Splunk Search

Splunk Search
Community Activity
mikeyty07
I am planning to build a dashboard where all the extracted traceId # are collected and injected to another search cri...
by mikeyty07 Communicator in Splunk Search 05-11-2023
0 3
0
3
jamin358
I'm creating a bunch of status dashboards where I need to search for a specific set of hosts and persist a result (ad...
by jamin358 Explorer in Splunk Search 05-11-2023
0 3
0
3
Splunk2095
Hi All, I ran into a tricky one and can’t wrap my head around it (or if it is even possible).  The use case is as fol...
by Splunk2095 Engager in Splunk Search 05-11-2023
0 6
0
6
atebysandwich
I have events that where hostnames  show up more than once and I would like to combine them. The fields available are...
by atebysandwich Path Finder in Splunk Search 05-11-2023
0 1
0
1
CodingMaestro
I have a splunk dashboard that looks like below,  And i have added the text filter. But when i try to search of the ...
by CodingMaestro Path Finder in Splunk Search 05-11-2023
0 6
0
6
foxglove
Hello all. I've been having some trouble with a tricky query. Essentially, I want to return all events that contain a...
by foxglove Engager in Splunk Search 05-11-2023
0 3
0
3
ABHAYA
I am using above splunk query   stats count by BankType.  I am getting result as   SBI   27 AXIS   15 CITI   12. but ...
by ABHAYA Path Finder in Splunk Search 05-11-2023
0 1
0
1
s0k0
I have created a post curl to add data in Splunk, internally my api hits Splunk api and in that api I send data in bo...
by s0k0 Observer in Splunk Search 05-11-2023
0 7
0
7
SplunkDash
Hey, I have issues with parsing events, multiple events/records (raw data) are within the same event. Sample data and...
by SplunkDash Motivator in Splunk Search 05-11-2023
0 10
0
10
splunker-2021
When I run | makeresults command then collect it to summary index there is no result. I am testing this to Search Hea...
by splunker-2021 Loves-to-Learn Everything in Splunk Search 05-11-2023
0 8
0
8
ABHAYA
for e.g. input :   I am getting result in an table format like  statuscodeUSB   35 but i wan to transform the result ...
by ABHAYA Path Finder in Splunk Search 05-11-2023
0 7
0
7
Arishtat
I have three types of data entries.     { <Irrelevant field omitted> "parameters": [ { "LicenseNumber": "123456" } ],...
by Arishtat Engager in Splunk Search 05-11-2023
0 3
0
3
djohnson99
Hello!I'm looking to get a time range from two events, one from a standard search, the other from a different search ...
by djohnson99 Explorer in Splunk Search 05-11-2023
0 4
0
4
MarcG
I'm attempting to chart a maximum duration by server and event_type, and I'd like to display the duration in HH:MM:SS...
by MarcG Explorer in Splunk Search 05-11-2023
0 7
0
7
uhaba
Hi, Looking for help on how to detect systems where a monitored value has decreased compared to yesterday's average v...
by uhaba Explorer in Splunk Search 05-10-2023
0 2
0
2
beaverjustin1
If I have queries with Lists/Arrays containing events :line.Data = [eventOne, eventThree];  line.Data = [eventOne, ev...
by beaverjustin1 Engager in Splunk Search 05-10-2023
0 2
0
2
beaverjustin1
If I have queries with dictionaries containing events as the key and frequencies as the value:line.Data = {"eventOne"...
by beaverjustin1 Engager in Splunk Search 05-10-2023
0 2
0
2
sabasiddiqui
How can we filter our query in days like Monday to Friday and calculate their average value. For eg, I am getting dat...
by sabasiddiqui Loves-to-Learn in Splunk Search 05-10-2023
0 6
0
6
Vish
I have added a Time filter for my charts in splunk but i want the default to be from 01-JAN-23, But the issue is when...
by Vish Explorer in Splunk Search 05-10-2023
0 4
0
4
kimsplunk
Hello I have a list of host pairs e.g. hostA1 and hostA2, hostB1 and hostB2, etc. I'm currently trying to search for ...
by kimsplunk Observer in Splunk Search 05-10-2023
0 3
0
3
splunkuser320
Hi, I am trying to create a line graph where I want to show job status overtime. So I want 1 line for failed and anot...
by splunkuser320 Path Finder in Splunk Search 05-10-2023
0 2
0
2
DanAlexander
Hi All,Can anyone help me create a regex to extract the bolded parts from the following _raw log, please?some text - ...
by DanAlexander Communicator in Splunk Search 05-10-2023
0 5
0
5
woodcock
I must join some exceedingly large DM datasets but I cannot get |tstats prestats=t append=t to work consistently in a...
by Esteemed Legend in Splunk Search 05-10-2023
4 10
4
10
joelwizard
I have some SPL that generates a table that looks like this for several builds of a job: Prepare1.003Execute Test44.5...
by joelwizard Explorer in Splunk Search 05-10-2023
0 6
0
6
danielbb
A colleague of mine uses the following dedup version:| strcat entity "-" IP "-" QID "-" Port "-" Tracking_Method "-" ...
by danielbb Motivator in Splunk Search 05-10-2023
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...