Splunk Search

Splunk Search
Community Activity
jhilton90
I have an index called index=advanced_hunting and in this index there is a field called category, where there are sev...
by jhilton90 Path Finder in Splunk Search 06-21-2023
0 2
0
2
wgawhh5hbnht
I have a lookup table that contains usernames and userids. I want to use this to match a username to userid & vice ve...
by wgawhh5hbnht Communicator in Splunk Search 06-21-2023
0 4
0
4
dhirendra761
Hi @Splunkers, I created panel which give output based on  multiselected fields, both are having different sources/in...
by dhirendra761 Contributor in Splunk Search 06-21-2023
0 7
0
7
ydholakia
I was setting `ModularInputs` to WARNING.. wanted to know the default value of `AdminManagerDispatch` ... as of now i...
by ydholakia Splunk Employee Splunk Employee in Splunk Search 06-21-2023
0 0
0
0
DanAlexander
Hi people, I need help designing a regex that will cover the below strings, please. ---------------------------------...
by DanAlexander Communicator in Splunk Search 06-21-2023
0 9
0
9
mrphu
Please! Help me fix search code. Thank you very much!  
by mrphu New Member in Splunk Search 06-21-2023
0 1
0
1
Aj01
index="go_pro" Appid="APP-5f" prod (":[ Axis" OR "ErrorCode" OR "System Error" OR "Invalid User :")| rex field=_raw "...
by Aj01 Path Finder in Splunk Search 06-21-2023
0 4
0
4
risingflight143
Hi All i have an unified group(i.e office365 unified group) created from Office365.  i want to know membership detail...
by risingflight143 Explorer in Splunk Search 06-21-2023
0 1
0
1
siksaw33
  I'm trying to extract some information from nested JSON data stored in Splunk. Here's a simplified and anonymize...
by siksaw33 Path Finder in Splunk Search 06-21-2023
0 11
0
11
alexeysharkov
Hello!  I have some events just like this 2023-06-20 17:25:35.878 INFO Trace:[::] [#kafka-producer-network-thread | p...
by alexeysharkov Path Finder in Splunk Search 06-20-2023
0 6
0
6
AL3Z
Hi,I'm trying to build a search query for the Unexpected Host Sending a Large Amount of Email  in which i need to Exc...
by AL3Z Builder in Splunk Search 06-20-2023
0 3
0
3
VP1
Each log event has more than 1 transaction because we are logging a mini batch log events. So, for every 2 minutes a ...
by VP1 Loves-to-Learn in Splunk Search 06-20-2023
0 2
0
2
jonvijay1993
I have a dbx query plus SPL commands that makes me a certain table, which I want to refer to via a table name, is it ...
by jonvijay1993 Explorer in Splunk Search 06-20-2023
0 2
0
2
thezero
Hi, Could you please help me to create a search which can list all apps enabled in Splunk (on splunk search head) an...
by thezero Path Finder in Splunk Search 06-20-2023
1 12
1
12
john-doe
Hello Folks, Needed help with index based search for any user being added to multiple windows groups (preferably more...
by john-doe Engager in Splunk Search 06-20-2023
0 3
0
3
sekhar463
Hai All,Good day,we have event in splunk for job_name Test job HAS  START_TIME  at 2023/06/15 23:30:33 and END_TIME 2...
by sekhar463 Path Finder in Splunk Search 06-19-2023
0 4
0
4
francine0
First query: index="raw_es2" app message="[Login][Password]Login simplified active." | stats count by message | renam...
by francine0 New Member in Splunk Search 06-19-2023
0 1
0
1
Taruchit
Hello All,I need help to understand the cache related fields returned by _audit index for scheduled searches.duration...
by Taruchit Contributor in Splunk Search 06-19-2023
0 0
0
0
Devi13
Hello Team, I need to have top 10 url's in the order of max average response time taken. Could you please help in tha...
by Devi13 Path Finder in Splunk Search 06-19-2023
0 2
0
2
Woodpecker
Hi,I'm trying to join two searches where the first search includes a single field with multiple values. The matching ...
by Woodpecker Path Finder in Splunk Search 06-19-2023
0 1
0
1
Abhineet
Hi, Require to combine events having one field value same and create single row . Query:  index=webmethods_dev5555_in...
by Abhineet Loves-to-Learn Everything in Splunk Search 06-19-2023
0 1
0
1
appsik
Hello Community, I have a table: Filename Status file1             1 file2             0     | eval Status=if(where S...
by appsik Explorer in Splunk Search 06-19-2023
0 2
0
2
Taruchit
Hello all, I need help to understand the difference between two fields run_time (fetched from index: _internal) and t...
by Taruchit Contributor in Splunk Search 06-19-2023
0 1
0
1
Thulasinathan_M
Is it possible for me to do a main search and based on the results from main search I find the fileName and want to u...
by Thulasinathan_M Contributor in Splunk Search 06-19-2023
0 3
0
3
interrobang
Hi everyone, I have a pretty huge multisearch query with multiple inputlookups, untangling the spaghetti monster whic...
by interrobang Explorer in Splunk Search 06-18-2023
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...