Splunk Search

Splunk Search
Community Activity
Lazous
Hello, I am trying to extract the data from the following message:the header data is in quotes and for each header da...
by Lazous Engager in Splunk Search 04-18-2023
0 5
0
5
Keerthi
I am trying to get the data only when my lastlogon(field name) is Null. but the above query is still giving me data f...
by Keerthi Path Finder in Splunk Search 04-18-2023
0 2
0
2
Skysurfer
I have a query that I am using to get the count of events index=system source=/var/log/syslog/* | rex field=source "...
by Skysurfer Explorer in Splunk Search 04-18-2023
0 2
0
2
mbtsoltis
How do you convert .34999832 to 34.99% or .399345 to 39.99% I need to see the .99 and not have it round up  
by mbtsoltis Explorer in Splunk Search 04-18-2023
0 3
0
3
POR160893
Hi, I have the following Splunk query:index=ABC sourcetype=DEF dv_assignment_group="SECURITY-NETWORK-L3" | table _tim...
by POR160893 Builder in Splunk Search 04-18-2023
0 3
0
3
mathewchase
I have seen many questions about disabled due to licensing violation, but I applied a reset key and now I have this m...
by mathewchase Engager in Splunk Search 04-18-2023
1 4
1
4
shubs
Hi all,Is it currently possible to somehow create a conditional macro expansion?For example, I have different list of...
by shubs Engager in Splunk Search 04-18-2023
0 2
0
2
Sekhar
Below two events  Start event  Index= x source= xtype | spath application | search application= x app " saved note" R...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
chanhee1
There are two types of raw data. What is the regular expression to get the value between the /* special symbol and th...
by chanhee1 Loves-to-Learn Lots in Splunk Search 04-17-2023
0 3
0
3
Sekhar
I have two events one is  calculate the SLA percentage from below querys   Start event query  Index=x source type= xx...
by Sekhar Explorer in Splunk Search 04-17-2023
0 12
0
12
kdineshreddy009
can we setup an alert based on data from current time stamp & based on information on past 15mins ?say at T1, got a l...
by kdineshreddy009 New Member in Splunk Search 04-17-2023
0 3
0
3
bhagyashriyan
Hi, I have many concurrent saved searches running due to which search delayed health indicator is always red. How to ...
by bhagyashriyan Explorer in Splunk Search 04-17-2023
0 1
0
1
att35
Hi, We have a data source containing File Path's from both Windows and Linux formats.  Applying regex separately work...
by att35 Builder in Splunk Search 04-17-2023
0 4
0
4
muradgh
Hi Splunkers, I need your assistance to create a search that provides the following:SPL query I will use it to look f...
by muradgh Path Finder in Splunk Search 04-17-2023
0 2
0
2
Sekhar
We have two events Start event  Index= x source= xtype | spath application | search application= x app " saved note" ...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
becksyboy
Hi All, I have an issue which i am unable to resolve. I have a lookup with two columns: Process_Command_Line, score U...
by becksyboy Contributor in Splunk Search 04-17-2023
0 6
0
6
Abhineet
We have splunk event having field "eventdateTime"  in format mentioned below. for example eventdateTime 2023-04-17 06...
by Abhineet Loves-to-Learn Everything in Splunk Search 04-17-2023
0 2
0
2
kmhanson
I am new to Regex expressions and trying to figure them out. I am trying to extract two sections of the following log...
by kmhanson Explorer in Splunk Search 04-17-2023
0 14
0
14
shrirangphadke
Hi, Sorry if my question is repeated or too naive. I have a text input field accepting "Module name". It works perf...
by shrirangphadke Path Finder in Splunk Search 04-17-2023
3 8
3
8
Keerthi
  I am scheduling this at 9.00 AM everyday using splunk DB connect .When i see the sourcetype nextday at 9.00 AM gett...
by Keerthi Path Finder in Splunk Search 04-17-2023
0 3
0
3
jonvijay1993
I have a multiselect for software version (version is just yyyy.mm.dd or an alphanumeric string).If the user selects ...
by jonvijay1993 Explorer in Splunk Search 04-17-2023
0 4
0
4
Sekhar
We have two events query Start event Index=x source type= xx "String" extacted fields s like manid,actionid,batch I'd...
by Sekhar Explorer in Splunk Search 04-17-2023
0 3
0
3
dvg06
Hi Legends How do I give bit more meaningful names for fields last_sum and first_sum in below query? i.e. something l...
by dvg06 Path Finder in Splunk Search 04-16-2023
1 1
1
1
GarzaREG
I have a requirement where I have been asked to monitor for new users getting added to Sudoer.  Are there specific ac...
by GarzaREG New Member in Splunk Search 04-16-2023
0 2
0
2
RanjiRaje
Hi All, I am facing some issue in using lookup command. Need your suggestions here please.. I have a lookup file as b...
by RanjiRaje Explorer in Splunk Search 04-15-2023
0 7
0
7
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...