Splunk Search

Splunk Search
Community Activity
wanda619
0
7
dtaylor
Good day, I'm trying to think of how I can write a search to find a specific event and then take all the events surro...
by dtaylor Path Finder in Splunk Search 03-18-2025
0 4
0
4
secure
Hello Everyone,i have a dataset where I'm generating a column of number of servers per day.  using a timechart comman...
by secure Path Finder in Splunk Search 03-18-2025
0 2
0
2
SN1
Hello I have this search| inputlookup defender_onboard.csv| fillnull value=NA| search Region="***" 4LetCode="*"| sear...
by SN1 Path Finder in Splunk Search 03-18-2025
0 2
0
2
Poojitha
Hi All,I have scheduled a splunk report to run at 11 AM IST everyday (cron schedule : 0 11 * * *). Search Head time z...
by Poojitha Communicator in Splunk Search 03-18-2025
0 2
0
2
dickersons
Hi,I am doing an initial search based off of initial field inputs within a dashboard.  The issue I am having is after...
by dickersons Explorer in Splunk Search 03-17-2025
0 1
0
1
rnayak
Hello:I have a query that extracts a set of 5 request_ids based on certain criteria.  I then need to include these re...
by rnayak New Member in Splunk Search 03-17-2025
0 7
0
7
MichalG1
Hello TeamSplunk 9.4.0. Running as root. All in one.Seems super simple problem. I am not able to have maxmind lookup ...
by MichalG1 Path Finder in Splunk Search 03-17-2025
0 8
0
8
tchamp
I have some rather large json data payloads being sent over to Splunk. I've seen payloads around 1MB in size. It took...
by tchamp Explorer in Splunk Search 03-17-2025
0 2
0
2
Praz_123
Need help for the below Query index=na sourcetype=na:co state=down host_state_type="HARD" [| tstats prestats=f values...
by Praz_123 Communicator in Splunk Search 03-17-2025
0 2
0
2
Na_Kang_Lim
I have a multisite setup. Each site has 3-4 indexers, with a Replication Factor = 2.Search Factor is = 1.When queryin...
by Na_Kang_Lim Path Finder in Splunk Search 03-16-2025
0 4
0
4
nithys
HiNeed help in finding DistinctAdminUserCount and DistinctAdminUserNames of each associated Name inside test or prod ...
by nithys Communicator in Splunk Search 03-15-2025
0 5
0
5
secure
Hii have a list of servers coming from two different sources list A has server without domain names and list B has se...
by secure Path Finder in Splunk Search 03-14-2025
0 6
0
6
Chakri
Below is my search | inputlookup uf_ssl_kv_lookup| search hostname=AB100*TILL* hostname!=AB100*TILL100 hostname!=AB10...
by Chakri Engager in Splunk Search 03-14-2025
0 5
0
5
Punnu
Hello All,  This is my first post . I have just started learning writing splunk query . Ok so we have one application...
by Punnu Path Finder in Splunk Search 03-14-2025
0 4
0
4
RamMur
Hello,I'm trying to join based on a common field using a similar query like below, however, the in the result i only ...
by RamMur Explorer in Splunk Search 03-14-2025
0 4
0
4
ccWildcard
Splunk: 8.0.3 (I know its old we're working on approvals to upgrade)We’re receiving behavior I have never encountered...
by ccWildcard Explorer in Splunk Search 03-14-2025
0 2
0
2
okumar1
Hello everyone,I have set up my Splunk server[with receiving port 9997 is enabled] and Splunk forwarder to monitor my...
by okumar1 Engager in Splunk Search 03-14-2025
0 8
0
8
Varun18
Hi Team,I have a multivalue field in one of the user fields, along with other fields. However, when exporting the dat...
by Varun18 Loves-to-Learn in Splunk Search 03-13-2025
0 6
0
6
nithys
HiUsing below query to capture 4xx,5xx error ,but getting as no result found index=* source IN ("/aws/lambda/*") ...
by nithys Communicator in Splunk Search 03-13-2025
0 2
0
2
LizAndy123
So I have in the past used a report which finds a string and then calculates the size left and it came as 1 whole eve...
by LizAndy123 Path Finder in Splunk Search 03-13-2025
0 3
0
3
_Mauro_Costa_
Hello,I have 2 columns, one with date and other with the day of weekbased on day of week whenever is Saturday or Sund...
by _Mauro_Costa_ Explorer in Splunk Search 03-13-2025
0 1
0
1
pm771
We use Enterprise Splunk  Version: 9.1.6I have noticed a strange behavior of searchmatch() function. | makeresults | ...
by pm771 Communicator in Splunk Search 03-12-2025
0 5
0
5
hummingbird81
Hi All, looking for some advice as in how to take the latest values from 2 datasets .  We have a base search that pul...
by hummingbird81 Explorer in Splunk Search 03-12-2025
0 5
0
5
SN1
I want to get total memory allocated on 1 indexer and how much memory it is using. so that i could get remaining disk...
by SN1 Path Finder in Splunk Search 03-12-2025
0 8
0
8
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...