Splunk Search

Splunk Search
Community Activity
splunkrocks2014
How to write a search that will determine if a lookup file has been updated? Thanks.
by splunkrocks2014 Communicator in Splunk Search 11-02-2016
0 4
0
4
wcooper003
I have an intensive search populating a dashboard that i'd like to schedule once a day, or as requested by the user -...
by wcooper003 Communicator in Splunk Search 11-02-2016
0 2
0
2
gpburgett
I've got a custom command that we're running over a large set of data. When I just run the part of the query up to ri...
by gpburgett Splunk Employee Splunk Employee in Splunk Search 11-02-2016
1 1
1
1
asingla
I have components which are sending UDP messages to splunk. The message format is key1=value1|key2=value2|.... Fe...
by asingla Communicator in Splunk Search 11-02-2016
4 12
4
12
aliroumani
Dear Sirs, in symantec dlp we have different policies consider it as (1,2,3,...etc) and when i user violate any polic...
by aliroumani Explorer in Splunk Search 11-02-2016
0 1
0
1
wgoodwin_splunk
I have a customer that is attempting to check a field “Account_Name”. Some of the events have multiple account names...
by wgoodwin_splunk Splunk Employee Splunk Employee in Splunk Search 11-02-2016
0 2
0
2
splunk_hvijay
Need a help urgently in using a lookup in a search. I have a lookup table as below and need to use this data in the s...
by splunk_hvijay Explorer in Splunk Search 11-02-2016
0 2
0
2
dayananda7449
Hi There, I am trying to figure out how to remove duplicates in a custom perfmon counters data that is exported to ...
by dayananda7449 New Member in Splunk Search 11-01-2016
0 1
0
1
splunk_hvijay
I want to compare two dates using case statement Theoretically, case( _time > "2016-01-01") . If True, Print "Yes" in...
by splunk_hvijay Explorer in Splunk Search 11-01-2016
0 1
0
1
jonbelanger
Would like to do this: Where indexa has two fields, md5 and allmd5 Two records exist like this: md5=99ed710da1d10b...
by jonbelanger Explorer in Splunk Search 11-01-2016
0 3
0
3
galwood
Is there a way to search a log and figure out which heavy forwarder sent the log to the indexer?
by galwood New Member in Splunk Search 11-01-2016
0 3
0
3
demkic
Suppose I am interested in finding out the top 5 videogames bought (in the last 24 hours) per top 10 stores and would...
by demkic Explorer in Splunk Search 11-01-2016
0 4
0
4
pdumblet
I have a proxy log index which contains a URL field. I also have a lookup table, which contains a list of known ba...
by pdumblet Explorer in Splunk Search 11-01-2016
0 2
0
2
brent_weaver
I have files I am ingesting that have variable formats. I want to pick those lines out that only have an IP address a...
by brent_weaver Builder in Splunk Search 11-01-2016
0 6
0
6
sravankaripe
11-01-2016 14:53:32.199 -0500 INFO StreamedSearch - Streamed search connection terminated: search......................
by sravankaripe Communicator in Splunk Search 11-01-2016
0 3
0
3
ektasiwani
Hi, I want to get results of a search in a CSV file. I tried this, but its giving me error HTTP 400 Invalid output m...
by ektasiwani Communicator in Splunk Search 11-01-2016
0 2
0
2
demkic
Hi folks, I have Splunk version 6.2.7 and am trying to create a report to display the top 10 products sold within th...
by demkic Explorer in Splunk Search 11-01-2016
0 7
0
7
tmaltizo
I need to provide month over month AV compliance given the following calculation: (Total # AV compliant servers / To...
by tmaltizo Path Finder in Splunk Search 11-01-2016
0 9
0
9
cbr654
I have 2 fields called sc_bytes & cs_bytes in my results. How can I then filter my results to give me events when th...
by cbr654 Path Finder in Splunk Search 11-01-2016
1 2
1
2
julianj
Hello Experts, I need help in determining the OS and Browser's that appear in our logs. I understand the easiest th...
by julianj Explorer in Splunk Search 11-01-2016
0 8
0
8
splgeek
Hello ppl I have a set of Error messages in an event log that looks like this ERROR [43f796d8da] there are several c...
by splgeek Explorer in Splunk Search 11-01-2016
0 2
0
2
adamsmith47
I have a lookup which has an IP address column, and I'm trying to find which if the IP addresses from this lookup tab...
by adamsmith47 Communicator in Splunk Search 11-01-2016
0 2
0
2
nickbijmoer
Hello, I want to extract a field with the field extractor in Splunk. But when I extract these logs on log 1, I will ...
by nickbijmoer Path Finder in Splunk Search 11-01-2016
0 4
0
4
whl329
I can't get any output data. My test dataset includes two fields f1 and f2: | inputcsv tmp1030.csv | arules f1 f2 ...
by whl329 Engager in Splunk Search 11-01-2016
1 2
1
2
MowLiao
Hi, Does anyone know how I can view the full city list that Splunk uses for iplocation? I'm exporting my data, then...
by MowLiao New Member in Splunk Search 10-31-2016
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...