Splunk Search

Splunk Search
Community Activity
joe06031990
Hi, I have the bellow event:   {"log":"2023-02-16t14:14:25.827471424z stderr F I0216 14:14:25.827359               1 ...
by joe06031990 Communicator in Splunk Search 02-17-2023
0 4
0
4
Yossarian622
Unfortunately I have no control over the log data formatting... it is in format:  Field1=Value1|Field2=Value2| ... |C...
by Yossarian622 Engager in Splunk Search 02-16-2023
0 6
0
6
meleschi
I have the following data that I'm trying to timechart the differences between: 2023-02-16T16:14:04: Data Processing ...
by meleschi Explorer in Splunk Search 02-16-2023
0 1
0
1
power12
Hello Splunkers, I have the following raw data2023-02-15T12:43:06.774603-08:00 abc OpenSM[727419]: osm_spst_rcv_proce...
by power12 Communicator in Splunk Search 02-16-2023
0 2
0
2
ft_kd02
Hi all,I'm working on a dashboard in which I populate a panel with summary data. The summary data runs once per hour ...
by ft_kd02 Path Finder in Splunk Search 02-16-2023
0 3
0
3
fredclown
I'm logged into my system as an admin, so I have access to all the indexes. I've also verified this by looking at the...
by fredclown Builder in Splunk Search 02-16-2023
0 1
0
1
GhanaRusk
I've a couple of queries - index="main"app="student-api" "tags.studentId"=3B70E5 message="Id and pwd entered correctl...
by GhanaRusk Engager in Splunk Search 02-16-2023
0 11
0
11
sabari80
Following query is printing 'pp_user_action_name','Total_Calls','Avg_User_Action_Response' not getting 'pp_user_actio...
by sabari80 Explorer in Splunk Search 02-16-2023
0 3
0
3
gut1kor
Hi Team,I have events being pushed to HTTP event collector 24/7. In my dashboard I query and format the events using ...
by gut1kor Explorer in Splunk Search 02-16-2023
0 0
0
0
Shobhitha1
Hello Everyone, I have a requirement where I have to generate a query.  event 1 : <l:event dateTime="2023-02-10 11:28...
by Shobhitha1 New Member in Splunk Search 02-16-2023
0 3
0
3
Stijn
source=PR1 sourcetype="sap:abap" EVENT_TYPE=STAD EVENT_SUBTYPE=MAIN (TCODE="ZORF_BOX_CLOSING") SYUCOMM="SICH_T" ACCOU...
by Stijn Loves-to-Learn in Splunk Search 02-16-2023
0 3
0
3
midcoffessplunk
メインサーチのイベントの_timeをサブサーチに渡したいのですが、上手くいきません。何か方法はありますでしょうか。 index=event_data|eval earlytime=_time-60 latesttime=_time+6...
by midcoffessplunk Engager in Splunk Search 02-15-2023
0 1
0
1
dickersons
Hi, I am using a regex to search for a field "statusCode" which could have multiple values, i.e. "200", "400", "500",...
by dickersons Explorer in Splunk Search 02-15-2023
0 5
0
5
LeeMoe
I have a dataset which has a column "Port" that contains (limited) numerical values.  I want to make these values dis...
by LeeMoe Path Finder in Splunk Search 02-15-2023
0 8
0
8
solaced
I have a lookup which I want to compare search results against and find duplicate values.   How do I ignore duplicate...
by solaced Explorer in Splunk Search 02-15-2023
0 5
0
5
carl_landry
Hi, I have a problem finding answers about the failure of a universal forwarder to re-ingest an XML file. 02-08-2023 ...
by carl_landry New Member in Splunk Search 02-15-2023
0 0
0
0
splunkuser320
I am trying to create a query to get the sum of multiple fields by a field.    index="*****"|stats sum(field_A) as  A...
by splunkuser320 Path Finder in Splunk Search 02-15-2023
0 2
0
2
MDSplunkNinja
I have a table of data with values like this:String         NumericClient 1      99.9Client 2      99.2Client 3      ...
by MDSplunkNinja Explorer in Splunk Search 02-15-2023
0 2
0
2
Woodpecker
Hi,I have search which has S_host name values of different DB instances say MSSQL and Oracle in a single field.eg: S_...
by Woodpecker Path Finder in Splunk Search 02-14-2023
0 2
0
2
AL3Z
Hi,I want to create a search out of the below event, to raise an alert if the particular system having the label lost...
by AL3Z Builder in Splunk Search 02-14-2023
0 10
0
10
sahilmits
Here is the query i have and need to extract the "sts:ExternalId"   requestParameters: { [-]policyDocument: {<!-- -->"Version...
by sahilmits Engager in Splunk Search 02-14-2023
0 7
0
7
sjringo
If I am starting with this query:index&#61;anIndex sourcetype&#61;aSourcetype ( aJobName AND "COMPLETED OK" )The job im inter...
by sjringo Contributor in Splunk Search 02-14-2023
0 1
0
1
queriousGeorge
I have two searches that will return orderNumbers 1.index&#61;main "Failed insert" | table orderNumber//returns small lis...
by queriousGeorge Engager in Splunk Search 02-14-2023
0 3
0
3
power12
Hello Splunkers,I have a field called state_sinfo which have values like (up,up*,up$,up^,continue,continue$,continued...
by power12 Communicator in Splunk Search 02-14-2023
0 1
0
1
akpuvvada
I am trying to find entries between a date-time range based on a field in the event 'Date'. It date-time value of the...
by akpuvvada Engager in Splunk Search 02-14-2023
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...
Top Solution Authors