Splunk Search

Splunk Search
Community Activity
splunker09
I have an index which has 15 hosts and around 15 sourcetypes mapped to all hosts.  How can I get events of only few s...
by splunker09 Engager in Splunk Search 08-26-2023
0 1
0
1
Thulasinathan_M
Hi Splunk Experts,I've a big list of rex commands in my search query. While using dashboard I added those rex command...
by Thulasinathan_M Contributor in Splunk Search 08-25-2023
0 2
0
2
splunk219783
I thought this would be easy but i'm struggling.  I have a CSV of firewall rules from yesterday, and a CSV of Firewal...
by splunk219783 Path Finder in Splunk Search 08-25-2023
0 1
0
1
RahulMisra
I have a lookup file( with one column combinedrules{}) which would be dynamic and i want to run a scheduled search to...
by RahulMisra Engager in Splunk Search 08-25-2023
0 10
0
10
sekhar463
hi All, i am using below search to get status if any offline  and i want to create alert if status offline for more t...
by sekhar463 Path Finder in Splunk Search 08-25-2023
0 18
0
18
mikfro
HiWe have logs of images created in a series, like below. They are identified by a unique series id, the number of ev...
by mikfro Loves-to-Learn in Splunk Search 08-25-2023
0 2
0
2
superuser88
 INDEX Name generated (10 million new records every day)INDEX Fields username, secret, key Lookup file secrets.csv wi...
by superuser88 Engager in Splunk Search 08-25-2023
0 4
0
4
rstrong30
I simply need to timechart the numeric values from field that is being returned.  For exampleindex=proxy | timechart ...
by rstrong30 Loves-to-Learn in Splunk Search 08-24-2023
0 1
0
1
superuser88
I have two indexesIndex accounts: [user. payroll]Index employees: [user, emp_details, emp_information] I am trying to...
by superuser88 Engager in Splunk Search 08-24-2023
0 2
0
2
dural_yyz
I'm looking specifically at the index for _configtracker to audit changes to serverclass.conf file.  Because the natu...
by dural_yyz Motivator in Splunk Search 08-24-2023
0 3
0
3
Woodpecker
Hi,is it possible to search a field value and then count it for example first today and then add the count of the sam...
by Woodpecker Path Finder in Splunk Search 08-24-2023
0 0
0
0
muqeeiz
Hi, I have the following log lines:2023-08-23 06:27:13,551 DEBUG [org.keycloak.protocol.oidc.utils.RedirectUtils] (ex...
by muqeeiz Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
Splunk_321
I have a splunk query to get execution time of methods shown below   basesearch | where like(method,"A") OR like(met...
by Splunk_321 Path Finder in Splunk Search 08-24-2023
0 1
0
1
dwelbba00
I'm working on building a dashboard that will take a base report and parse it into different items that can be flagge...
by dwelbba00 New Member in Splunk Search 08-24-2023
0 5
0
5
hitong
Hi,   When I extract any fields from json log, following error is generated  "The extraction failed. If you are extra...
by hitong Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
woodlandrelic
HiI am trying to add % to the "by percent" column only.  I can't seem to get it to show.Thanks  
by woodlandrelic Path Finder in Splunk Search 08-23-2023
0 3
0
3
LearningGuy
Hello,How to join data from index and dbxquery without using JOIN, APPEND or stats command?Issue with JOIN:  limit of...
by LearningGuy Motivator in Splunk Search 08-23-2023
0 12
0
12
abi2023
| timechart span=1mon count by status | addtotals row=t col=f labelfield=Total True False "Not available" fieldname="...
by abi2023 Path Finder in Splunk Search 08-23-2023
0 2
0
2
mninansplunk
Hello,I'm still in the learning process of Splunk searches and I have been tasked to create a table that contains onl...
by mninansplunk Path Finder in Splunk Search 08-23-2023
0 5
0
5
pmunaret
Hi all, I encountered the problem in MLTK that the data from the search is passed in multiple chunks to my custom cla...
by pmunaret Explorer in Splunk Search 08-23-2023
1 2
1
2
saurabhkunte
Hello,I have a lookup file with data in following format name _timesrv-a.xyz.com 2017.07.23srv-b.wxyz.com 2017.07.23 ...
by saurabhkunte Path Finder in Splunk Search 08-23-2023
1 9
1
9
humi
Hi all, i count the number of ssl-login-fail for each hour. index... host... action="ssl-login-fail" | timechart span...
by humi Explorer in Splunk Search 08-23-2023
0 3
0
3
sulaimancds
index=o365 [ | inputlookup watchlistriskyusers.csv | rename email AS query | fields query ] sourcetype="o365:manageme...
by sulaimancds Engager in Splunk Search 08-23-2023
0 7
0
7
Coder1a
Hello, I am new to splunk rex, so need help for regex. In logs, i have extracted  string, however again i need to ext...
by Coder1a Loves-to-Learn in Splunk Search 08-23-2023
0 1
0
1
sahil237888
Need help in creating a query to get the result from one sourcetype and get other field values based on the output fr...
by sahil237888 Path Finder in Splunk Search 08-23-2023
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...