Splunk Search

Splunk Search
Community Activity
MirrorCraze
I have a data like this.{     ...   name: AppName   metrics: {<!-- -->     data: [       {          details: { ...         } ...
by MirrorCraze Explorer in Splunk Search 12-18-2023
0 5
0
5
WanLohnston
Hi all, I have this query:| timechart span&#61;1s count AS TPS| eventstats max(TPS) as MaxPeakTPS| stats avg(TPS) as avgT...
by WanLohnston Explorer in Splunk Search 12-18-2023
0 4
0
4
LearningGuy
HelloWhen I turned on Total for Statistics under Format &gt; Summary, the output shows long digit after decimal point: T...
by LearningGuy Motivator in Splunk Search 12-18-2023
0 13
0
13
Dharani
Hi,below are the log details.index&#61;ABC sourcetype&#61;logging_0Below are the values of "ErrorMessages" field:invalid - 5 ...
by Dharani Path Finder in Splunk Search 12-18-2023
0 6
0
6
avi7326
This is my source code&lt;/search&gt;        &lt;option name&#61;"charting.chart"&gt;column&lt;/option&gt;        &lt;option name&#61;"charting.dr...
by avi7326 Path Finder in Splunk Search 12-18-2023
0 3
0
3
Pratyusha
Hi Everyone,I have a column chart for the below query. As shown in the below screenshot, the x-axis label is sorted i...
by Pratyusha Engager in Splunk Search 12-17-2023
0 2
0
2
balcv
I have a search that returns a list of users and the country logins have occurred from grouped by user.index&#61;o365 Use...
by balcv Contributor in Splunk Search 12-17-2023
0 2
0
2
diskioinferno
I have 2 multivalue fields (old and new) containing group lists for 1 or more users. The new values is the list of gr...
by diskioinferno Engager in Splunk Search 12-17-2023
0 3
0
3
Poojitha
Hi All,I am facing error using wildcard in multivalue field. I am using mvfind to find a string.  eval test_loc&#61;case(...
by Poojitha Communicator in Splunk Search 12-16-2023
0 7
0
7
nithys
Hi Team,I am using a query which has same index and source but fetch two results based on the search and combine to a...
by nithys Communicator in Splunk Search 12-16-2023
0 3
0
3
murad
HiKinda a new to splunk . Sending data to splunk via HEC. Its a DTO which contains various fields, one of them being ...
by murad Observer in Splunk Search 12-16-2023
0 3
0
3
mohammadsharukh
Dear All,Scenario--&gt; 1AV server is having multiple endpoint reporting to it. This AV server integrated with Splunk an...
by mohammadsharukh Path Finder in Splunk Search 12-16-2023
0 1
0
1
nkavouris
I have a search as follows:index&#61;*|search sourcetype&#61;*|spath logs{} output&#61;logs|spath serial_number output&#61;serial_num...
by nkavouris Path Finder in Splunk Search 12-15-2023
0 2
0
2
GaetanVP
Hello Splunkers,I have a Splunk HF that will receive multiple logs coming from different machines, all sending via UD...
by GaetanVP Contributor in Splunk Search 12-15-2023
1 4
1
4
Satheesh_red
I have a Splunk result like below.VMcol1col2vm1carsedanvm2carsedanvm3planePrivvm4bikeFazervm5bikethunder I would like...
by Satheesh_red Path Finder in Splunk Search 12-15-2023
0 10
0
10
the_dude
index&#61;jedi domain&#61;"jedi.lightside.com" (master!&#61;"yoda" AND master!&#61;"mace" AND master&#61;"Jinn") | table saber_color, J...
by the_dude Engager in Splunk Search 12-15-2023
0 8
0
8
suvi6789
Hi, I need help in a splunk search. My requirement is get the stats for failed and successful count along with the pe...
by suvi6789 Path Finder in Splunk Search 12-14-2023
0 5
0
5
jbanAtSplunk
Hi, I have Windows Event for specific application that have payload in Windows Event Log, when using Splunk_TA_window...
by jbanAtSplunk Communicator in Splunk Search 12-14-2023
0 3
0
3
smanojkumar
Hi There!   I would like to find the values of host that were in macro 1 but not in macro 2search 1 &#96;macro 1&#96; | field...
by smanojkumar Contributor in Splunk Search 12-14-2023
0 7
0
7
anandhalagaras1
Hi All,Need a help to write a query based on the field "Timestamp" which is different from "_time" value.Sample Event...
by anandhalagaras1 Contributor in Splunk Search 12-14-2023
0 5
0
5
Siddharthnegi
| table Status, timeval, CompanyCode, CN|appendpipe [stats count| eval error&#61;"thats not cool" | where count&#61;&#61;0 |table...
by Siddharthnegi Contributor in Splunk Search 12-14-2023
0 7
0
7
EricMonkeyKing
Hi all,For this sort of json string, how can I extract KeyA, KeyB, KeyC? { "KeyA": [ { "path": "/attibuteA", "op": "r...
by EricMonkeyKing Explorer in Splunk Search 12-14-2023
0 5
0
5
duesser
 I have a multivalue field, which I would like to expand to individual fields, like so:| makeresults count&#61;1 | eval a...
by duesser Path Finder in Splunk Search 12-14-2023
0 4
0
4
KingUs80
I'm currently working on crafting a Splunk Query to identify systems that have been inactive for a specified duration...
by KingUs80 Loves-to-Learn Lots in Splunk Search 12-13-2023
0 2
0
2
varsh_6_8_6
HiI am trying to see for a ticket that is not assigned to an analyst for the last 15 mins from the time of arrival. I...
by varsh_6_8_6 Explorer in Splunk Search 12-13-2023
0 1
0
1
Get Updates on the Splunk Community!

Telemetry Pipeline Management Series

As observability data volumes continue to surge, managing metric storage efficiently has become a critical ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...
Top Solution Authors