Splunk Search

Splunk Search
Community Activity
clv1clv1
All- I am new to Splunk and trying to figure out how to return a matched term from a CSV table with inputlookup. I j...
by clv1clv1 Explorer in Splunk Search 12-18-2017
1 15
1
15
chitreshakumar
I have an average duration field which has months ,days ,hours and minutes.I want it to be sorted descending order -M...
by chitreshakumar Communicator in Splunk Search 12-18-2017
0 2
0
2
jbdumoulin
Hello splunkers ! Today I'm building a report, in which I'm tasked to exclude some specific results. These are typic...
by jbdumoulin Engager in Splunk Search 12-18-2017
0 2
0
2
sunnyparmar
Hi All, I am executing query which is giving me the below result and I want to shorten the data and show in table fo...
by sunnyparmar Communicator in Splunk Search 12-18-2017
0 3
0
3
robertlynch2020
Hi I have a Maths problem that i am hoping Splunk has a function for. It is in relation to calculation the % of tim...
by robertlynch2020 Influencer in Splunk Search 12-18-2017
0 6
0
6
mikaelbje
I'm trying to create a timeline using the Timeline Custom Visualization of future or historical saved searches in ord...
by mikaelbje Motivator in Splunk Search 12-18-2017
0 4
0
4
ashiqm
While making Splunk search using Java SDK, is there any way to provide event sampling value into the query. There ar...
by ashiqm Explorer in Splunk Search 12-18-2017
0 1
0
1
jvmerilla
Hi, Is it possible to reformat the _time, for example, remove the day so only the month and the year will remain? I...
by jvmerilla Path Finder in Splunk Search 12-17-2017
0 11
0
11
rajashekar_s
I am trying to match a field A from base query with a kv store lookup to get field B from lookup. Apparently there ar...
by rajashekar_s Path Finder in Splunk Search 12-17-2017
0 2
0
2
zacksoft
This is the algorithm of my query. Could someone help me in constructing it. If (A happens) { Then ( Exec...
by zacksoft Contributor in Splunk Search 12-17-2017
0 14
0
14
sagar1905
I'm trying to divide my query into two parts, D>8000 as X and D<=8000 as Y, so i put it .... my search | eval count(i...
by sagar1905 New Member in Splunk Search 12-17-2017
0 7
0
7
ntalwar
Can someone help me converting 1513554224 into readable time format. I tried couple of formats but not working. I am...
by ntalwar New Member in Splunk Search 12-17-2017
0 4
0
4
leagawa
I have a lookup table of AD accounts lookup table fields CN, DisplayName, passwordlastset, pwdlasts...
by leagawa New Member in Splunk Search 12-17-2017
0 1
0
1
christopheryu
Sorry, this is more of a regex question but can't figure it out myself. I would like to extract a string preceded by ...
by christopheryu Communicator in Splunk Search 12-17-2017
0 4
0
4
Deepz2612
Hi , For logs such as below please help me in extracting the data enclosed within double quotes. Contact Dealership...
by Deepz2612 Explorer in Splunk Search 12-17-2017
0 4
0
4
splunknoob408
I've got a date field that I extracted from log messages, and it is pulled from two different sources. One source ze...
by splunknoob408 Explorer in Splunk Search 12-16-2017
0 4
0
4
johndoe23
Hi, I have to analyse a call-centre log. Here’s a brief description if the scenario. There’s a telephone line called...
by johndoe23 Engager in Splunk Search 12-16-2017
0 3
0
3
DataOrg
000220170822013085255 017 AWS not associated with salary Number ASSD-BUS-0000 1 000220170822013085259 017 AWS not a...
by DataOrg Builder in Splunk Search 12-16-2017
0 6
0
6
dernst
Hi Guys, I am new to Splunk and regex and trying to extract a given field plus its value. So in the example below,...
by dernst New Member in Splunk Search 12-16-2017
0 3
0
3
Ovi
I have a multisite indexer cluster with one SH I configured automated GeoIP2-City Maxmind DB (paid subscription) down...
by Ovi Path Finder in Splunk Search 12-16-2017
1 1
1
1
daniel333
All, I am looking to create a single timechart which displays the count of status by requestcommand by action. So t...
by daniel333 Builder in Splunk Search 12-15-2017
0 2
0
2
efavreau
Let's say you have 100 events, and each one increases in duration by 1 second. So event 1 is 1 second long and event ...
by efavreau Motivator in Splunk Search 12-15-2017
0 1
0
1
jenniferhao
when I ran a script to access Splunk API , and got this error: Search Factory: Unknown search command '1'. could you...
by jenniferhao Explorer in Splunk Search 12-15-2017
0 8
0
8
tamduong16
I have the following search: index="monthlycdr" "Call Duration"=* Name=\"***\" | eval "Call Duration"=replace('Cal...
by tamduong16 Contributor in Splunk Search 12-15-2017
0 9
0
9
gingyish
*etc* = removed text for anonymity I have a very complex search query that input the following table: Network , Sou...
by gingyish New Member in Splunk Search 12-15-2017
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...