Splunk Search

Splunk Search
Community Activity
alex4
Kindly help me with a new SPLIn am getting results for the existing below SPL.I tried applying a new condition in exi...
by alex4 Loves-to-Learn Lots in Splunk Search 10-06-2023
0 3
0
3
jip31
HelloWhen I run a search i have the message "could not load lookup" with different lookup nameFor example :Could not ...
by jip31 Motivator in Splunk Search 10-05-2023
0 2
0
2
jhuysing
Have a log with related eventOne event has the number widgets made in the period and another event has the actual tim...
by jhuysing Explorer in Splunk Search 10-05-2023
0 1
0
1
eranhauser
How can one add to the result of a Splunk query running on Splunk UI the time span i.e. the values one can put in ear...
by eranhauser Path Finder in Splunk Search 10-05-2023
0 5
0
5
sjringo
I have a query that gives me four totals for a month.  I am trying to figure out how to show each four total for each...
by sjringo Contributor in Splunk Search 10-05-2023
0 3
0
3
abhi04
Hi,I have a alert query that uses mstats, I want this query to not throw alert during public holidays (from 9 AM to 5...
by abhi04 Communicator in Splunk Search 10-05-2023
0 3
0
3
AKG11
Hi,I am looking to parse the nested JSON events. basically need to break them into multiple events.I an trying some t...
by AKG11 Path Finder in Splunk Search 10-05-2023
0 2
0
2
irkey
Trying to find anomalies for events. I have multiple services and multiple customers. I have an error "bucket" that i...
by irkey Explorer in Splunk Search 10-05-2023
0 4
0
4
sarit_s
HelloI'm trying to calculate ratio of two fields but im getting wrong resultsif i'm calculating each one of them sepa...
by sarit_s Communicator in Splunk Search 10-05-2023
0 8
0
8
Muditks
This splunk search is not showing any result. index=os OR index=linux sourcetype=vmstat OR source=iostat [| input loo...
by Muditks Observer in Splunk Search 10-05-2023
0 1
0
1
yohhpark
system_id = AA-1, AA-1-a, AA-1-b, AA-10, AA-10-a, AA-10-b, AA-12, AA-12-a, AA-12-b,,, and so on. Notice all the syste...
by yohhpark Path Finder in Splunk Search 10-05-2023
0 1
0
1
jamesvz84
I am trying to determine how many searches are searching on a particular index per day. I know how much data the ind...
by jamesvz84 Communicator in Splunk Search 10-05-2023
1 8
1
8
finchy
Hi, What's the best way to only do a Lookup based on the results of the main search?  I want to only run this when 2 ...
by finchy Explorer in Splunk Search 10-04-2023
0 5
0
5
TaraAshley
Hello, I was wondering if it is possible to locate or search in Splunk if a specific lookup table is being used in a ...
by TaraAshley Engager in Splunk Search 10-04-2023
0 2
0
2
runiyal
Have following data in the logfile    {xxxx},{"GUID":"5561859B8D624FFC8FF0B87219060DC5"} {xxxx},{"GUID":"5561859B8D62...
by runiyal Path Finder in Splunk Search 10-04-2023
0 5
0
5
NanSplk01
I have found a search in the charge back application that might fit for seeing the SVC's by index.  Unfortunately tha...
by NanSplk01 Communicator in Splunk Search 10-04-2023
0 2
0
2
faustf
Hi,we are logging api requests in Splunk. I would like to create a sort of health check table where every column repr...
by faustf Communicator in Splunk Search 10-04-2023
0 3
0
3
Tester237
Hi, I'm trying to plot graph for previous 2 weekday average. Below is the query usedindex="xyz" sourcetype="abc" app...
by Tester237 Explorer in Splunk Search 10-04-2023
0 2
0
2
P3G4SUS
Lets say I have a table of two fields. and some of the cells are empty.How do I find the number of empty cells using ...
by P3G4SUS New Member in Splunk Search 10-04-2023
0 2
0
2
alexeysharkov
Hello friends!I get JSON like this{"key":"27.09.2023","value_sum":35476232.82,"value_cnt":2338}and so on...{ [-]   ke...
by alexeysharkov Path Finder in Splunk Search 10-04-2023
0 4
0
4
shreyasbsharma
Hi Team, I have a got a request to plot graph of previous 30 days. But the org has a retention period of 7days set on...
by shreyasbsharma Engager in Splunk Search 10-04-2023
0 7
0
7
sarit_s
HelloIm trying to run a chart command grouped by 2 fields but im getting an error:this is my query :   | chart value...
by sarit_s Communicator in Splunk Search 10-03-2023
0 8
0
8
FGAnders
Hi,Is it somehow possible to find difference between two or more amounts from different events when the events are so...
by FGAnders Explorer in Splunk Search 10-03-2023
0 3
0
3
Sekhar
Log like.message: [22/09/23 10:31:47:935 GMT] [ThreadPoolExecutor-thread-15759] INFO failed.", suspenseAccountNumber=...
by Sekhar Explorer in Splunk Search 10-03-2023
0 5
0
5
yohhpark
system_id = AA-1, AA-1-a, AA-1-b, AA-10, AA-10-a, AA-10-b, AA-12, AA-12-a, AA-12-b,,, and so on. Notice all the syste...
by yohhpark Path Finder in Splunk Search 10-03-2023
0 2
0
2
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and stall ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...
Top Solution Authors