Splunk Search

Splunk Search
Community Activity
apignata
I have the following JSON structure in my events. I am trying to figure out an SPL Query to format the JSON in a tabl...
by apignata Explorer in Splunk Search 03-27-2023
0 1
0
1
vickycoder27
I have a curl response which is json string[], I am able to fetch the data using split(), mvexpand() and then substri...
by vickycoder27 Explorer in Splunk Search 03-26-2023
0 4
0
4
itsmevic
I'm running the below query to find out when was the last time an index checked in. However, in using this query the ...
by itsmevic Communicator in Splunk Search 03-26-2023
0 5
0
5
bt149
I have a log set from FW's. These logs have a field called "src."  From what I can tell, this field is populated with...
by bt149 Path Finder in Splunk Search 03-25-2023
0 4
0
4
SplunkNewbie100
Hi all,   I  want to replace random substrings in path: C:\Users\sjfklsj\Appdata\.... -> C:\Users\---\Appdata\.... C:...
by SplunkNewbie100 New Member in Splunk Search 03-25-2023
0 2
0
2
bosseres
Hello everyone In the result of my search I got such results (last command was stats values(list) as list, values(sta...
by bosseres Contributor in Splunk Search 03-25-2023
0 3
0
3
Sven1
I am working to merge two searches. The first search outputs one or more account names:     index=x sourcetype=y | ta...
by Sven1 Path Finder in Splunk Search 03-24-2023
0 12
0
12
Abhineet
Hi,  looking for splunk query having field name similar to field in lookup file with respective value in lookup file....
by Abhineet Loves-to-Learn Everything in Splunk Search 03-24-2023
0 6
0
6
pierre_weg
Hello fellows!I have a sourcetype called cmdb with a field called BIA to any src_host. After this join index=lab sour...
by pierre_weg Path Finder in Splunk Search 03-24-2023
0 6
0
6
Veeru
Actually I want to pass the time from first query to second and get results out on basis of first query time.First qu...
by Veeru Path Finder in Splunk Search 03-24-2023
0 1
0
1
iwascar
Hi everyone,I have a column called "SCRN_NM"  (name of screen)and only want to extract English data, not non-English ...
by iwascar New Member in Splunk Search 03-24-2023
0 1
0
1
shashilendraman
how to search value of "Dst_IP" field from "ASA" index to "otx" index "indicator" field and display the scrip" field ...
by shashilendraman Explorer in Splunk Search 03-24-2023
1 5
1
5
surabhi
Hi,   We have a platform where lot of dashboards are populated using splunk searches via splunk api call. All the que...
by surabhi New Member in Splunk Search 03-24-2023
0 0
0
0
pm2012
Hi SMEs, I have a unique requirement which need one of my extracted filed name = actual_time to be mapped with _time ...
by pm2012 Explorer in Splunk Search 03-24-2023
0 1
0
1
mag314
How do you filter out IPv6 and internal routed 169.254.0.0/16 from a multi-value field?Data ExampleHOST              ...
by mag314 Explorer in Splunk Search 03-23-2023
0 1
0
1
Zarack
I have some Checkpoint logs (Firewall) that are generating an alert (Data hygiene - events in the future), I would li...
by Zarack Engager in Splunk Search 03-23-2023
0 1
0
1
sjaworski
I am trying to store a list of searches in a lookup table and then pass each search to the map command. |inputlook...
by sjaworski Communicator in Splunk Search 03-23-2023
3 10
3
10
mikeyty07
I have 2 kind of logs where there are two types of uri which i want to rex into different fields {logType=DOWNSTREAM_...
by mikeyty07 Communicator in Splunk Search 03-23-2023
1 4
1
4
ttovarzoll
I am trying to build an Alert for login failures in AWS CloudTrail. In general I have it working -- but my joins are ...
by ttovarzoll Path Finder in Splunk Search 03-23-2023
0 3
0
3
krishanp
Hello, I am attempting to start a Splunk docker container (search head) and add it as a search peer to an existing en...
by krishanp Explorer in Splunk Search 03-23-2023
0 2
0
2
dpuhr
Hi,I am looking for a solution to a problem that has been addressed here: Using a column of field names to dynamicall...
by dpuhr Explorer in Splunk Search 03-23-2023
0 8
0
8
Konrad_Schlude
I'm looking for a way to search for freetext after a join.It is easy when the field is known. For instance, there is ...
by Konrad_Schlude Explorer in Splunk Search 03-23-2023
0 3
0
3
tb582
I have a specific source type and hosts that I want to export the raw logs for the past 24h is there a way to do that...
by tb582 Explorer in Splunk Search 03-23-2023
0 10
0
10
Dayalss
Can someone please help me in extracting the field Specific_DL_Testing from the below sample log. instance of the "\S...
by Dayalss Engager in Splunk Search 03-23-2023
0 9
0
9
PeterGian
Hello amazing community! I'm now stuck with a problem that most probably has a really simple solution   I have a tab...
by PeterGian Engager in Splunk Search 03-23-2023
0 3
0
3
Get Updates on the Splunk Community!

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...
Top Solution Authors