Splunk Search

Splunk Search
Community Activity
pgoldweic
Hi, I have an existing search as follows:    | eval tempTime=strptime(due_at."-0000","%Y-%m-%d %H:%M:%S.%3N%z")    | ...
by pgoldweic Communicator in Splunk Search 10-27-2023
0 2
0
2
martaBenedetti
Hi all,   I've configured a new role to inherit settings from user and power role and I let default values for srchJo...
by martaBenedetti Path Finder in Splunk Search 10-27-2023
0 2
0
2
ericSplunk
I created a dashboard with a query looks like this : index=cbclogs sourcetype = cbc_cc_performance source="/var/log/c...
by ericSplunk Engager in Splunk Search 10-27-2023
0 4
0
4
xyberdef
Hello,I have one more begginers question regarding reports and dashboards I am trying to do overview of most used se...
by xyberdef Explorer in Splunk Search 10-27-2023
0 2
0
2
Flenwy
Hello everyone,I'm currently setting up a lot of alarms in Splunk, and a question has arisen regarding what is better...
by Flenwy Explorer in Splunk Search 10-27-2023
0 2
0
2
AyushiSrivas
i want the output in the below format :-Input as below:-host           sql instance           db nameabc             ...
by AyushiSrivas Loves-to-Learn in Splunk Search 10-27-2023
0 1
0
1
Dennis
Hello,Didn't get any hits on this issue so starting a new thread, and didn't find any previous defect reported on thi...
by Dennis Explorer in Splunk Search 10-27-2023
0 3
0
3
gerrysr6
As I understand the documentation ANDs are implied, so "eventtype=A eventtype=B"  is the same as "eventtype=A AND eve...
by gerrysr6 Explorer in Splunk Search 10-27-2023
0 1
0
1
Gaikwad
Splunk app for AWS security dashboard shows '0' data, need help to fix this issue  when I try to run/edit query shows...
by Gaikwad Explorer in Splunk Search 10-27-2023
0 3
0
3
NoSpaces
 Hello to everyone!I have a strange issue with some events that come from our virtual environment.As you can see in t...
by NoSpaces Contributor in Splunk Search 10-27-2023
0 16
0
16
learningquery
Hi community,| eval ycw = strftime(_time, "%Y_%U")| stats count(eval("FieldA"="True")) as FieldA_True,              c...
by learningquery Explorer in Splunk Search 10-26-2023
0 11
0
11
smanojkumar
Hi There!   I'm having the dropdown "office" in dashboard 1 as a multiselect (full office, half office), based  on th...
by smanojkumar Contributor in Splunk Search 10-26-2023
0 6
0
6
Sid
I am trying to setup a dashboard which gives me details like user's current concurrency settings & roles utilization ...
by Sid Explorer in Splunk Search 10-26-2023
0 2
0
2
Taruchit
Hello All,Using the below code, I get the defined quota limits for each role in Splunk environment: -  |rest /service...
by Taruchit Contributor in Splunk Search 10-26-2023
0 2
0
2
xyberdef
Hello,I am trying to make report which will display what notables were closed with what disposition. But unfortunatel...
by xyberdef Explorer in Splunk Search 10-26-2023
0 4
0
4
pm
hi i am windows user i am trying to install universal forwarders in ubuntu i am a windows user can anyone share like ...
by pm New Member in Splunk Search 10-26-2023
0 1
0
1
sjringo
What I am trying to do is graph / timechart active users.   I am starting with this query:index=anIndex sourcetype=pe...
by sjringo Contributor in Splunk Search 10-26-2023
0 2
0
2
avi7326
 I want to extract the below contractWithCustomers and  contracts  using rex named as entity . For ID 1349c1f4-989c-4...
by avi7326 Path Finder in Splunk Search 10-26-2023
0 3
0
3
andrewtrobec
Splunk Enterprise 9.0.5.1Hello!I have to calculate the delta between two timestamps that have nanosecond granularity....
by andrewtrobec Motivator in Splunk Search 10-26-2023
0 1
0
1
PiotrSekula
When I call:https://api.{REALM}.signalfx.com/v1/timeserieswindowwith my access token as header: X-SF-TOKENI receive:{<!-- -->...
by PiotrSekula New Member in Splunk Search 10-26-2023
0 0
0
0
manojchacko78
I am extracting these three values and if there is any empty value in any of the fields, it returns as no result.How ...
by manojchacko78 Path Finder in Splunk Search 10-26-2023
0 2
0
2
duesser
Hello,I would like to use a subsearch to literally paste a command into the SPL e.g.:  | makeresults [| makeresults |...
by duesser Path Finder in Splunk Search 10-26-2023
0 8
0
8
sabari80
I have a query to retrieve user experience metrics from Dynatrace index. Wanted to compare the response times for 2 d...
by sabari80 Explorer in Splunk Search 10-26-2023
0 7
0
7
rphillips_splk
I'd like to add metadata to my events at the source and change the _meta value periodically without restarting the fo...
by rphillips_splk Splunk Employee Splunk Employee in Splunk Search 10-26-2023
0 7
0
7
ejwade
I'm looking for the regular expression wizards out there. I need to do a rex with two capture groups: one for name, a...
by ejwade Contributor in Splunk Search 10-26-2023
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...