Splunk Search

Splunk Search
Community Activity
OrionCulver
Hi,We currently have events where identifying the app that makes the event depends multiple fields, as well as substr...
by OrionCulver Explorer in Splunk Search 11-09-2023
0 5
0
5
coreyCLI
I have a KV store collection that is populated.  I have a lookup definition pointing to the KV store.  If you use the...
by coreyCLI Communicator in Splunk Search 11-09-2023
0 6
0
6
vijreddy30
Hi All, My requirement is source data records data need to be encrypted. What does process need to follow? Is there a...
by vijreddy30 Loves-to-Learn Everything in Splunk Search 11-09-2023
0 3
0
3
duesser
I am basically faced with this problem:  | makeresults count=3 | streamstats count | eval a.1 = case(count=1, 1, coun...
by duesser Path Finder in Splunk Search 11-09-2023
0 1
0
1
scout29
I am trying to write a regex to extract a field called "registrar" from some data like i have below. Can you please h...
by scout29 Path Finder in Splunk Search 11-08-2023
0 4
0
4
virginiatech199
Does anyone know a pattern for detecting half-duplex connections from server/laptop sources to server destinations? n...
by virginiatech199 Explorer in Splunk Search 11-08-2023
0 1
0
1
lorinj62
I have events like this :11/06/2023 12:34:56 ip 1.2.3.4 This is record 1 of 5USER PID %CPU %MEM VSZ RSS TTY STAT STAR...
by lorinj62 Engager in Splunk Search 11-08-2023
0 3
0
3
viku7474
I have a field called environment which has values like dev,prod,uat,sit.Now I want to create a new_field which all t...
by viku7474 Explorer in Splunk Search 11-08-2023
0 3
0
3
oleg90
Hello! Could you advise, please, how can I compare results of 2 searches, which returns results in a different format...
by oleg90 Explorer in Splunk Search 11-08-2023
0 6
0
6
kk2204
I've got a search query which outputs 175 rows. I want it to output only top 5%. The row count will change over time ...
by kk2204 Explorer in Splunk Search 11-08-2023
0 6
0
6
henryfox
After installing the latest UF 9.1.1 on a linux i tried to  connect it to the deployment server./splunk set deploy-po...
by henryfox Engager in Splunk Search 11-08-2023
0 0
0
0
rajnsoni92
I am a beginner in Splunk queries. I might would be asking for some simple query but I am not able to construct it af...
by rajnsoni92 Explorer in Splunk Search 11-08-2023
0 2
0
2
sherwin_r
I am  having trouble comparing the columns age and expectedAge, where the column expectedAge is a result of a lookup ...
by sherwin_r Explorer in Splunk Search 11-08-2023
0 3
0
3
sphiwee
My regular expression has been working fine.. but now theres data with "[]" and it is being skipped   here is the reg...
by sphiwee Contributor in Splunk Search 11-08-2023
0 1
0
1
ssaenger
Hi All,I have a search query that allows me to pull results from an index summary.One of the fields is a time/date fi...
by ssaenger Communicator in Splunk Search 11-08-2023
0 14
0
14
Satyapv
Hello,I have below code for a dropdown menu and the problem is the moment i select any of the value from drop down de...
by Satyapv Engager in Splunk Search 11-08-2023
0 3
0
3
yoshileigh66
Apparently my Google-Fu isn't the best and I can't find an explanation. Can someone please enlighten me? I have a loo...
by yoshileigh66 Explorer in Splunk Search 11-08-2023
0 3
0
3
neokevin
Hi All,I want to create an SPL query that first returns data by matching the destination IP address from Palo Alto lo...
by neokevin Engager in Splunk Search 11-08-2023
0 3
0
3
Lavender
Hi,I have 2 saved searches that fetch data from datamodel (pivot table) and the result of these savedsearch is storin...
by Lavender Loves-to-Learn Everything in Splunk Search 11-07-2023
0 0
0
0
djoobbani
Can someone please help me with this.So I have the following query:source=abc type=Change msg=" consumed" event_type=...
by djoobbani Path Finder in Splunk Search 11-07-2023
0 18
0
18
sp
I need to run a Splunk search with "transaction" command and I have four pattern variations for the start of the tran...
by sp Loves-to-Learn in Splunk Search 11-07-2023
0 2
0
2
Satyapv
Dear All,I have look up file with Transaction details and Transaction Name Like below. Will be great if someone sugge...
by Satyapv Engager in Splunk Search 11-07-2023
0 8
0
8
Hema_Nithya
I have a query to fetch Kernel version from all the Linux servers . We update the Kernel Patch every quarter . I have...
by Hema_Nithya Explorer in Splunk Search 11-07-2023
0 1
0
1
Hema_Nithya
How to highlight empty fields in the dashboard in colours . Simple step pls 
by Hema_Nithya Explorer in Splunk Search 11-07-2023
0 3
0
3
parthiban
Hi everyoneI need to grouping the below 3 events with correlation ID. I have tried transaction cmd below but it is no...
by parthiban Path Finder in Splunk Search 11-07-2023
0 18
0
18
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors