Splunk Search

Splunk Search
Community Activity
bluewizard
I have the following search to track search usage, i have a list of user who i want to track in a csv file. However, ...
by bluewizard Explorer in Splunk Search 07-26-2023
0 2
0
2
Harish2
index=abc sourcetype=app_logs |stats count as events by host, host_ip |where events >0  When i schedule this as alert...
by Harish2 Path Finder in Splunk Search 07-26-2023
0 2
0
2
AA1
0
1
jip31
HiI have a field called ObjectD which is always different for each eventsBut in this field, there is always à charact...
by jip31 Motivator in Splunk Search 07-25-2023
0 18
0
18
Kirthika
I have the following query,   index="xxxx" source="*$Device_ID$*xxxx*" | eval Device_ID=mvindex(split(source,"/"),5) ...
by Kirthika Path Finder in Splunk Search 07-25-2023
0 6
0
6
anmar02930
I have a search that has "index=A", "Source=A", "Source=B" and both sources have the column "Address"I want to compar...
by anmar02930 Engager in Splunk Search 07-25-2023
0 1
0
1
swe
hi there, I want to display an image based on the result of a search. My dashboard has a "base search" which is use...
by swe Path Finder in Splunk Search 07-25-2023
1 6
1
6
ddetlef
I am successfully using some simple LDAPSEARCH + LDAPGROUP searches to produce membership lists for various AD groups...
by ddetlef Explorer in Splunk Search 07-25-2023
0 6
0
6
JohnEGones
HI people, I want from a query to only print out the first n-characters of the field value. So:   index=someIndex sou...
by JohnEGones Communicator in Splunk Search 07-25-2023
0 3
0
3
sarvananth
I'm new to Splunk Enterprise, and my task is to forward logs from Splunk HF (AWS EC2 instance) to an AWS Cloud Watch ...
by sarvananth Explorer in Splunk Search 07-25-2023
0 3
0
3
interrobang
Hi everyone,Working on a dash for which the goal is to automate manual data entry which needs to take place over 100s...
by interrobang Explorer in Splunk Search 07-24-2023
0 5
0
5
dungnq
Hi team,I have raw data with status: 200, 404, 503.183080267.ap-southeast-1.elb.amazonaws.com | app | 200183080267.ap...
by dungnq Loves-to-Learn in Splunk Search 07-24-2023
0 4
0
4
LearningGuy
How to perform lookup from index search with dbxquery?| index=vulnerability_index| table ip_address, vulnerability, s...
by LearningGuy Motivator in Splunk Search 07-24-2023
0 10
0
10
anikeshp7
I have created a lookup test123.csv owned by me and  A user queries and he gets the error - "User has insufficient pe...
by anikeshp7 Path Finder in Splunk Search 07-24-2023
0 6
0
6
Awanish1212
Suppose there are 10 events as "raw text" in Splunk in last 7 days as below :Event 1 : 7/11/23 5:28:33.265 PM"host":"...
by Awanish1212 Explorer in Splunk Search 07-24-2023
0 1
0
1
Talking_Master
Hi looking to create a time chart that has duration on the y axis and start date on the x-axis. The Y- axis is in hou...
by Talking_Master Explorer in Splunk Search 07-24-2023
0 1
0
1
PaulaCom
Hi All I'd like some help please with a query thats been asked of me and its a little out of my depth the current bel...
by PaulaCom Path Finder in Splunk Search 07-24-2023
0 5
0
5
Harikiranjammul
I have a data like belowServename     downtimeWeb1               7 day 2 hWeb2                2 h 23 minWeb2         ...
by Harikiranjammul Explorer in Splunk Search 07-24-2023
0 3
0
3
AnilPujar
is there any function available in splunk which converts the data in string format to json, which is actually json da...
by AnilPujar Path Finder in Splunk Search 07-24-2023
0 3
0
3
Falko
I tried to determine the size of my indexes in preparation for a Splunk Cloud Migration. I figured I could use the "e...
by Falko Explorer in Splunk Search 07-24-2023
0 0
0
0
zacksoft_wf
I am running this in Splunk ES (Enterprise Security). My objective is to find out those savedsearch_name whose averag...
by zacksoft_wf Contributor in Splunk Search 07-24-2023
0 1
0
1
jwalzerpitt
I am trying to run the following tstats search: | tstats summariesonly=true estdc(Malware_Attacks.dest) as "infected...
by jwalzerpitt Influencer in Splunk Search 07-24-2023
0 5
0
5
cinimins
Hello,I would like to make a stacked column chart with number of errors by hour and error type (warning, error, etc)T...
by cinimins Explorer in Splunk Search 07-24-2023
0 2
0
2
csar5634
Hi and just reaching out as stumped. Very grateful for assistance. This query returns the following in the statistics...
by csar5634 Explorer in Splunk Search 07-23-2023
0 6
0
6
sigma
1) I want to list top 10 usernames those got most 403 status codes.     for example a username named sigma got 2000 o...
by sigma Path Finder in Splunk Search 07-23-2023
0 4
0
4
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors