Splunk Search

Splunk Search
Community Activity
Chandrasekhar6
index=cs | rex "Type=(?<type>[a-z]+)" | rex field=AResponse.BResponse.Message mode=sed "s/Ref number+\w+\sfailed on ...
by Chandrasekhar6 Explorer in Splunk Search 12-07-2023
0 4
0
4
Bo3432
I am trying to remove window EventCodes 4688 and 4627. Nothing I have tried has worked. Her are the things that I hav...
by Bo3432 Explorer in Splunk Search 12-07-2023
0 4
0
4
PiotrAp
Hi,I'm trying to create a query which will display events matching following conditions: 5 or more different destinat...
by PiotrAp Path Finder in Splunk Search 12-07-2023
0 2
0
2
MirrorCraze
I have some search before, and after I extract fields (name, status) from json and mvzip it together, I got this tabl...
by MirrorCraze Explorer in Splunk Search 12-07-2023
0 4
0
4
alexc
Hello all! This will be a doozy, so get ready. We are running a search with tstats generated results,  from various t...
by alexc New Member in Splunk Search 12-06-2023
0 0
0
0
Bo3432
Hello,I am trying to find a command that will allow me to create a table and only display values. when using the user...
by Bo3432 Explorer in Splunk Search 12-06-2023
0 5
0
5
ZYSanshou
So when an upstream error is logged in our splunk it has two fields that contain all the information about the error....
by ZYSanshou Engager in Splunk Search 12-06-2023
0 2
0
2
NightShark
Hello,The rex command to catch and group the Accesses multi values are not working even though the results in regex10...
by NightShark Path Finder in Splunk Search 12-06-2023
0 2
0
2
ripson
I am using Splunk 9.0.4 and I need to make a query where I extract data from a main search.So I am interested in resu...
by ripson Engager in Splunk Search 12-06-2023
0 2
0
2
Jack_Accent
Hello! Still very new to Splunk so hoping to get some clarification.My dashboard is currently using a post-process se...
by Jack_Accent Loves-to-Learn in Splunk Search 12-06-2023
0 1
0
1
nehamvinchankar
Hi all, i want to extract fields from event which is in json format INFO [processor: anchsdgeiskgcbc/5; event: 1-57d2...
by nehamvinchankar Path Finder in Splunk Search 12-06-2023
0 5
0
5
siva_cg
Hi, I am trying to create a report in which I would like to get the field value by looking into a range of values th...
by siva_cg Path Finder in Splunk Search 12-05-2023
0 13
0
13
RJ_10
can anyone please tell me  the scenario based interview questions for splunk admin role ?
by RJ_10 New Member in Splunk Search 12-05-2023
0 1
0
1
dbarba
Hello!As the subject of the question says, I'm trying to create SPL queries for several visualizations but it has bec...
by dbarba Explorer in Splunk Search 12-05-2023
0 16
0
16
AL3Z
Hi,How we can find the difference of these two date difference in year days hour min fromtill11/28/2023 03:38 PM11/28...
by AL3Z Builder in Splunk Search 12-05-2023
0 7
0
7
aaronzabell
I imported a csv into Splunk and now I need to compare two of the fields to find identical values. Compare the values...
by aaronzabell Path Finder in Splunk Search 12-05-2023
0 10
0
10
Muthu_Vinith
Hey All, I’m a splunk beginner I'm looking to create a query that to be used  as an alert, specifically to identify s...
by Muthu_Vinith Path Finder in Splunk Search 12-05-2023
0 10
0
10
Rajaion
Hello community,I'm having a problem that's probably easy to solve, but I can't figure it out.I have a query that wil...
by Rajaion Path Finder in Splunk Search 12-05-2023
0 5
0
5
joemcmahon
When performing a query that creates a summary report, the associated search.log file shows:ResultsCollationProcessor...
by joemcmahon Explorer in Splunk Search 12-05-2023
0 0
0
0
dataisbeautiful
I am querying a change in a value each week over last 4 weeks. Ineed to know the value from the week before the searc...
by dataisbeautiful Communicator in Splunk Search 12-05-2023
0 1
0
1
avi7326
How to get a single table from this query having all the correlationId together in one table 
by avi7326 Path Finder in Splunk Search 12-05-2023
0 3
0
3
nehamvinchankar
How to extract field from below eventI want nname,ID,app and Time , here nname is mule_330299_prod_App01_Clt1ID=91826...
by nehamvinchankar Path Finder in Splunk Search 12-04-2023
0 3
0
3
Dharani
Hi, I want to schedule one splunk alert , please let me know if below option is possible:When the first alert receive...
by Dharani Path Finder in Splunk Search 12-04-2023
0 1
0
1
SubtotalAMG
I'm not a programmer but I am trying to get the display of my graph to depict "No Results" or "N/A" when the Where co...
by SubtotalAMG Loves-to-Learn Lots in Splunk Search 12-04-2023
0 7
0
7
mjemi
I need to drop EventCode 4634 and 4624 with Login_type 3, how i can use nullqueue option and write the correct REGEX ...
by mjemi Loves-to-Learn Everything in Splunk Search 12-04-2023
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...