Splunk Search

Splunk Search
Community Activity
daniel333
Should be easy enough, but not working for me. I am trying to pull a hostname of a log. I am terrible at regex and tr...
by daniel333 Builder in Splunk Search 02-10-2016
0 5
0
5
IRHM73
Hi, I wonder whether someone could help me please. I'm trying to create a search which identifies inactive users ove...
by IRHM73 Motivator in Splunk Search 02-10-2016
0 6
0
6
dkeck
Hi, I have this code: |rex max_match=0 field=values "value\":\"(?<example>(.*?))\"" |eval example=mvindex(example,0...
by dkeck Influencer in Splunk Search 02-10-2016
0 5
0
5
sunrise
Hi Splukers, I cannot get a search to produce what I want. Please help me. I tried the following search and got resu...
by sunrise Contributor in Splunk Search 02-09-2016
0 4
0
4
mookiie2005
We have a lot of searches that run to ensure we are receiving data from a Splunk forwarder and that it is still runni...
by mookiie2005 Communicator in Splunk Search 02-09-2016
0 2
0
2
LWilliamson1
Search: index="A" |dedup Id | table Id | join max=0 type=inner Id [search index="B" ]| stats count(Id) When swit...
by LWilliamson1 Explorer in Splunk Search 02-09-2016
0 1
0
1
sat94541
How do we add users or groups to roles in a Splunk search head cluster or create new roles?
by sat94541 Communicator in Splunk Search 02-09-2016
2 5
2
5
splunker9999
Hi, I have events with the below format: "phone":{"areaCode":"732","prefix":"986","lineNumber":"0245", Is there a...
by splunker9999 Path Finder in Splunk Search 02-09-2016
0 4
0
4
maclun
Hi, There is a web app that has an 'init' event on load. It carried current 'version' and 'sessionId'. All other eve...
by maclun New Member in Splunk Search 02-09-2016
0 1
0
1
chaseto
Hello Experts, I have 2 different sources source 1 has hostname, ip address source 2 has hostname, os, os version...
by chaseto Explorer in Splunk Search 02-09-2016
0 8
0
8
zabarai
Hi, I'm pretty new to spluk, I'm looking for some help with malware detection. What would the search expression l...
by zabarai Engager in Splunk Search 02-09-2016
2 1
2
1
mattholt
We need to find the most talkative indexers within Splunk for the last 24 hour period.
by mattholt New Member in Splunk Search 02-09-2016
0 1
0
1
lyndac
I am indexing JSON data. I need to be able to do stats based "by patches" and "by admin". I can't get spath or mv...
by lyndac Contributor in Splunk Search 02-09-2016
2 3
2
3
diliptmonson
Hi All, I am trying to link 2 indexes using join. I have tried the following code: index=index1| join Id[index=in...
by diliptmonson Explorer in Splunk Search 02-09-2016
0 3
0
3
jambajuice
I need to create an outputlookup file with more than 10,000 results. I've looked through the limits.conf examples an...
by jambajuice Communicator in Splunk Search 02-09-2016
3 5
3
5
SylviaB
Persistent queues are not available for splunktcp, I use several Forwarders on networks n, sending to a central forw...
by SylviaB New Member in Splunk Search 02-09-2016
0 2
0
2
taraksinha
Hi Guys, What is the difference between user and author fields along with the fields below as well? title, author, ...
by taraksinha New Member in Splunk Search 02-09-2016
0 1
0
1
anasar
Hi I have the below json file in Splunk. How do I extract based on api calls? Eg. apiname count20...
by anasar New Member in Splunk Search 02-09-2016
0 3
0
3
ststephe
I don't know if this has been answered in another question, but I'm trying to run a report for external IPs that have...
by ststephe Engager in Splunk Search 02-09-2016
0 6
0
6
Hindoo
Hello I enter in the search: index =main | timechart count by sourcetype And I "save as" a dashboard panel ... ...
by Hindoo Path Finder in Splunk Search 02-09-2016
1 11
1
11
vesug
I have a couple logins (user) and the ip addresses (c_ip) in a lookup table. As a true test to make a search to compa...
by vesug New Member in Splunk Search 02-09-2016
0 2
0
2
prakash007
I'm trying to calculate Total count and avg(count) of users on a specific file... I don't think it's the right way t...
by prakash007 Builder in Splunk Search 02-08-2016
0 5
0
5
ianformanek
When I issue 'splunk status' on Linux, the exit code is 0 even when splunk is not running. This makes it hard to use ...
by ianformanek Explorer in Splunk Search 02-08-2016
2 9
2
9
bowesmana
I have a log that records a transaction name, channel, and timing information, and need to calculate the maximum rate...
by SplunkTrust SplunkTrust in Splunk Search 02-08-2016
0 4
0
4
rgonzale6
We use inputlookup to run large numbers (thousands) of indicators against network traffic in our org. This has worke...
by rgonzale6 Path Finder in Splunk Search 02-08-2016
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...