Splunk Search

Splunk Search
Community Activity
Taruchit
Hi All,I have 4 indexes: -index1index2index3index4Each index has its own search criteria, there are some common field...
by Taruchit Contributor in Splunk Search 03-10-2023
0 4
0
4
KhalidSheikh
While processing an AS request for target service krbtgt, the account XXX-G-Dashboard-Dev did not have a suitable key...
by KhalidSheikh Engager in Splunk Search 03-10-2023
0 2
0
2
zewashere
Hello, i'm new to Splunk and i need some advices.I've created a lookup named my_color_lookup, with 2 column : color,d...
by zewashere New Member in Splunk Search 03-10-2023
0 1
0
1
Vivekmishra01
I want to add new row to my search result using values from the previous result. Basically I am counting few strings ...
by Vivekmishra01 Explorer in Splunk Search 03-10-2023
0 3
0
3
jason_hotchkiss
Hello I have the following search which produces  statistics(746) in Splunk: index=my_index sourcetype=my_st id=100 h...
by jason_hotchkiss Communicator in Splunk Search 03-10-2023
0 3
0
3
cmcdole
I need to create a single field named MemberOf from the XML snippet below.  It should look like this: memberOf CN=But...
by cmcdole Path Finder in Splunk Search 03-10-2023
0 4
0
4
Ashwini008
Hi,I want to write a case condition where i can check values from Range column.For instanceIf range for both cost & p...
by Ashwini008 Builder in Splunk Search 03-10-2023
0 5
0
5
ivan5593
Hello,I'm having an issue with a field search. I have a lookup where I specify for every sourcetype which field is re...
by ivan5593 Explorer in Splunk Search 03-09-2023
0 2
0
2
SplunkDash
Hello, I have complex JSON events ingested as *.log files. I have issues (or couldn't do) with extracting fields from...
by SplunkDash Motivator in Splunk Search 03-09-2023
0 25
0
25
ckutach
I have 2 groups of data:messageId1: ['A', 'B', 'C']messageId2: ['A', 'E', 'F', 'G', 'T', 'Z'] How do I return the val...
by ckutach Engager in Splunk Search 03-09-2023
0 2
0
2
vik
I am trying to split the values in both the columns and create 5 rows by assigning respective values. I need an outpu...
by vik Explorer in Splunk Search 03-09-2023
0 2
0
2
sjim
Here's my query: index=comp_logs "processed=" | eval name=consumerGroupId | timechart span=1h sum(processed) as proce...
by sjim Loves-to-Learn in Splunk Search 03-09-2023
0 1
0
1
marcos_eng1
Hello Splunkers,  I have client that already has a IBM Qradar SIEM and wants to Integrates with Splunk SOAR (formely ...
by marcos_eng1 Explorer in Splunk Search 03-09-2023
0 1
0
1
shady6
Following is my query:index=backup | stats count by errorsI have thousands of error codes in logs and I need to trigg...
by shady6 Loves-to-Learn in Splunk Search 03-09-2023
0 1
0
1
Nico99
Hello community!I'm looking for a way to optimize this search below and I need some help : index="oswinsec" source="X...
by Nico99 Explorer in Splunk Search 03-09-2023
0 2
0
2
raghul725
Hello, I am performing the following search to extract the time taken to upload   index=* my_search |rex "\[upload\] ...
by raghul725 Explorer in Splunk Search 03-09-2023
0 2
0
2
Gabriel
Hello everyone Is there a way to determine what occupies disk storage? The following SPL yields a line graph that sho...
by Gabriel Path Finder in Splunk Search 03-09-2023
0 2
0
2
jenniferhao
The original data : _time reg exp raw 2019-09-20 A 1 100 2019-09-20 B 2 200 2019-09-20 C ...
by jenniferhao Explorer in Splunk Search 03-09-2023
0 6
0
6
ckutach
I am trying to make 2 searches using different indexes and sources The first search is looking for all entries with "...
by ckutach Engager in Splunk Search 03-08-2023
0 1
0
1
Indu
Hi , I have an alert scheduled to run every day 7 am and this runs on Time Range : Yesterday. Wanted to know how Splu...
by Indu Engager in Splunk Search 03-08-2023
0 2
0
2
wheels531
I'm trying to use spath to extract fields from a json object in an event. This is the event2023-03-08T22:47:06.664521...
by wheels531 Engager in Splunk Search 03-08-2023
0 1
0
1
aohls
I have a search where I have multiple evals to check if items are true of false. With my results I want to show somet...
by aohls Contributor in Splunk Search 03-08-2023
0 1
0
1
pinVie
Hello all, Is there any possibility to detect if somebody ran a | delete command? I do know about the "can delete" ...
by pinVie Path Finder in Splunk Search 03-08-2023
1 4
1
4
satishp00
Hi , I m new to splunk and still exploring. I have created a timechart with a span on 10 mins . The timechart has a s...
by satishp00 Engager in Splunk Search 03-08-2023
0 1
0
1
kmaron
I have a search with a timechart command to fill a single value dashboard entry based on a count that comes from a DB...
by kmaron Motivator in Splunk Search 03-08-2023
0 15
0
15
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors