Splunk Search

Splunk Search
Community Activity
alvinsullivan01
I have issue to transform data and extracting the fields value. Here is my sample data.2025-07-20T10:15:30+08:00 h1 t...
by alvinsullivan01 Explorer in Splunk Search 08-01-2025
0 16
0
16
neerajs_81
Hello All,  Below is my dataset from a base query. How can i calculate the average value of the column ?Incidentavg_t...
by neerajs_81 Builder in Splunk Search 07-31-2025
0 9
0
9
Karthikeya
We will create two indexes per application one for non_prod and one for prod logs in same splunk. They create 2 AD gr...
by Karthikeya Communicator in Splunk Search 07-31-2025
0 29
0
29
arvind_Sugajeev
We have the "Reassign Knowledge Objects" option via SplunkCloud portal in the settings but is it possible to do it vi...
by arvind_Sugajeev Explorer in Splunk Search 07-30-2025
0 5
0
5
Manjunathmuni
Hello Splunkers,The hardcoded time parameters inside a simple search don't work with v9.4.3.  It only takes the input...
by Manjunathmuni Observer in Splunk Search 07-30-2025
0 9
0
9
meetmshah
I want to configure Federated Search so that Deployment A can search Deployment B, and Deployment B can also search D...
by SplunkTrust SplunkTrust in Splunk Search 07-30-2025
0 3
0
3
splunklearner
We are having multiple roles created in Splunk restricted by their index and users will be added to this role via AD ...
by splunklearner Communicator in Splunk Search 07-29-2025
0 7
0
7
CyberAar
The Splunk documentation says that the order rule is lexicographic. I am trying to sort the following values:| makere...
by CyberAar Explorer in Splunk Search 07-29-2025
0 4
0
4
wjrbrady
Hello ,I am trying to change in the search itself to change the span in timechart.  So if the hour is say greater tha...
by wjrbrady Engager in Splunk Search 07-28-2025
0 12
0
12
prashanthan1987
We are looking for feasible to integrate with Mule Cloudhub with Splunk Cloud directly for logs ingestion. Please sug...
by prashanthan1987 Explorer in Splunk Search 07-28-2025
0 2
0
2
Gunner
I have devices using a specific v4 address range and a specific v6 address range. I'd like to get the percent of devi...
by Gunner New Member in Splunk Search 07-28-2025
0 1
0
1
KishoreSrini
Hello all, I am working on an Splunk query which suppose to filter some logs by utilizing data from lookup. Consider ...
by KishoreSrini Explorer in Splunk Search 07-28-2025
0 5
0
5
Karthikeya
Sorry for everyone that I am posting multiple posts for my issue. Just summarising everything here.. please help me w...
by Karthikeya Communicator in Splunk Search 07-26-2025
0 4
0
4
JacobPN
I am looking to restrict the use of certain search commands for particular users / roles. In particular I would like ...
by JacobPN Path Finder in Splunk Search 07-25-2025
0 7
0
7
weidertc
I need to filter a list of timestamps which are less than _time.this works:| makeresults count=1 | eval timestamps = ...
by weidertc Contributor in Splunk Search 07-25-2025
0 3
0
3
Karthikeya
Before one week I created a summary index named waf_opco_yes_summary and it is working fine. Now they asked to change...
by Karthikeya Communicator in Splunk Search 07-25-2025
0 10
0
10
cdevoe57
I am attempting to run a query that will find the status fo 3 services and list which ones are failed and which ones ...
by cdevoe57 Path Finder in Splunk Search 07-24-2025
0 8
0
8
kuul13
I am trying to find the time taken by our processes. I wrote a basic query that fetch a start, end time, and the diff...
by kuul13 Explorer in Splunk Search 07-24-2025
0 3
0
3
kinicky
I have a dotnet application logging template formatted log messages with serilog library and since everything is in J...
by kinicky Engager in Splunk Search 07-24-2025
0 2
0
2
bp2025
Hello!I have the following query with the provided fields to track consumption data for customers.action=load OR acti...
by bp2025 Engager in Splunk Search 07-24-2025
0 1
0
1
yuvaraj_m91
{<!-- -->  "abcdxyz" : {<!-- -->    "transaction" : "abcdxyz",    "sampleCount" : 60,    "errorCount" : 13,    "errorPct" : 21.666666...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 07-24-2025
0 2
0
2
schres1
I have a query similar to the one below.  index &#61; "idx" source &#61; "mysource"  |spath path&#61;myField output&#61;res|stats cou...
by schres1 Explorer in Splunk Search 07-23-2025
0 4
0
4
pedropiin
Hi everyone,I'm working on a dashboard that's comparing two different applications. One of the tables has their perfo...
by pedropiin Path Finder in Splunk Search 07-23-2025
0 4
0
4
mchoudhary
Hi Team,I have been getting a skipped search notification in my CMC overview under Health from quite some time.It is ...
by mchoudhary Explorer in Splunk Search 07-23-2025
0 1
0
1
mbasharat
Hi,I have a simple multi-select filter as below on my main dashboard.&lt;input type&#61;"multiselect" token&#61;"projects" searc...
by mbasharat Builder in Splunk Search 07-23-2025
0 10
0
10
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...