Splunk Search

Splunk Search
Community Activity
ddrillic
We get an error message in the UI, saying that the dispatch directory is full. How can we clean it? We have two SHs.....
by ddrillic Ultra Champion in Splunk Search 02-03-2023
1 15
1
15
the_wolverine
./splunk cmd splunkd clean-dispatch Where can I find the full documentation for this command which is used to "clea...
by the_wolverine Champion in Splunk Search 02-03-2023
7 7
7
7
splunkcol
I find myself using Splunk Cloud and I see that the licensing is being exceeded on daily. In the Cloud Monitoring Con...
by splunkcol Builder in Splunk Search 02-03-2023
0 1
0
1
splunkcol
A question, When we talk about correlation, is it necessarily because a query is being made in 2 or more sources? Or ...
by splunkcol Builder in Splunk Search 02-03-2023
0 3
0
3
FPERVIL
I have a query where I'm looking for users who are performing large file transfers (>50MB).  This query runs every da...
by FPERVIL Explorer in Splunk Search 02-03-2023
0 1
0
1
kyokkygo
  I try use macros to get external indexes in child dataset VPN, but search with tstats on this dataset doesn't work...
by kyokkygo Engager in Splunk Search 02-03-2023
0 1
0
1
amand
The internal logs flow to splunk UI but the applications logs are not flowing to splunk UI.We have a cluster with sev...
by amand New Member in Splunk Search 02-03-2023
0 5
0
5
RobertRi
Hello Community! I'm searching for a solution to highlight the "HostC", which has an AppC failure and no further log ...
by RobertRi Communicator in Splunk Search 02-03-2023
0 2
0
2
Neel88
Hi,I need to create the 2 drop down for date where user can manually select start_date and end_date. And based on tha...
by Neel88 Explorer in Splunk Search 02-03-2023
0 2
0
2
brennson90
Hi, i'm currently working on a props.conf and have different values from _time and the timestamp in my logs. What did...
by brennson90 Path Finder in Splunk Search 02-02-2023
0 3
0
3
harryhcg
I have 2 index, abc and bcz index abc data is in raw format like below. <random ip address>|-NA\CAPITA|5xxhxh545|jljd...
by harryhcg Explorer in Splunk Search 02-02-2023
0 5
0
5
Neel88
Hello,I am using 2 multi select dropdown. When its on  the default value  'ALL' then it doesn't show any value in the...
by Neel88 Explorer in Splunk Search 02-02-2023
0 1
0
1
interrobang
 (index="external*" Feedback* "Text") | transaction channel startswith=POST endswith=received maxspan=1m maxevents=2 ...
by interrobang Explorer in Splunk Search 02-02-2023
0 3
0
3
cool_pbenjamin
I have a search along these lines     "duration: " | rex field=host "(?P<host_type>[my_magic_regex])" | rex "duration...
by cool_pbenjamin New Member in Splunk Search 02-02-2023
0 1
0
1
jamesjung01
| inputlookup suspicious_win_comm.csv lookup table contents has only keyword keyword <- field name tasklist ver i...
by jamesjung01 Explorer in Splunk Search 02-02-2023
0 2
0
2
power12
Hello SplunkersI am pretty new to splunk admin .I have the following config set up in indexes.conf where I set up one...
by power12 Communicator in Splunk Search 02-02-2023
0 8
0
8
poojithavasanth
Hello, I wanted a EVAL statement which manually adds a specified time may be "00:00:00" for the event containing only...
by poojithavasanth Explorer in Splunk Search 02-02-2023
0 2
0
2
tfujita_splunk
Numeral system macros for SplunkExamples of Single Value panel and Table.Hello,Just an announcement.I have created ma...
by tfujita_splunk Splunk Employee Splunk Employee in Splunk Search 02-02-2023
3 0
3
0
Neel88
I am working on the saved search not index/lookup.I tried this code - | eval date=strftime(strptime(<fieldname>,"%Y-%...
by Neel88 Explorer in Splunk Search 02-02-2023
0 5
0
5
naveenalagu
Basically I have a set of raw data with different time stamp in CCYYMMDDHHMMSS format. I want to list out the stats w...
by naveenalagu Explorer in Splunk Search 02-02-2023
0 6
0
6
erikschubert
Hello everyone,I have a search in the following format:(index="index1" group=a) OR (index="index2" group=a)....Later ...
by erikschubert Engager in Splunk Search 02-02-2023
0 1
0
1
syamaguchi3
Hi I'm implementing some searches provided by Splunk Threat Research Team to detect threats from AD logs. But I canno...
by syamaguchi3 Explorer in Splunk Search 02-02-2023
0 2
0
2
tomapatan
I have the following search which returns a table of all hostnames and operating systems. | inputlookup hosts.csv| se...
by tomapatan Contributor in Splunk Search 02-02-2023
0 4
0
4
AKBBB
Hi Guys, Less Event displayed while searching as * then search hostname while its showing if I search at the beginnin...
by AKBBB Explorer in Splunk Search 02-02-2023
0 11
0
11
arriel96
A have two tables anda i want to relation this two tables by nember of events in a hour, i  manage to make a SQL quer...
by arriel96 Explorer in Splunk Search 02-02-2023
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...