Splunk Search

Splunk Search
Community Activity
Nagalakshmi
Hi Team, We have users logging in multiple devices. So, we need to showcase the count of devices  and user logged in....
by Nagalakshmi Path Finder in Splunk Search 08-28-2023
0 6
0
6
shashank_24
Hi, I am trying to join 2 searches with produce some results but I am getting this error which says -  "subsearch pro...
by shashank_24 Path Finder in Splunk Search 08-27-2023
0 7
0
7
mohammadsharukh
Dear All,   I was going through a Splunk conf 21 where the narrator explained to use the index time instead of search...
by mohammadsharukh Path Finder in Splunk Search 08-27-2023
0 1
0
1
kwells
Is it possible to set up the VSCode extension to connect to multiple instances?
by kwells New Member in Splunk Search 08-26-2023
0 1
0
1
aliosa
Hello I am beginner with Splunk.I made a query and my search result is like      text1 text2 text3 response: { "st...
by aliosa Loves-to-Learn Lots in Splunk Search 08-26-2023
0 5
0
5
splunker09
I have an index which has 15 hosts and around 15 sourcetypes mapped to all hosts.  How can I get events of only few s...
by splunker09 Engager in Splunk Search 08-26-2023
0 1
0
1
Thulasinathan_M
Hi Splunk Experts,I've a big list of rex commands in my search query. While using dashboard I added those rex command...
by Thulasinathan_M Contributor in Splunk Search 08-25-2023
0 2
0
2
splunk219783
I thought this would be easy but i'm struggling.  I have a CSV of firewall rules from yesterday, and a CSV of Firewal...
by splunk219783 Path Finder in Splunk Search 08-25-2023
0 1
0
1
RahulMisra
I have a lookup file( with one column combinedrules{}) which would be dynamic and i want to run a scheduled search to...
by RahulMisra Engager in Splunk Search 08-25-2023
0 10
0
10
sekhar463
hi All, i am using below search to get status if any offline  and i want to create alert if status offline for more t...
by sekhar463 Path Finder in Splunk Search 08-25-2023
0 18
0
18
mikfro
HiWe have logs of images created in a series, like below. They are identified by a unique series id, the number of ev...
by mikfro Loves-to-Learn in Splunk Search 08-25-2023
0 2
0
2
superuser88
 INDEX Name generated (10 million new records every day)INDEX Fields username, secret, key Lookup file secrets.csv wi...
by superuser88 Engager in Splunk Search 08-25-2023
0 4
0
4
rstrong30
I simply need to timechart the numeric values from field that is being returned.  For exampleindex=proxy | timechart ...
by rstrong30 Loves-to-Learn in Splunk Search 08-24-2023
0 1
0
1
superuser88
I have two indexesIndex accounts: [user. payroll]Index employees: [user, emp_details, emp_information] I am trying to...
by superuser88 Engager in Splunk Search 08-24-2023
0 2
0
2
dural_yyz
I'm looking specifically at the index for _configtracker to audit changes to serverclass.conf file.  Because the natu...
by dural_yyz Motivator in Splunk Search 08-24-2023
0 3
0
3
Woodpecker
Hi,is it possible to search a field value and then count it for example first today and then add the count of the sam...
by Woodpecker Path Finder in Splunk Search 08-24-2023
0 0
0
0
muqeeiz
Hi, I have the following log lines:2023-08-23 06:27:13,551 DEBUG [org.keycloak.protocol.oidc.utils.RedirectUtils] (ex...
by muqeeiz Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
Splunk_321
I have a splunk query to get execution time of methods shown below   basesearch | where like(method,"A") OR like(met...
by Splunk_321 Path Finder in Splunk Search 08-24-2023
0 1
0
1
dwelbba00
I'm working on building a dashboard that will take a base report and parse it into different items that can be flagge...
by dwelbba00 New Member in Splunk Search 08-24-2023
0 5
0
5
hitong
Hi,   When I extract any fields from json log, following error is generated  "The extraction failed. If you are extra...
by hitong Loves-to-Learn in Splunk Search 08-24-2023
0 3
0
3
woodlandrelic
HiI am trying to add % to the "by percent" column only.  I can't seem to get it to show.Thanks  
by woodlandrelic Path Finder in Splunk Search 08-23-2023
0 3
0
3
LearningGuy
Hello,How to join data from index and dbxquery without using JOIN, APPEND or stats command?Issue with JOIN:  limit of...
by LearningGuy Motivator in Splunk Search 08-23-2023
0 12
0
12
abi2023
| timechart span=1mon count by status | addtotals row=t col=f labelfield=Total True False "Not available" fieldname="...
by abi2023 Path Finder in Splunk Search 08-23-2023
0 2
0
2
mninansplunk
Hello,I'm still in the learning process of Splunk searches and I have been tasked to create a table that contains onl...
by mninansplunk Path Finder in Splunk Search 08-23-2023
0 5
0
5
pmunaret
Hi all, I encountered the problem in MLTK that the data from the search is passed in multiple chunks to my custom cla...
by pmunaret Explorer in Splunk Search 08-23-2023
1 2
1
2
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors