Splunk Search

Splunk Search
Community Activity
maitrifer
Hi All I'm new to Splunk and I'm confused between stats eventstats and streamstats. Can anyone help me to understand?
by maitrifer Engager in Splunk Search 05-26-2023
2 5
2
5
supersnedz
Hello I have created a dashboard that shows the previous 4 days and the equivalent days the week before for asset cou...
by supersnedz Path Finder in Splunk Search 05-26-2023
0 3
0
3
SplunkDash
Hello,I have a Roll Up events. One file created every month and new events added up every day within that file. How w...
by SplunkDash Motivator in Splunk Search 05-26-2023
0 5
0
5
Sekhar
Have drop down vaules like below Extual vaul Index =abc source = abc source   Drop down values like prod  lable  Valu...
by Sekhar Explorer in Splunk Search 05-25-2023
0 3
0
3
dmoberg
We have a log file that is split into multiple events. In these events we need to count the number of occurrences whe...
by dmoberg Path Finder in Splunk Search 05-25-2023
0 2
0
2
rajneeshc1981
I have a new lookup setup I want to query against it .presently its not working may I know what I have to do in order...
by rajneeshc1981 Explorer in Splunk Search 05-25-2023
0 12
0
12
ajitdev381
My application logs json object . Sample logs look like this:     {"ts":"05 25 2023 14:57:05.114","msg":"Listeners is...
by ajitdev381 Engager in Splunk Search 05-25-2023
0 1
0
1
jialiu907
I am looking for the table to be in decreasing order and with the Total row on top. This is my current search. index=...
by jialiu907 Path Finder in Splunk Search 05-25-2023
0 1
0
1
cwhelan
I am looking to find all scheduled searches within the environment that are using a timeframe of 'All time' e.g. if a...
by cwhelan Explorer in Splunk Search 05-25-2023
0 10
0
10
POR160893
Hi, I have a dashboard where the data is coming from a lookup called "ABC" which has 2 fields called "src_ip" and "de...
by POR160893 Builder in Splunk Search 05-25-2023
0 2
0
2
JohnCM8181
I am trying to write a search that displays a table that shows whether a log in cloud watch exists or not every 15 mi...
by JohnCM8181 New Member in Splunk Search 05-25-2023
0 1
0
1
damode1
I have the below sample botsv3 sample data set which is sysmon in xml format. I need to convert that into json format...
by damode1 Path Finder in Splunk Search 05-24-2023
0 5
0
5
TravellingGuy
Hi! I have a search query problem that's wrecking my newbie brain. I have log events that look like this:     { "op...
by TravellingGuy Engager in Splunk Search 05-24-2023
0 4
0
4
risingflight143
Hi All I have a room mailbox in office365 and i want to get the information of how many meetings were booked for one ...
by risingflight143 Explorer in Splunk Search 05-24-2023
0 1
0
1
man03359
I am relatively new to Splunk and I am trying to extracting fields in Splunk,  I have a pattern I am attempting to ex...
by man03359 Communicator in Splunk Search 05-24-2023
0 6
0
6
k_ashabi
I have a lookup table from which I need to read the IP addresses one by one, perform calculations on each address, an...
by k_ashabi Loves-to-Learn Lots in Splunk Search 05-24-2023
0 7
0
7
neeravmathur
Hi All, We noticed that one of our Heavy Forwarder has not been sending _audit and _internal logs to our indexer. It ...
by neeravmathur Path Finder in Splunk Search 05-24-2023
0 7
0
7
devtech83
I have mail.log. This is displayed in the "Event" column:     May 24 14:02:05 srv7 amavis[10129]: (10129-08) Passed C...
by devtech83 Engager in Splunk Search 05-24-2023
0 1
0
1
jonvijay1993
I have a query for for my dropdown with tokens inserted here and there and whenever the values on those tokens change...
by jonvijay1993 Explorer in Splunk Search 05-24-2023
0 4
0
4
jenkinsta
I am making a trend chart of specific data set. What I am looking for is (generic example)index=nessus | eval Month=s...
by jenkinsta Path Finder in Splunk Search 05-24-2023
0 2
0
2
jonvijay1993
I have a union [] command that I want to execute only if a check box is checked, how can I manage this? SPL2 branch d...
by jonvijay1993 Explorer in Splunk Search 05-24-2023
0 11
0
11
acontarciego
What's the quickest and safest way to move indexed data from one location to another? I have data that is currently s...
by acontarciego Explorer in Splunk Search 05-23-2023
3 7
3
7
dm1
I want to convert some of the below individual json objects in the event into nested single json object like the seco...
by dm1 Builder in Splunk Search 05-23-2023
0 2
0
2
damode1
I want to convert some of the below individual json objects in the event into nested single json object like the seco...
by damode1 Path Finder in Splunk Search 05-23-2023
0 2
0
2
rolabrie
Using the Splunk addon for AWS to collect ec2 instance metadata I get an array called tags with key/value pairs such ...
by rolabrie Loves-to-Learn in Splunk Search 05-23-2023
0 8
0
8
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...