Splunk Search

Splunk Search
Community Activity
Lavender
Hi, Kindly help on sorting the values from append query as below: index=* source=*|stats sum(Tot) sum(in_prog) sum(su...
by Lavender Loves-to-Learn Everything in Splunk Search 05-10-2023
0 3
0
3
satyaallaparthi
Hello,    I have 2 different files names lookup1.csv and lookup2.csv, which have column A and column B in both.    Ho...
by satyaallaparthi Communicator in Splunk Search 05-10-2023
0 3
0
3
Splunk_321
Hi All,I have a requirement where I need to group count of methods responsetime into different time intervals.Below i...
by Splunk_321 Path Finder in Splunk Search 05-09-2023
0 2
0
2
jialiu907
So I am trying to search through some results and I am trying to display the results that ExitStatus=0 which means it...
by jialiu907 Path Finder in Splunk Search 05-09-2023
0 1
0
1
michaeler
I'm trying to do a drilldown of a timechart where the Y-axis field is Domain and the value is a count, X-axis is time...
by michaeler Communicator in Splunk Search 05-09-2023
0 1
0
1
jlaska
I'm working with two similar, but not quite the same datasets and I want to create a table which displays data from e...
by jlaska Engager in Splunk Search 05-09-2023
0 2
0
2
Splunk77
I am working on a query to report on events generated within 2 minutes of the first event for the same host. In the f...
by Splunk77 Explorer in Splunk Search 05-09-2023
0 2
0
2
AL3Z
Hi all, I'm looking for the search how we can seperate the multiple columns in to single column  Ex: Host         sca...
by AL3Z Builder in Splunk Search 05-09-2023
0 1
0
1
gvk_us
Hi, We have applications Availability data in splunk.With below SPL, I got this data. Base_SPL..| streamstats reset_o...
by gvk_us Explorer in Splunk Search 05-09-2023
0 7
0
7
AL3Z
Hi All, How do we list out the fields in tabular format..Eg: hostname  action  windows     allowed                   ...
by AL3Z Builder in Splunk Search 05-09-2023
0 1
0
1
Vish
In the below chart if u can see i have used round and avg to first_response and closure time. But my values are not a...
by Vish Explorer in Splunk Search 05-09-2023
0 4
0
4
thenormalone
I have a dashboard that has a dropdown which takes in the values from a csv file. Is there a way I can add on to the ...
by thenormalone Path Finder in Splunk Search 05-08-2023
0 3
0
3
balcv
I have a field returned with some search data that contains a date and time in UTC.  I would like to be able to add 1...
by balcv Contributor in Splunk Search 05-07-2023
0 2
0
2
Jouman
Hi all,  I have a field named as item_description which is an array of decimal value, which represents the descriptio...
by Jouman Path Finder in Splunk Search 05-06-2023
0 4
0
4
LearningGuy
how do I escape single quote within DBXquery SQL like commandFor example:   content = '. . . . . .  src_port': 20, 'd...
by LearningGuy Motivator in Splunk Search 05-06-2023
0 1
0
1
landen99
I would like to import a lookup table in a subsearch for a raw value search: index=i1 sourcetype=st1 [inputlookup us...
by landen99 Motivator in Splunk Search 05-06-2023
2 6
2
6
srv007
The data is in key value format instead of field value due to limitation of fields to be used. There are 10+ key valu...
by srv007 Path Finder in Splunk Search 05-06-2023
0 9
0
9
spl_stu
How to view the currently running search of Splunk and display the amount of memory consumed during the execution of ...
by spl_stu Explorer in Splunk Search 05-06-2023
0 4
0
4
Blackdragon7
I can load a Sysmon  log into Splunk as a lookup table, but how do I view it after that? What code do I use to view t...
by Blackdragon7 Observer in Splunk Search 05-05-2023
0 7
0
7
bmanikya
Distcp job application_1681357021637_0984 MAPREDUCE Wed May 3 04:32:32 MST 2023 Wed May 3 04:32:40 MST 2023 SUCCEEDED...
by bmanikya Loves-to-Learn Everything in Splunk Search 05-05-2023
0 6
0
6
kc_prane
Hi I am using the below query and i need the results in hourly basis for the time i selected ?   "My Base search"   |...
by kc_prane Communicator in Splunk Search 05-05-2023
0 2
0
2
pavanae
I have a Splunk search outputs result as follows. DetailslinkProduct Details :Product 1:- ABC123Product 2:- DEF456abc...
by pavanae Builder in Splunk Search 05-05-2023
0 1
0
1
Jsk1950
I try to show all the value in Spluk dashoard . I have this kind of data   { returnCode= 2,  itemCount=35, cdt=4 , li...
by Jsk1950 New Member in Splunk Search 05-05-2023
0 0
0
0
DeanDeleon0
Hello, I'm using the following search string to monitor SQL Server DB Tables that are being audited by SQL Server Aud...
by DeanDeleon0 Path Finder in Splunk Search 05-05-2023
0 11
0
11
superisk
Hi all, I am confident with strptime/strftime but i'm really struggling with the correct strptime argument for the fo...
by superisk Explorer in Splunk Search 05-05-2023
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...