Splunk Search

Splunk Search
Community Activity
WanLohnston
Hi all, I have this query:| timechart span=1s count AS TPS| eventstats max(TPS) as MaxPeakTPS| stats avg(TPS) as avgT...
by WanLohnston Explorer in Splunk Search 12-18-2023
0 4
0
4
LearningGuy
HelloWhen I turned on Total for Statistics under Format > Summary, the output shows long digit after decimal point: T...
by LearningGuy Motivator in Splunk Search 12-18-2023
0 13
0
13
Dharani
Hi,below are the log details.index=ABC sourcetype=logging_0Below are the values of "ErrorMessages" field:invalid - 5 ...
by Dharani Path Finder in Splunk Search 12-18-2023
0 6
0
6
avi7326
This is my source code</search>        <option name="charting.chart">column</option>        <option name="charting.dr...
by avi7326 Path Finder in Splunk Search 12-18-2023
0 3
0
3
Pratyusha
Hi Everyone,I have a column chart for the below query. As shown in the below screenshot, the x-axis label is sorted i...
by Pratyusha Engager in Splunk Search 12-17-2023
0 2
0
2
balcv
I have a search that returns a list of users and the country logins have occurred from grouped by user.index=o365 Use...
by balcv Contributor in Splunk Search 12-17-2023
0 2
0
2
diskioinferno
I have 2 multivalue fields (old and new) containing group lists for 1 or more users. The new values is the list of gr...
by diskioinferno Engager in Splunk Search 12-17-2023
0 3
0
3
Poojitha
Hi All,I am facing error using wildcard in multivalue field. I am using mvfind to find a string.  eval test_loc=case(...
by Poojitha Communicator in Splunk Search 12-16-2023
0 7
0
7
nithys
Hi Team,I am using a query which has same index and source but fetch two results based on the search and combine to a...
by nithys Communicator in Splunk Search 12-16-2023
0 3
0
3
murad
HiKinda a new to splunk . Sending data to splunk via HEC. Its a DTO which contains various fields, one of them being ...
by murad Observer in Splunk Search 12-16-2023
0 3
0
3
mohammadsharukh
Dear All,Scenario--> 1AV server is having multiple endpoint reporting to it. This AV server integrated with Splunk an...
by mohammadsharukh Path Finder in Splunk Search 12-16-2023
0 1
0
1
nkavouris
I have a search as follows:index=*|search sourcetype=*|spath logs{} output=logs|spath serial_number output=serial_num...
by nkavouris Path Finder in Splunk Search 12-15-2023
0 2
0
2
GaetanVP
Hello Splunkers,I have a Splunk HF that will receive multiple logs coming from different machines, all sending via UD...
by GaetanVP Contributor in Splunk Search 12-15-2023
1 4
1
4
Satheesh_red
I have a Splunk result like below.VMcol1col2vm1carsedanvm2carsedanvm3planePrivvm4bikeFazervm5bikethunder I would like...
by Satheesh_red Path Finder in Splunk Search 12-15-2023
0 10
0
10
the_dude
index=jedi domain="jedi.lightside.com" (master!="yoda" AND master!="mace" AND master="Jinn") | table saber_color, J...
by the_dude Engager in Splunk Search 12-15-2023
0 8
0
8
suvi6789
Hi, I need help in a splunk search. My requirement is get the stats for failed and successful count along with the pe...
by suvi6789 Path Finder in Splunk Search 12-14-2023
0 5
0
5
jbanAtSplunk
Hi, I have Windows Event for specific application that have payload in Windows Event Log, when using Splunk_TA_window...
by jbanAtSplunk Communicator in Splunk Search 12-14-2023
0 3
0
3
smanojkumar
Hi There!   I would like to find the values of host that were in macro 1 but not in macro 2search 1 `macro 1` | field...
by smanojkumar Contributor in Splunk Search 12-14-2023
0 7
0
7
anandhalagaras1
Hi All,Need a help to write a query based on the field "Timestamp" which is different from "_time" value.Sample Event...
by anandhalagaras1 Contributor in Splunk Search 12-14-2023
0 5
0
5
Siddharthnegi
| table Status, timeval, CompanyCode, CN|appendpipe [stats count| eval error="thats not cool" | where count==0 |table...
by Siddharthnegi Contributor in Splunk Search 12-14-2023
0 7
0
7
EricMonkeyKing
Hi all,For this sort of json string, how can I extract KeyA, KeyB, KeyC? { "KeyA": [ { "path": "/attibuteA", "op": "r...
by EricMonkeyKing Explorer in Splunk Search 12-14-2023
0 5
0
5
duesser
 I have a multivalue field, which I would like to expand to individual fields, like so:| makeresults count=1 | eval a...
by duesser Path Finder in Splunk Search 12-14-2023
0 4
0
4
KingUs80
I'm currently working on crafting a Splunk Query to identify systems that have been inactive for a specified duration...
by KingUs80 Loves-to-Learn Lots in Splunk Search 12-13-2023
0 2
0
2
varsh_6_8_6
HiI am trying to see for a ticket that is not assigned to an analyst for the last 15 mins from the time of arrival. I...
by varsh_6_8_6 Explorer in Splunk Search 12-13-2023
0 1
0
1
nkavouris
Hello Splunkers,I am New to Splunk and am trying to figure out how to parse nested JSON data spit out by an end-of-li...
by nkavouris Path Finder in Splunk Search 12-13-2023
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...