Splunk Search

Splunk Search
Community Activity
AL3Z
Hi,I'm trying to exclude list of sites from my search from lookup table its not working as expected, base search sub ...
by AL3Z Builder in Splunk Search 07-18-2023
0 11
0
11
man03359
Hi All!I want to calculate the sum of failed and declined | eval Msg=if((Failure_Message=="200 Emv error " OR Failure...
by man03359 Communicator in Splunk Search 07-18-2023
0 12
0
12
keishsplunk
Hi All, we had successfully upgraded to Splunk 9.0.4.  However, we observed that when using tstats command, we are ge...
by keishsplunk Explorer in Splunk Search 07-18-2023
0 4
0
4
nmarun
Hi,[12:30:13 INF 0ceafa153290582e1f1faec3f98d84ac] Gateway API|Request...[12:30:15 INF 0ceafa153290582e1f1faec3f98d84...
by nmarun Explorer in Splunk Search 07-17-2023
0 5
0
5
dantimola
Since Splunk stream doesn't support M1/arm-based processors yet, are there any Splunk stream alternatives that we can...
by dantimola Communicator in Splunk Search 07-17-2023
0 0
0
0
isac_santana
Guys, good morningI'm having trouble inverting this table below. I need to leave the horizontal "key_type" informatio...
by isac_santana Explorer in Splunk Search 07-17-2023
0 2
0
2
abi2023
I have spl in splunkindex=demo search compliance= standard1 | timechart span=1week count by status | add totals row=t...
by abi2023 Path Finder in Splunk Search 07-17-2023
0 1
0
1
henryf
I have installed Splunk add on for AWS and created the inputs, which have a listed source type. However, when I try t...
by henryf Explorer in Splunk Search 07-17-2023
0 7
0
7
Lithyum
Hi.I need help in understanding how this can be done:The application's log have a multivalue like this:<somedata> [fi...
by Lithyum Engager in Splunk Search 07-17-2023
0 2
0
2
emzed
Is there anyone who can explain me strange behaivor of "values" function. I created statistic by "stats" with "values...
by emzed Path Finder in Splunk Search 07-17-2023
0 4
0
4
rissois
I've a search that return a table like this:column1             column2               column3      a                 ...
by rissois Observer in Splunk Search 07-17-2023
0 2
0
2
rezaeimo
i have a search query and i want to add another condition to check the url if test!=staging. the first test is coming...
by rezaeimo Explorer in Splunk Search 07-17-2023
0 9
0
9
maayan
Hi,I have a table of 3 columns: Event name, time(=when the event happened) and source (file name).I need to create a ...
by maayan Path Finder in Splunk Search 07-17-2023
0 1
0
1
rikinet
I have JSON event data like this (it is shown as a collapsable tree structure in the event view): { "data": { ...
by rikinet Path Finder in Splunk Search 07-16-2023
0 3
0
3
Liran
I need to create a baseline for what is common in an environment before creating a rule.The rule can be as simple as:...
by Liran Observer in Splunk Search 07-16-2023
0 2
0
2
sjringo
I have been trying to figure this out but getting stumped. I have seen other questions similar but just slightly diff...
by sjringo Contributor in Splunk Search 07-15-2023
0 8
0
8
john_arrowwood
I am trying to summarize AWS ELB Access Logs.  Once I get the raw URLs, I need to substitute out the path and query p...
by john_arrowwood Explorer in Splunk Search 07-15-2023
0 4
0
4
AyushiSrivas
I have a list of below host in a csvuasws12usaws120usaws11usaws13susaws13usaws130usaws14usaws15usaws16usaws17usaws173...
by AyushiSrivas Loves-to-Learn in Splunk Search 07-15-2023
0 8
0
8
simpkins1958
We have table with a list of users. Some user names are all lower case, some all upper case, some mixed case. We can ...
by simpkins1958 Contributor in Splunk Search 07-15-2023
0 6
0
6
LearningGuy
Split pattern in CSV lookup format into multiple rows| lookup table.csvNote that the number of SubnetID-IP pair is no...
by LearningGuy Motivator in Splunk Search 07-14-2023
0 3
0
3
cdieringerwm
Greetings.Suppose I have an event schema of just a URL, where the query section of the URL may change: ```ndjson{ url...
by cdieringerwm Observer in Splunk Search 07-14-2023
0 3
0
3
mahesh27
|tstats count where index=app-data  (TERM(Errors) TERM( Started) TERM( in)  TERM(*s)  TERM(*ms))  OR (TERM(system)  T...
by mahesh27 Communicator in Splunk Search 07-14-2023
0 3
0
3
manju1318
Hi, I am working on a task: calculating the percentage of employees working in food industry for each country. I trie...
by manju1318 Engager in Splunk Search 07-14-2023
0 2
0
2
sabari80
How to calculate 90 percentile and average on the same query. following query is not providing 90 percentile values  ...
by sabari80 Explorer in Splunk Search 07-14-2023
0 5
0
5
AL3Z
Hi,I need a  help in enhancing the below search  if users triggers one or more of these policies:Index=dlp sourcetype...
by AL3Z Builder in Splunk Search 07-14-2023
0 3
0
3
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...