Splunk Search

Splunk Search
Community Activity
mark_groenveld
I am searching for a key:value report app where the values are inconsistent but include a report cluster name consist...
by mark_groenveld Path Finder in Splunk Search 03-28-2025
0 8
0
8
rwheeloc
I've done a bit of searching and haven't quite found a solution to what I'm trying to accomplish (or I haven't unders...
by rwheeloc Explorer in Splunk Search 03-28-2025
0 4
0
4
Blueochotona
The two raw results are as follows : (1)EventType="Device" Event="InstallProfileConfirmed" User="sysadmin" Enrollment...
by Blueochotona Engager in Splunk Search 03-28-2025
0 4
0
4
Poojitha
Hi All,I have a lookup that contains set of email ids and associated accounts.Example : Account IDOWNER_EMAIL34234234...
by Poojitha Communicator in Splunk Search 03-27-2025
0 1
0
1
harishsplunk7
We have a total of five search heads, and while four of them are successfully executing the curl command, one search ...
by harishsplunk7 Explorer in Splunk Search 03-27-2025
0 2
0
2
tkwaller1
Simple search but Im having issues nailing down what I want to see.This search returns all the views the logged in us...
by tkwaller1 Path Finder in Splunk Search 03-27-2025
0 5
0
5
RSS_STT
Fields value of 2nd and 3rd events are enter changing. please suggest how to maintain order in Splunk status command....
by RSS_STT Explorer in Splunk Search 03-27-2025
0 4
0
4
SN1
hello i have this search| inputlookup lkp-all-findings| lookup lkp-findings-blacklist.csv blfinding as finding OUTPUT...
by SN1 Path Finder in Splunk Search 03-27-2025
0 8
0
8
feichinger
I do have a solution for this, but I just wonder if there is a more straight forward approach to get a better underst...
by feichinger Path Finder in Splunk Search 03-27-2025
0 1
0
1
doniaelansasy
I’ve encountered an issue while working on a configuration for a Splunk deployment. I was creating a stanza in the in...
by doniaelansasy Loves-to-Learn Lots in Splunk Search 03-26-2025
0 11
0
11
DATT
I have a field that I need to search on that is a long string of comma-separated values.  It comes from our vulnerabi...
by DATT Path Finder in Splunk Search 03-26-2025
0 5
0
5
rvsroe
In the fundamentals 1 course lab 8 tells us to: "As a best practice and for best performance, place dedup as early in...
by rvsroe Explorer in Splunk Search 03-26-2025
0 6
0
6
HX
I would like to get the number of hosts per index in the last 7 days, the query as below gave me the format but not t...
by HX Engager in Splunk Search 03-26-2025
0 3
0
3
ayomotukoya
I have the below search and I want to modify it to get the bandwidth utilization percentage. Whats the best way to go...
by ayomotukoya Explorer in Splunk Search 03-26-2025
0 10
0
10
ramuzzini
Need help cleaning up my rex command line with data delineated by (,) then extracting the value after the (=) charact...
by ramuzzini Path Finder in Splunk Search 03-25-2025
0 3
0
3
b17gunnr
 Hello folks,I have a series of event results which take the format as shown below: appDisplayName: foo appId: f...
by b17gunnr Path Finder in Splunk Search 03-25-2025
0 3
0
3
reswob4
I have a problem where I cannot remotely access the web interface (not via HTTPS or HTTP on either 8000 or 8089) of o...
by reswob4 Builder in Splunk Search 03-25-2025
0 3
0
3
SN1
Hello I am running searchindex=_introspectiondedup host table hostin result i am not able to see one indexer and one ...
by SN1 Path Finder in Splunk Search 03-25-2025
0 6
0
6
secure
Hi everyonei have a dataset| makeresults| eval APP1="appdelta", hostname1= mvappend("syzhost.domain1","abchost.domain...
by secure Path Finder in Splunk Search 03-24-2025
0 2
0
2
gcoles
This might be a silly question, but has anyone figured out how to add line breaks to text that has been evaluated wit...
by gcoles Communicator in Splunk Search 03-24-2025
11 16
11
16
shimada-k
Hi Experts,I have the following data. {<!-- -->"TIMESTAMP": 1742677200,"SYSINFO": "{\"number_of_notconnect_interfaces\":0,\"h...
by shimada-k Explorer in Splunk Search 03-24-2025
0 6
0
6
kiwiglen
I have an index with a list of transactions, the transactions in the system start as 1 process with a transaction num...
by kiwiglen Observer in Splunk Search 03-23-2025
0 11
0
11
nithys
Hi I have dashboard with Data Entity drop down ,i want to add a drop drown "ALL" ,if i select ALL and hit submit butt...
by nithys Communicator in Splunk Search 03-23-2025
0 3
0
3
molla
Hi Splunkers, I would like to display a count divided by several locations on a map. On the map, I would like only th...
by molla Explorer in Splunk Search 03-23-2025
0 2
0
2
b17gunnr
Hello folks,I trying to use a base search within a dashboard but it consistently returns no results. However, when I ...
by b17gunnr Path Finder in Splunk Search 03-21-2025
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...