Splunk Search

Splunk Search
Community Activity
tb5821
rex field=title "(?titleNEW(.*?)(?:-))" I have this rex command above but it still outputs the dash at the end which...
by tb5821 Communicator in Splunk Search 02-11-2023
0 2
0
2
szabados
I want to use a lookup table, but every time, I add the command to my search "| lookup name_of_my_lookup", I'm gettin...
by szabados Communicator in Splunk Search 02-10-2023
1 5
1
5
vinothkumark
Hi All,I have a field name ip_address which has 50 IP values in it.  at every 5mins interval, I will receive the same...
by vinothkumark Path Finder in Splunk Search 02-10-2023
0 1
0
1
jhewel2495
Hello, what I am trying to do in this search is sum the total CPU seconds, by report class, for a one day period. Onc...
by jhewel2495 Engager in Splunk Search 02-10-2023
0 1
0
1
atebysandwich
I have two lists: one has a list of hostnames and another has a list of prefixes to hostnames. I would like to create...
by atebysandwich Path Finder in Splunk Search 02-10-2023
0 1
0
1
corti77
Hi,I am trying to get a list of workstations trying to connect to malicious DNS using PaloAlto and SYSMON logs.From P...
by corti77 Contributor in Splunk Search 02-10-2023
0 5
0
5
AL3Z
Hi, I'm trying to create a correlation search in splunk unable to figure out options Time range  earliest time/latest...
by AL3Z Builder in Splunk Search 02-10-2023
0 3
0
3
POR160893
Hi, My overall goal is to create a resulting data table with headings including HourOfDay, BucketMinuteOfHour, DayOfW...
by POR160893 Builder in Splunk Search 02-10-2023
0 6
0
6
kanurag1795
Is there a way to get logs in JSON format for an API call from a Springboot Application?
by kanurag1795 Engager in Splunk Search 02-10-2023
0 1
0
1
ursfischer
Hello all As a splunk in an early station  I currently have the following challenge:We have many indexes and we want...
by ursfischer Engager in Splunk Search 02-10-2023
0 3
0
3
POR160893
Hi, I am running the following query to check seasonality in my index:index="ABC| timechart count by _time | timechar...
by POR160893 Builder in Splunk Search 02-10-2023
0 1
0
1
Chris231289
Hi i am new,  I have 2 excel documents, one containing firewall logs and the other containing Sys logs. how would i c...
by Chris231289 Loves-to-Learn Lots in Splunk Search 02-10-2023
0 2
0
2
sekhar463
Hi All, Good day, I have juniper data in Splunk using sourcetype = juniper* but need some searches to create dashboar...
by sekhar463 Path Finder in Splunk Search 02-10-2023
0 3
0
3
StringBee
I want to create a alert that will notify if error_count is continuously increasing over time for any of the group me...
by StringBee Explorer in Splunk Search 02-10-2023
0 6
0
6
Pundittech
hi Have a large index that contains event logs. Trying to extract usernames of EventID 4648. How can I get this displ...
by Pundittech Loves-to-Learn Lots in Splunk Search 02-09-2023
0 4
0
4
btsr
Hi All, Our JSON payload looks like as shown below. The msg.details array can have any number key/value pairs in any ...
by btsr Explorer in Splunk Search 02-09-2023
0 1
0
1
rakeshkiit
index=na160 starttime="02/02/2023:00:00:00" endtime="02/02/2023:24:00:00" requestId="TID:131610985000004c2d"|stats co...
by rakeshkiit Engager in Splunk Search 02-09-2023
0 4
0
4
nibinabr
Hi, I have a query that evaluates the value of a variable like this *...|eval var1= var2*10|....* where var1 and var...
by nibinabr Communicator in Splunk Search 02-09-2023
0 8
0
8
sonamchauhan
Is there a delay in the Splunk API server 'seeing' events that are already indexed?I use the Splunk API to query logs...
by sonamchauhan Engager in Splunk Search 02-09-2023
0 1
0
1
ap666
I get logs from a system which has a field that contains names. Lets say Abc.xyz is the name of the field. I have a l...
by ap666 Explorer in Splunk Search 02-09-2023
0 5
0
5
Splunk77
I am trying to monitor drop in events per index. What is the best way to get a baseline and detect deviation to the v...
by Splunk77 Explorer in Splunk Search 02-09-2023
0 3
0
3
lindonmorris
This is not a question, rather I am sharing something that I discovered with a Splunk OnDemand support call. I though...
by lindonmorris Explorer in Splunk Search 02-09-2023
1 1
1
1
Baragatti
For example: i have been hitting the pavement trying to figure out a search query for events that happened between 3:...
by Baragatti Observer in Splunk Search 02-09-2023
0 4
0
4
atebysandwich
I have a lookup with a field called IP. The field has values that have multiple IPs in them an I would like to sperat...
by atebysandwich Path Finder in Splunk Search 02-09-2023
0 4
0
4
navarone0161
Please need help with this command -Average response time with 10% additional buffer ( single number) – Use “Eval” op...
by navarone0161 Explorer in Splunk Search 02-09-2023
0 2
0
2
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...