Splunk Search

Splunk Search
Community Activity
yuvaraj_m91
I have two different logs where the error is capturing in different fields in each log message...(error_message and e...
by yuvaraj_m91 Loves-to-Learn Lots in Splunk Search 12-12-2023
0 1
0
1
nehamvinchankar
How to get difference of  lastest value with now i have multiple values in latest column and only one value in now co...
by nehamvinchankar Path Finder in Splunk Search 12-12-2023
0 1
0
1
att35
Hi.I have a data model that consists of two root event datasets. Both accelerated using simple SPL.First dataset I ca...
by att35 Builder in Splunk Search 12-12-2023
1 1
1
1
GaryZ
Is there a way of creating a search where we can have both LIKE and NOT LIKE, based on user selected option? ie. if $...
by GaryZ Path Finder in Splunk Search 12-11-2023
0 1
0
1
akr
I am new to Splunk. I am trying to overwrite the values of a field (eventLevel) that is in Japanese. I created a look...
by akr Loves-to-Learn Lots in Splunk Search 12-11-2023
0 1
0
1
mojoes
Hi, I am new at Splunk and I'm following the lab in Enriching Data with Lookups, where I'm requested to exclude a val...
by mojoes Engager in Splunk Search 12-11-2023
0 1
0
1
Abhirup_10
I have a csv file with the user list and I want to create an alert to monitor the user login failure alert from the u...
by Abhirup_10 New Member in Splunk Search 12-10-2023
0 1
0
1
splunkernator
Do you need to return output from one section of a chain search to another, like when writing a function in a program...
by splunkernator Path Finder in Splunk Search 12-09-2023
0 17
0
17
Rhidian
Hi, I'm trying to calculate the number of events per day so I can then divide by 86400 to get the daily EPS. I know I...
by Rhidian Path Finder in Splunk Search 12-09-2023
0 12
0
12
Muthu_Vinith
Hi, I have two datasets for example –1.Index=abc host=def_inven, consider as Dataset A (inventory with 100 servers) a...
by Muthu_Vinith Path Finder in Splunk Search 12-09-2023
0 7
0
7
AK89
Looking for help with this rex command. I want to capture the continuous string after "invalid user" whether it has s...
by AK89 Explorer in Splunk Search 12-08-2023
0 3
0
3
smanojkumar
Hi There!   I'm facing the error "Search is waiting for the input"<form stylesheet="dashboard.css,infobutton.css" scr...
by smanojkumar Contributor in Splunk Search 12-08-2023
0 1
0
1
bharath_hk12
Hi,I have logger statements like below:Event data - {"firstName":"John","lastName":"Doe"} My query needs <rex-stateme...
by bharath_hk12 Explorer in Splunk Search 12-08-2023
0 7
0
7
vamshikn72
What is the character limit of an alert name in splunk ES?
by vamshikn72 Explorer in Splunk Search 12-07-2023
0 2
0
2
jwhughes58
I've got this searchindex=main sourcetype="bigfix" | eval raw=_raw | rex mode=sed field=raw "s/\n/ /g" | rex field=...
by jwhughes58 Contributor in Splunk Search 12-07-2023
0 1
0
1
a212830
Hi, I'm configuring some new roles, and came across the "schedule_rtsearch" capability. The doc simply says "Lets t...
by a212830 Champion in Splunk Search 12-07-2023
1 6
1
6
RENUKA1
Hello All, I need to convert the Timeline with different times into one.For example:12:05AM 12:10AM 12:15AM should be...
by RENUKA1 Loves-to-Learn Lots in Splunk Search 12-07-2023
0 3
0
3
Chandrasekhar6
index=cs | rex "Type=(?<type>[a-z]+)" | rex field=AResponse.BResponse.Message mode=sed "s/Ref number+\w+\sfailed on ...
by Chandrasekhar6 Explorer in Splunk Search 12-07-2023
0 4
0
4
Bo3432
I am trying to remove window EventCodes 4688 and 4627. Nothing I have tried has worked. Her are the things that I hav...
by Bo3432 Explorer in Splunk Search 12-07-2023
0 4
0
4
PiotrAp
Hi,I'm trying to create a query which will display events matching following conditions: 5 or more different destinat...
by PiotrAp Path Finder in Splunk Search 12-07-2023
0 2
0
2
MirrorCraze
I have some search before, and after I extract fields (name, status) from json and mvzip it together, I got this tabl...
by MirrorCraze Explorer in Splunk Search 12-07-2023
0 4
0
4
alexc
Hello all! This will be a doozy, so get ready. We are running a search with tstats generated results,  from various t...
by alexc New Member in Splunk Search 12-06-2023
0 0
0
0
Bo3432
Hello,I am trying to find a command that will allow me to create a table and only display values. when using the user...
by Bo3432 Explorer in Splunk Search 12-06-2023
0 5
0
5
ZYSanshou
So when an upstream error is logged in our splunk it has two fields that contain all the information about the error....
by ZYSanshou Engager in Splunk Search 12-06-2023
0 2
0
2
NightShark
Hello,The rex command to catch and group the Accesses multi values are not working even though the results in regex10...
by NightShark Path Finder in Splunk Search 12-06-2023
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...