Splunk Search

Splunk Search
Community Activity
jijomathai
We have Splunk message validation scenarios in our test scenarios and need to know whether any Open API's are availab...
by jijomathai New Member in Splunk Search 09-20-2023
0 0
0
0
Neel881
Hello,How to fill the gaps from days with no data in tstats + timechart query?Query: | tstats count as Total where in...
by Neel881 Path Finder in Splunk Search 09-20-2023
0 7
0
7
sarit_s
HelloI have a table with 7 columns, some of them calculated from lookupI want to count the total of one of the column...
by sarit_s Communicator in Splunk Search 09-20-2023
0 1
0
1
Dustem
hi guys, I want to detect that more than 10 different ports of the same host are sniffed and scanned every 15 minutes...
by Dustem Explorer in Splunk Search 09-19-2023
0 7
0
7
mohammadsharukh
I am working to create a use case to detect account created and deleted within short period of timeCould you please g...
by mohammadsharukh Path Finder in Splunk Search 09-19-2023
0 1
0
1
CocoaCollette
How do I rename/conjoin/remove the space between the field "ThreeDSecureResult" and "description"? The value is comin...
by CocoaCollette New Member in Splunk Search 09-19-2023
0 1
0
1
srajabi
Hey I have the following query: ```| makeresults | eval prediction_str_body="[{'stringOutput':'Alpha','doubleOutput':...
by srajabi Engager in Splunk Search 09-19-2023
0 2
0
2
LearningGuy
Hello,How to pre-calculate and search historical data from correlation between index and CSV/DB lookup?For example:Fr...
by LearningGuy Motivator in Splunk Search 09-19-2023
0 2
0
2
BK_MSP
I had data like this in Splunk.DT=2023-09-13T23:59:56.029-0500|LogId=WFTxLog|AppId=SWBS|AppInst=server1:/apps/comp/sw...
by BK_MSP New Member in Splunk Search 09-19-2023
0 1
0
1
Yashvik
Hello All,I need to identify the top log sources which are sending large data to Splunk. Tried Licence master dashboa...
by Yashvik Explorer in Splunk Search 09-19-2023
0 8
0
8
neerajs_81
Hi All, just wondering if anyone has a search that shows which user deleted another user in Linux  ?Typically in the ...
by neerajs_81 Builder in Splunk Search 09-19-2023
0 3
0
3
ssaenger
Hi All,i have read similar posts but none that will get me to an answer.My log entry is this;2023-09-19 16:17:01,306 ...
by ssaenger Communicator in Splunk Search 09-19-2023
0 4
0
4
rjdefrancisco
The following works fine in the Search app:   ... | makemv delim=";" hashes | ...   The equivalent curl call   curl ....
by rjdefrancisco Explorer in Splunk Search 09-19-2023
0 2
0
2
thisissplunk
I want to list about 10 unique values of a certain field in a stats command. I cannot figure out how to do this. I fi...
by thisissplunk Builder in Splunk Search 09-19-2023
1 8
1
8
jip31
HiI have a basic questions about the inputs.conf fileIn our apps, we have a inputs.conf file under etc/apps/test/inpu...
by jip31 Motivator in Splunk Search 09-19-2023
0 1
0
1
MG
I have the actual list of indexes in a lookup file. I ran below query to find the list of indexes with the latest ing...
by MG Engager in Splunk Search 09-19-2023
0 8
0
8
RahulMisra
I have an output of   index=feds  | fillnull value="" | table httpRequest.clientIp labels{}.name awswaf:clientip:geo:...
by RahulMisra Engager in Splunk Search 09-19-2023
0 5
0
5
MScottFoley
I have logs with a Customer field where the name of the customer is not consistent.    customer=Bobs Pizza  customer=...
by MScottFoley Path Finder in Splunk Search 09-19-2023
0 5
0
5
ivan123357
Hi! I am faced with the following task and do not understand which way to go. I want to create an alert that will be ...
by ivan123357 Explorer in Splunk Search 09-19-2023
0 3
0
3
aditsss
Hi Team,Below is my querysearch index="abc" sourcetype =$Regions$ source="/amex/app/gfp-settlement-raw/logs/gfp-settl...
by aditsss Motivator in Splunk Search 09-19-2023
0 6
0
6
kteng2024
I am looking for indexes which are utilizing only 10%-20% of storage allocated to them. Can i please know is there an...
by kteng2024 Path Finder in Splunk Search 09-19-2023
0 3
0
3
Marta88
Hi, I would like to know the difference between version 1 and version 2 of the stats command. Thank you Kind regards ...
by Marta88 Explorer in Splunk Search 09-19-2023
1 3
1
3
tayshawn
Hello everyone! We have a container service running on AWS ECS with Splunk log driver enabled (via HEC token). At mom...
by tayshawn New Member in Splunk Search 09-18-2023
0 1
0
1
BeaGarcia
Hello! I want to count how many different kind of errors appeared for different services. At the moment, I'm searchin...
by BeaGarcia New Member in Splunk Search 09-18-2023
0 1
0
1
Roy_9
Hello, I am trying to find the dates  when the host stopped sending logs to splunk in the last 6 months.I have used t...
by Roy_9 Motivator in Splunk Search 09-18-2023
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...