Splunk Search

Splunk Search
Community Activity
cbs01
We are successfully ingesting Websense logs into Splunk but the user field is recorded in LDAP context and has spaces...
by cbs01 Engager in Splunk Search 07-03-2014
0 1
0
1
matthewhaswell
I have a query that provides windows startup, ending and duration - however I was looking for a way to graph this? T...
by matthewhaswell Path Finder in Splunk Search 07-03-2014
0 1
0
1
echojacques
So I have this basic search for a line graph visualization: (search goes here) | timechart count Let's say I've ha...
by echojacques Builder in Splunk Search 07-03-2014
0 9
0
9
jravida
Hi folks, I'm trying to merge events that share a common keyword value, with the mvcombine. The problem is it just l...
by jravida Communicator in Splunk Search 07-03-2014
0 1
0
1
dreamwork801
So I'm running this search string here: index = git | rename Data.payload.head_commit.modified{} as FilesModified | ...
by dreamwork801 Path Finder in Splunk Search 07-03-2014
0 2
0
2
caroline_fortun
Hello everyone, I´m trying to filter some Windows Security Event Logs that contains the machine name as the username...
by caroline_fortun Explorer in Splunk Search 07-03-2014
0 4
0
4
geoffmartin
I'm trying to produce a multivalue field out of another multivalue field in my data model, and that's proven to be qu...
by geoffmartin Engager in Splunk Search 07-03-2014
0 1
0
1
sergeyvinnik
Anybody can answer to simple question? How to remove from indexing host= d:\TEST.log just "<TD>" combination? What sh...
by sergeyvinnik Explorer in Splunk Search 07-03-2014
0 3
0
3
yuanliu
My Splunk is 5.0.5. I constructed a rex to extract user from free-hand logs. In some logs, user is null. This skew...
by SplunkTrust SplunkTrust in Splunk Search 07-03-2014
0 9
0
9
albyva
Is it possible to add a comment field in a Macro so that it is displayed in a search? For example, if a macro contain...
by albyva Communicator in Splunk Search 07-03-2014
0 1
0
1
splunker12er
How does the results of the correlation events go to "notable" index ? Is there any configuration file for this ? Al...
by splunker12er Motivator in Splunk Search 07-03-2014
0 1
0
1
jlhamlet
Hi, I have a proxy log that logs the time the query was executed and also give the duration in seconds. "11/Jan/201...
by jlhamlet Path Finder in Splunk Search 07-03-2014
0 3
0
3
Bliide
Hello, I am trying to extract a field and I have an error in my REGEX. The line looks like this: 6/26/2014 13:00:1...
by Bliide Path Finder in Splunk Search 07-03-2014
1 5
1
5
RicoSuave
As a splunk user, i want to find the most common events in my search results. How would I accomplish this? I am tryin...
by RicoSuave Builder in Splunk Search 07-02-2014
2 2
2
2
bwhyle
My goal is to create a search that produces a report of ftp users that have logged in (successfully) in the past 7 da...
by bwhyle Engager in Splunk Search 07-02-2014
1 3
1
3
Mubarish
Hi How to run three different searches on click of a submitbutton? The scenario to choose a particular search will b...
by Mubarish Path Finder in Splunk Search 07-02-2014
0 4
0
4
pradeepkumarg
How can i get the top 3 rows from each group in a table. Here is sample data output from my query The output is res...
by pradeepkumarg Influencer in Splunk Search 07-02-2014
0 2
0
2
jsmith39
I'm new to writing regular expressions and am having a difficult time building a field using extract fields. Unfortun...
by jsmith39 Path Finder in Splunk Search 07-02-2014
0 5
0
5
jonathanfalconi
Hi, I'm using 6.1 I have a group of people who are looking at a way to create monthly reports based on their list o...
by jonathanfalconi Explorer in Splunk Search 07-02-2014
0 2
0
2
Bhuavana
Hi, I need to move the csv file generated inside the folder $SPLUNK_HOME$\var\run\splunk [as part of outputcsv comma...
by Bhuavana Explorer in Splunk Search 07-02-2014
0 1
0
1
Nikita_Danilov
Hi all, I need to make by default all searches in Splunk 6.1.1 as case InSensitive. For example, this search are cas...
by Nikita_Danilov Path Finder in Splunk Search 07-02-2014
0 5
0
5
asherinb
We have a case where 4 log files are being monitored. Daily the log file is rolled to a back up and truncated at the ...
by asherinb Explorer in Splunk Search 07-02-2014
0 2
0
2
hdus001
Hi, I'm trying to create a table that shows me the number of times a URL is requested for and what its average respo...
by hdus001 New Member in Splunk Search 07-02-2014
0 5
0
5
mataharry
I removed a server from my cluster, and it still shows up in the dropdowns of the SOS app. How is it maintained, can ...
by mataharry Communicator in Splunk Search 07-01-2014
2 2
2
2
zliu
When submitting queries in rapid succession to Splunk (via the REST API), I'm getting 503 errors from splunkd. This s...
by zliu Splunk Employee Splunk Employee in Splunk Search 07-01-2014
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...