Splunk Search

Splunk Search
Community Activity
Karthikeya
Before one week I created a summary index named waf_opco_yes_summary and it is working fine. Now they asked to change...
by Karthikeya Communicator in Splunk Search 07-25-2025
0 10
0
10
cdevoe57
I am attempting to run a query that will find the status fo 3 services and list which ones are failed and which ones ...
by cdevoe57 Path Finder in Splunk Search 07-24-2025
0 8
0
8
kuul13
I am trying to find the time taken by our processes. I wrote a basic query that fetch a start, end time, and the diff...
by kuul13 Explorer in Splunk Search 07-24-2025
0 3
0
3
kinicky
I have a dotnet application logging template formatted log messages with serilog library and since everything is in J...
by kinicky Engager in Splunk Search 07-24-2025
0 2
0
2
bp2025
Hello!I have the following query with the provided fields to track consumption data for customers.action=load OR acti...
by bp2025 Engager in Splunk Search 07-24-2025
0 1
0
1
yuvaraj_m91
{<!-- -->  "abcdxyz" : {<!-- -->    "transaction" : "abcdxyz",    "sampleCount" : 60,    "errorCount" : 13,    "errorPct" : 21.666666...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 07-24-2025
0 2
0
2
schres1
I have a query similar to the one below.  index &#61; "idx" source &#61; "mysource"  |spath path&#61;myField output&#61;res|stats cou...
by schres1 Explorer in Splunk Search 07-23-2025
0 4
0
4
pedropiin
Hi everyone,I'm working on a dashboard that's comparing two different applications. One of the tables has their perfo...
by pedropiin Path Finder in Splunk Search 07-23-2025
0 4
0
4
mchoudhary
Hi Team,I have been getting a skipped search notification in my CMC overview under Health from quite some time.It is ...
by mchoudhary Explorer in Splunk Search 07-23-2025
0 1
0
1
mbasharat
Hi,I have a simple multi-select filter as below on my main dashboard.&lt;input type&#61;"multiselect" token&#61;"projects" searc...
by mbasharat Builder in Splunk Search 07-23-2025
0 10
0
10
Splunkie
I am trying to remove a field which  has a suffix of sophos_event_input after the username. ExampleUsername_FieldJoe-...
by Splunkie Explorer in Splunk Search 07-23-2025
0 3
0
3
DexterWard
I have an audit table with before and after records of changes made to a user table. So every time an update is made ...
by DexterWard New Member in Splunk Search 07-23-2025
0 1
0
1
kundeng
Am I missing something?  I have vscode running splunk extension and created a simple _default.spl2nb.  I'm able to te...
by kundeng Path Finder in Splunk Search 07-22-2025
0 2
0
2
seetide
I want to search the "NONE" not in 3 allowed enum value. I need to ignore the "NONE" if it is in the allowed enum. Fo...
by seetide New Member in Splunk Search 07-22-2025
0 6
0
6
smcdonald20
I have a field, where all values are pre-fixed with "OPTIONS-IT\". I would like to remove this, but not sure on the b...
by smcdonald20 Path Finder in Splunk Search 07-22-2025
0 6
0
6
bt149
I have a field called key. key has multivalues that are also dynamic. I have another field called values, that is als...
by bt149 Path Finder in Splunk Search 07-22-2025
0 5
0
5
jenny_life
Hello everyone. I want to add line as division line on the scatter chart. I'd like to know which values are in speci...
by jenny_life Path Finder in Splunk Search 07-21-2025
0 7
0
7
Nawab
I have a requirement where I want to see all users and their last login time, we are connected through Ldap so settin...
by Nawab Communicator in Splunk Search 07-21-2025
0 3
0
3
kuul13
I was able to write a query that group by api (msgsource) to show the response times, but I am trying to see if I can...
by kuul13 Explorer in Splunk Search 07-20-2025
0 6
0
6
tkrprakash
Hi All,I have an input lookup file with 2 fields  first filed contains some path and the second filed is an httpcode ...
by tkrprakash Loves-to-Learn Lots in Splunk Search 07-17-2025
0 2
0
2
Na_Kang_Lim
I am looking for the best way in terms of performance when adding filtering of certain events for security rules. Nor...
by Na_Kang_Lim Path Finder in Splunk Search 07-17-2025
0 6
0
6
Andre_
Hello,I have Database Connect setup and it's working all fine. But I can't wrap my head around how the Alert Action w...
by Andre_ Path Finder in Splunk Search 07-17-2025
0 8
0
8
OliverG91
Given this search result:Company A         Visa            15                                 MC                5    ...
by OliverG91 Explorer in Splunk Search 07-16-2025
0 4
0
4
NorthropGrumman
Hi everyone and thanks in advance.I'm trying to collate all our SOCKS traffic on our network over the last 90 days.Ou...
by NorthropGrumman New Member in Splunk Search 07-16-2025
0 4
0
4
thierry
I have events already in an index looking like this:{<!-- -->   "location": "Paris",   "temperature": 25,   "humidity": 57}I ...
by thierry Splunk Employee Splunk Employee in Splunk Search 07-15-2025
0 10
0
10
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...