Splunk Search

Splunk Search
Community Activity
vader13
I have six different SPL queries that I run on a specific IP Address.  Is it possible to save a search as a report, s...
by vader13 Explorer in Splunk Search 09-18-2023
0 2
0
2
bimatomsoc
There are some values of IP addresses from `cim_Authentication_indexes`.This index is for look up.I want to make if t...
by bimatomsoc Explorer in Splunk Search 09-18-2023
0 4
0
4
danroberts
Hello, Can anyone help me to extract the below file name which is OU_..... from the below raw data.  12:04:19.85 14/0...
by danroberts Explorer in Splunk Search 09-18-2023
0 7
0
7
Anantha123
Please help me on how I can check if the field value is continuously increasing for 3 hours. tried below query but do...
by Anantha123 Communicator in Splunk Search 09-18-2023
0 2
0
2
alex4
I have a below Splunk query which gives me the result. My SPL searches the " eventType IN (security.threat.detected, ...
by alex4 Loves-to-Learn Lots in Splunk Search 09-18-2023
0 3
0
3
pukka
Hello,I was aware that splunk is very versatile application which allows the users to manipulate the data is many way...
by pukka Loves-to-Learn Everything in Splunk Search 09-17-2023
0 14
0
14
grotti
Hello! I need some help from splunkers!!! I'm using the search index=notable | search status_label=Closed | top limit...
by grotti Engager in Splunk Search 09-17-2023
0 2
0
2
Niro
Hello, I have the following search     index=wineventlog EventCode=4728 OR EventCode = 4731 OR EventCode=4729 OR Even...
by Niro Explorer in Splunk Search 09-17-2023
0 2
0
2
abi2023
in my search I have no lookup command. Anyone knows why I am getting this error.
by abi2023 Path Finder in Splunk Search 09-17-2023
0 1
0
1
anil1219
Hi, I want to use timechart or bucket span to view the result every 30 mins using below query. Could you please let m...
by anil1219 Engager in Splunk Search 09-17-2023
0 2
0
2
immutableT
Hello, There must be something `rex` specific with my query below since it is not extracting the fields, while the re...
by immutableT Engager in Splunk Search 09-16-2023
0 2
0
2
jaydiare
Hello, I wonder if somebody can please help me to sort the following data: Into this table: Any ideas are welcome I...
by jaydiare Explorer in Splunk Search 09-16-2023
0 2
0
2
subitha_kennedy
Timezone issue --------different data is visible to different location users, when I select previous month.. conditio...
by subitha_kennedy Loves-to-Learn Everything in Splunk Search 09-15-2023
0 6
0
6
jeck11
Here are three lines of the file to illustrate what I'm going for:Line from fileDesired fieldURI : https://URL.net/to...
by jeck11 Path Finder in Splunk Search 09-15-2023
0 2
0
2
abi2023
I try change permission to all app option but I don't see the option. I s anyother way make my macro available for al...
by abi2023 Path Finder in Splunk Search 09-15-2023
0 1
0
1
richtate
Good day, I have this SPL: index=test_7d sourcetype="Ibm:BigFix:CVE" earliest=-1d | search FixletSourceSeverityTxt="C...
by richtate Path Finder in Splunk Search 09-15-2023
0 2
0
2
LearningGuy
Hello,How to outputlookup csv with permission?  ***Note that I am not Splunk admin - I only have access to Splunk GUI...
by LearningGuy Motivator in Splunk Search 09-15-2023
0 6
0
6
mvagionakis
Hello Splunkers, I have two questions today, concerning user's queries and performance impact. I couldn't find a cle...
by mvagionakis Path Finder in Splunk Search 09-15-2023
0 5
0
5
avi7326
How to extract fields which comes under message and failedRecords.
by avi7326 Path Finder in Splunk Search 09-15-2023
0 1
0
1
Jouman
Dear all, I have a list of latitude and longitude pairs from my observed events and try to get the corresponding stre...
by Jouman Path Finder in Splunk Search 09-15-2023
0 0
0
0
mohsplunking
Hello Splunkers, Can someone help me with a query to detect multiple http errors from single IP , basically when the ...
by mohsplunking Path Finder in Splunk Search 09-14-2023
0 6
0
6
jip31
HiWhen I run the command below, it works fine index=toto event_id=4688 | eval file_name=if(event_id==4688, replace(N...
by jip31 Motivator in Splunk Search 09-14-2023
0 6
0
6
abhijeetallu
The first search query returns a count of 26 for domain X : index="web" sourcetype="weblogic_stdout" loglevel IN ("Em...
by abhijeetallu Engager in Splunk Search 09-14-2023
0 2
0
2
venugoski
Splunk queries not returning anything in table. I see events matching for these queries but nothing under 'Statistics...
by venugoski Explorer in Splunk Search 09-14-2023
0 3
0
3
10Q
Hi,I'm trying to set a specific color to each one of 4 my dynamic labels of my 3 trellis pie charts.I already added s...
by 10Q Engager in Splunk Search 09-14-2023
1 0
1
0
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...