IN ("SERVICE_STOP") )  | _time host type _raw  is the main query where we are sea...
by HPACHPANDE Explorer in Splunk Search 12-25-2023
0 2
0
2
krutika_ag
Hi,There are a lot of clients in my architecture and every other splunk instance is deployed in either /opt/bank/splu...
by krutika_ag Path Finder in Splunk Search 12-24-2023
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...