Splunk Search

Splunk Search
Community Activity
Ombessam
Hello Guys,I'm trying to get the following table:I have the following fields in my index: ip, mac, lastdetect (timest...
by Ombessam Path Finder in Splunk Search 04-11-2025
0 6
0
6
zijian
Hi,One of our three clustered indexers is having search errors and high CPU fluctuations for splunkd main process aft...
by zijian Explorer in Splunk Search 04-11-2025
0 6
0
6
Splunkie
Hi Friends,I am working a query that checks if the value of a field has changed to a state of resolved to exclude it ...
by Splunkie Explorer in Splunk Search 04-11-2025
0 4
0
4
Karthikeya
RegexPlease tell me what will be the best and effective way to write regex here:"vs_name":"v-juniper-uat.opco.sony-44...
by Karthikeya Communicator in Splunk Search 04-10-2025
0 11
0
11
testuser013
Hello,today I have found a bug(?) in the "New Search" function from the Table view.What I do mean with the "New Searc...
by testuser013 New Member in Splunk Search 04-10-2025
0 3
0
3
spm807
How do I show details of individual records in a count total? I have a query that counts events, and then returns the...
by spm807 Explorer in Splunk Search 04-09-2025
0 10
0
10
bpenny
We have a use case where some JSON being ingested into Splunk contains a list of values like this: "message_se...
by bpenny Explorer in Splunk Search 04-09-2025
0 4
0
4
rcbutterfield
How can you query an index to find out the data types of the fields and any attributes that describe the field?  from...
by rcbutterfield Explorer in Splunk Search 04-08-2025
0 2
0
2
madhav_dholakia
Hello,I am facing an issue when a saved report is used in a simple xml dashboard using | loadjob savedsearch="madhav....
by madhav_dholakia Contributor in Splunk Search 04-08-2025
0 1
0
1
SN1
this is the search| rest /services/server/status/partitions-space splunk_server=*| eval free = if(isnotnull(available...
by SN1 Path Finder in Splunk Search 04-08-2025
0 2
0
2
vishalduttauk
I have been using the Splunk Add on for Salesforce Add on for while now but i want to know if anyone else is using it...
by vishalduttauk Communicator in Splunk Search 04-08-2025
0 2
0
2
splunkinator53
This is the SPL i m using| rest /servicesNS/-/-/saved/searches splunk_server=local| fields title| search title=Report...
by splunkinator53 Explorer in Splunk Search 04-07-2025
0 3
0
3
python
Is it possible to identify obsolete dashboards? or the last time a dashboard was executed?
by python Explorer in Splunk Search 04-07-2025
0 4
0
4
jbrenner
I want to add a trendline to this chart:index=my_index | timechart dc(USER) as DISTINCT_USERSHow do I accomplish this...
by jbrenner Path Finder in Splunk Search 04-07-2025
0 1
0
1
shraddha09
0
7
Splunkduck09
Hi All, I would like to read Splunk indexed log/data using text editor tool (like Notepad, etc.). I understand Splunk...
by Splunkduck09 Explorer in Splunk Search 04-06-2025
0 7
0
7
osh55
I have the following simplified version of the query where for each caller, I need all_calls (from sourcetype=x) and ...
by osh55 Engager in Splunk Search 04-06-2025
0 5
0
5
okumar1
Hi All, could you please clarify me what is the diff between data models and splunk dashboards? Thanks
by okumar1 Engager in Splunk Search 04-06-2025
0 5
0
5
bhaskar5428
Please find the below attached screenshot and data sample i need to create 5 felids problem statement - old splunk qu...
by bhaskar5428 Explorer in Splunk Search 04-04-2025
0 5
0
5
DarthHerm
This has been scratching my head. I'm working on dashboards on user activity on our application. Multiple dashboards ...
by DarthHerm Explorer in Splunk Search 04-04-2025
0 6
0
6
dominiquevocat
I would like to periodically merge stuff in /local into /default and then delete whatever is in /localI have a reposi...
by SplunkTrust SplunkTrust in Splunk Search 04-04-2025
4 31
4
31
netmart
Hello,I wanted to filter Cisco ISE Logging Activities by authentication, authorization, and accounting.So far, I've b...
by netmart New Member in Splunk Search 04-04-2025
0 4
0
4
Siddharthnegi
HI , I want to extract purple part. But Severity can be Critical as well .[Time:29-08@17:52:05.880] [60569130] 17:52:...
by Siddharthnegi Contributor in Splunk Search 04-04-2025
0 2
0
2
Siddharthnegi
hello , i want to extract purple highlighted part.[Time:29-08@17:53:03.562] [60569219] 17:53:03.562 10.82.10.245 loca...
by Siddharthnegi Contributor in Splunk Search 04-04-2025
0 2
0
2
w564432
I often run into a case where I find I need to take the same dataset and compute aggregate statistics on different gr...
by w564432 Explorer in Splunk Search 04-03-2025
0 4
0
4
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...