Splunk Search

Splunk Search
Community Activity
msackett
I am trying to combine two searches into one chart. I am trying the append command, but am not having any luck gettin...
by msackett New Member in Splunk Search 09-28-2015
0 1
0
1
xvxt006
Hi, I have events like below. I need to extract 4EU56, 4YB2. the number of lines between statictext and Y-EER-RTY w...
by xvxt006 Contributor in Splunk Search 09-28-2015
0 8
0
8
rajnish1202
Hi, I have been using a props.conf file to extract fields in my event logs, but it does not seem to be working. Belo...
by rajnish1202 Explorer in Splunk Search 09-28-2015
0 2
0
2
pdjhh
Hi, I have set up a couple of alerts and have chosen an inline table in the subsequent email. The contents of that t...
by pdjhh Communicator in Splunk Search 09-28-2015
0 2
0
2
splunked38
Hi, I'm currently using the expensive transaction command to keep transactions without any duplicates. So if I had ...
by splunked38 Communicator in Splunk Search 09-28-2015
0 2
0
2
LuiesCui
Hi guys, I want to make a table with list in it with Splunk and I really need some help! I got a IPS to analyse and t...
by LuiesCui Communicator in Splunk Search 09-28-2015
0 9
0
9
kharma
So I currently have Windows event log (security) files and am attempting to compare two strings that are pulled out v...
by kharma New Member in Splunk Search 09-27-2015
0 3
0
3
sunnyparmar
Hi, I have a one text file which have some entries with the file types .pdf, .tif so now i want to make one hourly d...
by sunnyparmar Communicator in Splunk Search 09-26-2015
0 8
0
8
loggeruk
Greetings, I am trying to display the value of "002:emailsqu=33" over the last 24 hours and then graph it. The log c...
by loggeruk Explorer in Splunk Search 09-25-2015
0 5
0
5
raby1996
Hi all, currently I'm using a search Which gives me something like this for each group/event Group B...
by raby1996 Path Finder in Splunk Search 09-25-2015
0 3
0
3
giladirim
Hi, I have "impression" events for a mobile page that has many games on it, and they have 1 field called "game_ids" ...
by giladirim Engager in Splunk Search 09-25-2015
0 1
0
1
bfnpmsz
Ok, treat me nice, please... I am working on a dashboard which totals and reports data from two different date range...
by bfnpmsz New Member in Splunk Search 09-25-2015
0 5
0
5
marcusnilssonmr
Splunk mobile access server is marked as legacy in the documentation, what is the alternative?
by marcusnilssonmr Path Finder in Splunk Search 09-25-2015
0 1
0
1
santorof
I am currently trying to work on a search where are admins in my results. I want the search to show only regular user...
by santorof Communicator in Splunk Search 09-25-2015
0 6
0
6
tech8260
I'm trying to get our splunk server to index the local /var/log/audit/audit.log, but no matter what I do I don't see ...
by tech8260 New Member in Splunk Search 09-25-2015
0 2
0
2
hettervik
Hi! I'm trying to configure a multisite indexer cluster with two sites; site1 and site2. There are one peer in site1...
by SplunkTrust SplunkTrust in Splunk Search 09-25-2015
0 1
0
1
sheamus69
Hi, I'm trying to create a MAP search to see if Event B triggers within a certain time window of Event A being trigg...
by sheamus69 Communicator in Splunk Search 09-25-2015
0 1
0
1
szal
I'm generating a timechart that is supposed to display a daily figure which is an accumulation of total logged in hou...
by szal Explorer in Splunk Search 09-25-2015
0 6
0
6
raby1996
Hi all, So I have a search that i have saved as a report that looks like this when it completes Group Bun...
by raby1996 Path Finder in Splunk Search 09-24-2015
0 1
0
1
TheJagoff
Splunk Free Enterprose download. Trying to start Splunk - non-root user. To "Start and Show Plunk" I get the error: ...
by TheJagoff Communicator in Splunk Search 09-24-2015
0 4
0
4
stanbridge
Hi there! I have run the following search... index="prop_data" uri=*/property/*/* | stats avg(execution_time) by ur...
by stanbridge New Member in Splunk Search 09-24-2015
0 4
0
4
Cuyose
I see a ton of these type questions, but none seem to pertain to what I am doing or I just dont understand them. I h...
by Cuyose Builder in Splunk Search 09-24-2015
0 1
0
1
aramakrishnan
I have the following log(s) from which I want to extract the value inside the parenthesis. The parenthesis field is p...
by aramakrishnan New Member in Splunk Search 09-24-2015
0 5
0
5
deanamite91
I have the following search string index="commercial_performance" "Efficiency Variance *" OR "Intervention Variance ...
by deanamite91 Explorer in Splunk Search 09-24-2015
0 4
0
4
kapanig
Can I replace the maps app images with a static single image? I want to assign static _lat and _lon to a specific pla...
by kapanig Explorer in Splunk Search 09-24-2015
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...