Splunk Search

Splunk Search
Community Activity
of
Hi,I need help generating search queries using SPL, especially in my new role as a SOC Analyst. I would like to know ...
by of New Member in Splunk Search 12-27-2023
0 1
0
1
yolk
Hi,I have data like these entrieslink          id                     parent     name----          ---               ...
by yolk Observer in Splunk Search 12-26-2023
0 3
0
3
HPACHPANDE
(index=123) sourcetype=XYZ AND type IN ("SERVICE_STOP") )  | _time host type _raw  is the main query where we are sea...
by HPACHPANDE Explorer in Splunk Search 12-25-2023
0 2
0
2
krutika_ag
Hi,There are a lot of clients in my architecture and every other splunk instance is deployed in either /opt/bank/splu...
by krutika_ag Path Finder in Splunk Search 12-24-2023
0 4
0
4
Jason
What is the difference between the NOT operator and the != operator? I have always used NOT up to this point, but am...
by Jason Motivator in Splunk Search 12-22-2023
3 5
3
5
t_splunk_d
I want to get the result of the next line of the log message when I encounter  a key word.Example log:----error in ch...
by t_splunk_d Path Finder in Splunk Search 12-22-2023
0 4
0
4
MGlass
I am running the current search using the network toolkit but will not show the hostname field from the csv, do I nee...
by MGlass Explorer in Splunk Search 12-22-2023
0 2
0
2
GIA
hello I am pretty new using Splunk and I am being tasked to generate multiple of these kinds of reports in Splunk (or...
by GIA Path Finder in Splunk Search 12-21-2023
0 5
0
5
yuvaraj_m91
index="********"message_type =ERROR correlation_id="*"| eval err_field1 = spath(_raw,"response_details.body")| eval e...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 12-21-2023
0 2
0
2
quangnm21
This was my initial search. I cannot compare the two fields "srcdomain = destdomain" because when I intend to use eva...
by quangnm21 Explorer in Splunk Search 12-21-2023
0 3
0
3
Mr_Adate
Hello Friends, I need your help to find out matching fields values and their total count by comparing from two differ...
by Mr_Adate Explorer in Splunk Search 12-20-2023
0 9
0
9
indeed_2000
Hihow can I download splunk apm on premises? FYI: I don’t want use cloud version   Thanks 
by indeed_2000 Motivator in Splunk Search 12-20-2023
0 6
0
6
eholz1
Hello All,I have a search question. I have a csv file that returnds data.the ID field if there is no data - I want to...
by eholz1 Builder in Splunk Search 12-20-2023
0 3
0
3
indeed_2000
HiWhat is the different between Extract fields in query with rex or in config file.Pros and cons?how about performanc...
by indeed_2000 Motivator in Splunk Search 12-20-2023
0 4
0
4
youngsuh
Hi, communities,I am doing a calculation or eval command.    | eval dormancy=if(last_login="(never)",round((now()-str...
by youngsuh Contributor in Splunk Search 12-20-2023
0 1
0
1
nyajoefit22
Hello,I am trying to blacklist winevent code 4679 by   TaskCategory=Kerberos Service Ticket Operations. This regex is...
by nyajoefit22 Loves-to-Learn Lots in Splunk Search 12-20-2023
0 3
0
3
shruti14
Hi,So i have below base query :| inputlookup abc.csv where DECOMMISSIONED=N | fields DATABASE DB_VERSION APP_NAME ACT...
by shruti14 Explorer in Splunk Search 12-20-2023
0 1
0
1
mnj1809
Hello, I know that  mvsort command sort values lexicographically.But I want the output as below:62.0.3.7563.0.3.8475....
by mnj1809 Path Finder in Splunk Search 12-20-2023
0 9
0
9
Questioner
I try to make box plot graph using <viz>However, My code have this error,"Error in 'stats' command: The number of wil...
by Questioner Path Finder in Splunk Search 12-19-2023
0 2
0
2
mark_groenveld
I have a key called messageInside the value are several results but I need to only extract one result in the middle o...
by mark_groenveld Path Finder in Splunk Search 12-19-2023
0 2
0
2
michaeler
I'm trying to have a timechart showing the count of events by a category grouped by week. The search time is controll...
by michaeler Communicator in Splunk Search 12-19-2023
0 3
0
3
El_Franco
I have an index set up that holds a number of fields, one of which is a comma separated list of reference numbers and...
by El_Franco Explorer in Splunk Search 12-19-2023
0 3
0
3
ramkyreddy
this is my end_time: 1703027679.5678809After this query, it showed this output but i am getting the 1969 format| eval...
by ramkyreddy Explorer in Splunk Search 12-19-2023
0 1
0
1
ramkyreddy
TC Execution Summary for Last QuarterNo. of job runsAUSJERINDASIAugust150121110200Sept200140150220Oct100160130420I wa...
by ramkyreddy Explorer in Splunk Search 12-19-2023
0 4
0
4
riz1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...