Splunk Search

Splunk Search
Community Activity
Simona11
I have a lookup table with daily records which includes: area, alarm description, date, number of bags per area and f...
by Simona11 Explorer in Splunk Search 06-26-2025
0 5
0
5
splunklearner
Please extract User-Agent field from the below Json event .httpMessage: {<!-- --> [-]     bytes: 2     host: rbwm-api.sony.co...
by splunklearner Communicator in Splunk Search 06-25-2025
0 6
0
6
chrisboy68
Looking for SPL that will give me the ID Cost by month, only grabbing the last event (_time) for that month.  Sample ...
by chrisboy68 Contributor in Splunk Search 06-25-2025
0 14
0
14
captaincool07
Summary index or any alternativeHi, I have created a dashboard with 8 panels and time frame is last 5 minutes. Kept t...
by captaincool07 Loves-to-Learn Lots in Splunk Search 06-25-2025
0 9
0
9
Karthikeya
raw data - "attackData":{"rules":[{"data":"SCANTL&#61;10","action":"alert","selector":"","tag":"REPUTATION","id":"REP_602...
by Karthikeya Communicator in Splunk Search 06-25-2025
0 7
0
7
questionsdaniel
Hi, I'm attempting to write a search where I return a top 10 of a value. However, I am noticing that I return differe...
by questionsdaniel Observer in Splunk Search 06-24-2025
0 2
0
2
super_edition
Hello Everyone,I have 2 splunk search queriesquery-1index&#61;"my_index" kubernetes_namespace&#61;"my_ns" kubernetes_cluste...
by super_edition Path Finder in Splunk Search 06-24-2025
0 3
0
3
BraxcBT
I am logged in as the admin user, but whenever I try to access Tokens, Users, or other settings pages, I get a blank ...
by BraxcBT Explorer in Splunk Search 06-23-2025
0 3
0
3
LizAndy123
So I have successfully configured some reports and alerts that send the $result to Mattermost.My question is how to d...
by LizAndy123 Path Finder in Splunk Search 06-23-2025
0 1
0
1
hendriks
Hello, I have a simple distributed search config on a windows host, 1 SH, 1 IDX and 1 License server. Running a searc...
by hendriks Path Finder in Splunk Search 06-23-2025
0 9
0
9
jrodriguezap
I'm trying to split a pair of rows with a pair of multivalued columns. The value in both columns is related to each p...
by jrodriguezap Contributor in Splunk Search 06-22-2025
0 8
0
8
jfraley
I am looking for away to join results from two indexes based on the hostname. The main index has the hostname as just...
by jfraley Path Finder in Splunk Search 06-21-2025
0 3
0
3
mdorobek
Hello there, I try to import Azure NSG flow Events. To get the data into Splunk I use the Splunk Add-on for Microsoft...
by mdorobek Path Finder in Splunk Search 06-20-2025
1 14
1
14
bmer
Hello,I have 2 seperate splunks as below . One is "v1 endpoint" and other is "v2 endpoint"v1 endpoint: index&#61;"abc" "u...
by bmer Explorer in Splunk Search 06-19-2025
0 3
0
3
NanSplk01
I want to use the 2nd search as a subsearch only bringing back the actions. How can I do this?SEARCH| rest /servicesN...
by NanSplk01 Communicator in Splunk Search 06-19-2025
0 1
0
1
ashish_d
Please help share query to check &gt; network logs and firewall blocks for specific Host machine&gt; LDAP password login fa...
by ashish_d New Member in Splunk Search 06-19-2025
0 1
0
1
LogUx
Hello Splunkers !!How can I efficiently use the mvexpand command to expand multiple multi-value fields, considering i...
by LogUx Motivator in Splunk Search 06-18-2025
0 12
0
12
avikc100
this is my log  i need a report like below: where I can see price difference in a single report. I don't want to put ...
by avikc100 Path Finder in Splunk Search 06-17-2025
0 2
0
2
bhawana2192
I am using Splunk Cloud 6.5.0 version. How can i remove latitude and longitude values while hovering over map and di...
by bhawana2192 New Member in Splunk Search 06-17-2025
0 8
0
8
anthonyi
Hello.This search returns zero results, but a manual "OR" search shows results. I cannot find the reason (neither can...
by anthonyi Explorer in Splunk Search 06-16-2025
0 3
0
3
Raj_Splunk_Ing
Hi, I have this search query where i aggregate using the stats and sum by few fields...When I run the query in splunk...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-15-2025
0 6
0
6
InspiredSplunk
Hi I want to know how long and when either of two games are being played on the PS4 or a laptop and be notified via e...
by InspiredSplunk Observer in Splunk Search 06-13-2025
0 5
0
5
Soonerseast
Hi my data is comma delimited   , there  are 2 rows with a header. I'fd like the columns to be split by the comma int...
by Soonerseast Loves-to-Learn in Splunk Search 06-13-2025
0 3
0
3
rishabhpatel20
Hello, I have lookup file uploaded and now I want to see the data, I am not able to see it on map , I can see the det...
by rishabhpatel20 Explorer in Splunk Search 06-13-2025
0 2
0
2
AleCanzo
Hi, i'm searching for a way to modify my app/dashboard to be able to modify the entries of a table (such as delete/du...
by AleCanzo Path Finder in Splunk Search 06-13-2025
0 2
0
2
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors