Splunk Search

Splunk Search
Community Activity
nithys
Hi Team,I am using a query which has same index and source but fetch two results based on the search and combine to a...
by nithys Communicator in Splunk Search 12-16-2023
0 3
0
3
murad
HiKinda a new to splunk . Sending data to splunk via HEC. Its a DTO which contains various fields, one of them being ...
by murad Observer in Splunk Search 12-16-2023
0 3
0
3
mohammadsharukh
Dear All,Scenario--> 1AV server is having multiple endpoint reporting to it. This AV server integrated with Splunk an...
by mohammadsharukh Path Finder in Splunk Search 12-16-2023
0 1
0
1
nkavouris
I have a search as follows:index=*|search sourcetype=*|spath logs{} output=logs|spath serial_number output=serial_num...
by nkavouris Path Finder in Splunk Search 12-15-2023
0 2
0
2
GaetanVP
Hello Splunkers,I have a Splunk HF that will receive multiple logs coming from different machines, all sending via UD...
by GaetanVP Contributor in Splunk Search 12-15-2023
1 4
1
4
Satheesh_red
I have a Splunk result like below.VMcol1col2vm1carsedanvm2carsedanvm3planePrivvm4bikeFazervm5bikethunder I would like...
by Satheesh_red Path Finder in Splunk Search 12-15-2023
0 10
0
10
the_dude
index=jedi domain="jedi.lightside.com" (master!="yoda" AND master!="mace" AND master="Jinn") | table saber_color, J...
by the_dude Engager in Splunk Search 12-15-2023
0 8
0
8
suvi6789
Hi, I need help in a splunk search. My requirement is get the stats for failed and successful count along with the pe...
by suvi6789 Path Finder in Splunk Search 12-14-2023
0 5
0
5
jbanAtSplunk
Hi, I have Windows Event for specific application that have payload in Windows Event Log, when using Splunk_TA_window...
by jbanAtSplunk Communicator in Splunk Search 12-14-2023
0 3
0
3
smanojkumar
Hi There!   I would like to find the values of host that were in macro 1 but not in macro 2search 1 `macro 1` | field...
by smanojkumar Contributor in Splunk Search 12-14-2023
0 7
0
7
anandhalagaras1
Hi All,Need a help to write a query based on the field "Timestamp" which is different from "_time" value.Sample Event...
by anandhalagaras1 Contributor in Splunk Search 12-14-2023
0 5
0
5
Siddharthnegi
| table Status, timeval, CompanyCode, CN|appendpipe [stats count| eval error="thats not cool" | where count==0 |table...
by Siddharthnegi Contributor in Splunk Search 12-14-2023
0 7
0
7
EricMonkeyKing
Hi all,For this sort of json string, how can I extract KeyA, KeyB, KeyC? { "KeyA": [ { "path": "/attibuteA", "op": "r...
by EricMonkeyKing Explorer in Splunk Search 12-14-2023
0 5
0
5
duesser
 I have a multivalue field, which I would like to expand to individual fields, like so:| makeresults count=1 | eval a...
by duesser Path Finder in Splunk Search 12-14-2023
0 4
0
4
KingUs80
I'm currently working on crafting a Splunk Query to identify systems that have been inactive for a specified duration...
by KingUs80 Loves-to-Learn Lots in Splunk Search 12-13-2023
0 2
0
2
varsh_6_8_6
HiI am trying to see for a ticket that is not assigned to an analyst for the last 15 mins from the time of arrival. I...
by varsh_6_8_6 Explorer in Splunk Search 12-13-2023
0 1
0
1
nkavouris
Hello Splunkers,I am New to Splunk and am trying to figure out how to parse nested JSON data spit out by an end-of-li...
by nkavouris Path Finder in Splunk Search 12-13-2023
0 5
0
5
MirrorCraze
I have a data like this.{<!-- -->    env: prod   host: prod01   name: appName   info: {      data: [ ...     ]     indicators...
by MirrorCraze Explorer in Splunk Search 12-13-2023
0 1
0
1
Lennard
Hi guys, I started today with Splunk and have one question. I want to use an or function that if the second "or" the ...
by Lennard Engager in Splunk Search 12-13-2023
0 2
0
2
Jagat
I want to extract only the process name value from the logs and store in a table:Input Log:-------------&lt;30&gt;1 2023-12...
by Jagat Engager in Splunk Search 12-13-2023
0 4
0
4
nithys
Hi All,I need some help in searching, I have 1 index but it has multiple sources,Index &#61; Index1Source &#61; source 1Sourc...
by nithys Communicator in Splunk Search 12-12-2023
0 2
0
2
CoryC
How do I grab all of the versions of Splunk EXCEPT the top 1, basically the opposite ofindex&#61;winconfig sourcetype&#61;"WM...
by CoryC Engager in Splunk Search 12-12-2023
0 1
0
1
nehamvinchankar
Hi experts,I want to extract below fields in separate separate event to further work on it .INFO 2023-12-11 17:06:01,...
by nehamvinchankar Path Finder in Splunk Search 12-12-2023
0 4
0
4
KundanNagare23
We got output in table but all values are in one column  for each fields of output table. We want to split values in ...
by KundanNagare23 Loves-to-Learn Lots in Splunk Search 12-12-2023
0 4
0
4
ea-2023
Hello, I am working on a search to find domains queried via a particular host, and list out a count of hits per uniqu...
by ea-2023 Path Finder in Splunk Search 12-12-2023
0 5
0
5
Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...
Top Solution Authors