Splunk Search

Splunk Search
Community Activity
mark_groenveld
I am searching for a key:value report app where the values are inconsistent but include a report cluster name consist...
by mark_groenveld Path Finder in Splunk Search 03-28-2025
0 8
0
8
rwheeloc
I've done a bit of searching and haven't quite found a solution to what I'm trying to accomplish (or I haven't unders...
by rwheeloc Explorer in Splunk Search 03-28-2025
0 4
0
4
Blueochotona
The two raw results are as follows : (1)EventType="Device" Event="InstallProfileConfirmed" User="sysadmin" Enrollment...
by Blueochotona Engager in Splunk Search 03-28-2025
0 4
0
4
Poojitha
Hi All,I have a lookup that contains set of email ids and associated accounts.Example : Account IDOWNER_EMAIL34234234...
by Poojitha Communicator in Splunk Search 03-27-2025
0 1
0
1
harishsplunk7
We have a total of five search heads, and while four of them are successfully executing the curl command, one search ...
by harishsplunk7 Explorer in Splunk Search 03-27-2025
0 2
0
2
tkwaller1
Simple search but Im having issues nailing down what I want to see.This search returns all the views the logged in us...
by tkwaller1 Path Finder in Splunk Search 03-27-2025
0 5
0
5
RSS_STT
Fields value of 2nd and 3rd events are enter changing. please suggest how to maintain order in Splunk status command....
by RSS_STT Explorer in Splunk Search 03-27-2025
0 4
0
4
SN1
hello i have this search| inputlookup lkp-all-findings| lookup lkp-findings-blacklist.csv blfinding as finding OUTPUT...
by SN1 Path Finder in Splunk Search 03-27-2025
0 8
0
8
feichinger
I do have a solution for this, but I just wonder if there is a more straight forward approach to get a better underst...
by feichinger Path Finder in Splunk Search 03-27-2025
0 1
0
1
doniaelansasy
I’ve encountered an issue while working on a configuration for a Splunk deployment. I was creating a stanza in the in...
by doniaelansasy Loves-to-Learn Lots in Splunk Search 03-26-2025
0 11
0
11
DATT
I have a field that I need to search on that is a long string of comma-separated values.  It comes from our vulnerabi...
by DATT Path Finder in Splunk Search 03-26-2025
0 5
0
5
rvsroe
In the fundamentals 1 course lab 8 tells us to: "As a best practice and for best performance, place dedup as early in...
by rvsroe Explorer in Splunk Search 03-26-2025
0 6
0
6
HX
I would like to get the number of hosts per index in the last 7 days, the query as below gave me the format but not t...
by HX Engager in Splunk Search 03-26-2025
0 3
0
3
ayomotukoya
I have the below search and I want to modify it to get the bandwidth utilization percentage. Whats the best way to go...
by ayomotukoya Explorer in Splunk Search 03-26-2025
0 10
0
10
ramuzzini
Need help cleaning up my rex command line with data delineated by (,) then extracting the value after the (=) charact...
by ramuzzini Path Finder in Splunk Search 03-25-2025
0 3
0
3
b17gunnr
 Hello folks,I have a series of event results which take the format as shown below: appDisplayName: foo appId: f...
by b17gunnr Path Finder in Splunk Search 03-25-2025
0 3
0
3
reswob4
I have a problem where I cannot remotely access the web interface (not via HTTPS or HTTP on either 8000 or 8089) of o...
by reswob4 Builder in Splunk Search 03-25-2025
0 3
0
3
SN1
Hello I am running searchindex=_introspectiondedup host table hostin result i am not able to see one indexer and one ...
by SN1 Path Finder in Splunk Search 03-25-2025
0 6
0
6
secure
Hi everyonei have a dataset| makeresults| eval APP1="appdelta", hostname1= mvappend("syzhost.domain1","abchost.domain...
by secure Path Finder in Splunk Search 03-24-2025
0 2
0
2
gcoles
This might be a silly question, but has anyone figured out how to add line breaks to text that has been evaluated wit...
by gcoles Communicator in Splunk Search 03-24-2025
11 16
11
16
shimada-k
Hi Experts,I have the following data. {<!-- -->"TIMESTAMP": 1742677200,"SYSINFO": "{\"number_of_notconnect_interfaces\":0,\"h...
by shimada-k Explorer in Splunk Search 03-24-2025
0 6
0
6
kiwiglen
I have an index with a list of transactions, the transactions in the system start as 1 process with a transaction num...
by kiwiglen Observer in Splunk Search 03-23-2025
0 11
0
11
nithys
Hi I have dashboard with Data Entity drop down ,i want to add a drop drown "ALL" ,if i select ALL and hit submit butt...
by nithys Communicator in Splunk Search 03-23-2025
0 3
0
3
molla
Hi Splunkers, I would like to display a count divided by several locations on a map. On the map, I would like only th...
by molla Explorer in Splunk Search 03-23-2025
0 2
0
2
b17gunnr
Hello folks,I trying to use a base search within a dashboard but it consistently returns no results. However, when I ...
by b17gunnr Path Finder in Splunk Search 03-21-2025
0 6
0
6
Get Updates on the Splunk Community!

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...