Splunk Search

Splunk Search
Community Activity
hank72
Hi community. Some searches have:index="my_index"index=my_indexI want to extract a new field named user_index but can...
by hank72 Path Finder in Splunk Search 01-24-2023
0 1
0
1
svm157
Hi, I am very new to splunk and need help for the below situation. I am having two columns as below Row        Column...
by svm157 Loves-to-Learn Lots in Splunk Search 01-24-2023
0 5
0
5
sjaitly
I'm trying to create a dashboard to find the old version and new version of splunk from the logs but unable to find i...
by sjaitly Engager in Splunk Search 01-24-2023
0 2
0
2
Virpee
We have a use case where we need to have an alert emailed if a user (under the field User) does not have an event of ...
by Virpee Engager in Splunk Search 01-24-2023
0 2
0
2
power12
Hello SplunkersI have the following raw events 2023-01-20 18:45:59.000, mod_time="1674240490", job_id="79" , time_sub...
by power12 Communicator in Splunk Search 01-24-2023
0 8
0
8
harryhcg
Can someone help with query?I have 2 index abc and bczFrom abc index I want to show stats for field1where field2 from...
by harryhcg Explorer in Splunk Search 01-24-2023
0 2
0
2
mikefoti
Given web access log data with following fields: _time,  http_status, src_ip, dest_ip After a bruteforce attack on a ...
by mikefoti Communicator in Splunk Search 01-24-2023
0 1
0
1
user33
Hello, apologies if this was stated previously. I have multiple calls - each RequestID with a RequestReceive and Resp...
by user33 Path Finder in Splunk Search 01-24-2023
0 5
0
5
bam22
In the below search I am looking for rules hit by count, but how or where would I add a NOT or !, if I wanted to know...
by bam22 Engager in Splunk Search 01-24-2023
0 1
0
1
rprior
I have six eventtype's that each check Juniper router logs for an Interface bounce (an up/down event). These are work...
by rprior Explorer in Splunk Search 01-24-2023
0 3
0
3
munang
I'm trying to get data by registering it as a Splunk script using Python code. But the problem only occurs when I run...
by munang Path Finder in Splunk Search 01-24-2023
0 2
0
2
ipteam
Hello Guys, I'd like to create a search based on business hours, and like to use a field with value like this: "2023/...
by ipteam Engager in Splunk Search 01-23-2023
0 5
0
5
anrak33
My data looks like the following  student_idbrowser_idguiddatetimex_id12_aChrome_211221/9/23 14:45788a13_aChrome_4121...
by anrak33 Explorer in Splunk Search 01-23-2023
0 7
0
7
spl_1991
Given the below scenario: base search| table service_name,status,count Service_name Status Count serviceA 500_IN...
by spl_1991 Engager in Splunk Search 01-23-2023
0 2
0
2
villnooB
Is it possible to assign a value to a different fields. I am trying to combine two different events but the same inde...
by villnooB Explorer in Splunk Search 01-23-2023
0 4
0
4
kyokkygo
Hi! I try to accelerate only one dataset in datamodel with multiple datasets. How i can do it through datamodel.conf ...
by kyokkygo Engager in Splunk Search 01-23-2023
0 2
0
2
poojithavasanth
Hello, I have a Regex for splitting a Person full name into Person lastname, firstname and middlename. Regex used: (?...
by poojithavasanth Explorer in Splunk Search 01-23-2023
0 5
0
5
sjaitly
I need to extract ITSI app version from app.conf fileTo display the data on a dashoboard I found a way sing the confi...
by sjaitly Engager in Splunk Search 01-23-2023
0 3
0
3
sjs
Hey people, I want to find out the total number of hours that elapsed from the last event raised.   This is what I wa...
by sjs Path Finder in Splunk Search 01-22-2023
0 1
0
1
Daksesh
The position of IP address is getting changed(appearing before or after https) in the logs, in such scenario how rege...
by Daksesh Explorer in Splunk Search 01-22-2023
0 5
0
5
splunkos
Hello!Can I ask something very basic as it will help me get started quickly?How can I structure a query to:1) group r...
by splunkos New Member in Splunk Search 01-22-2023
0 1
0
1
Stephcg
I have an application that have some instances/hosts. Because of change of throughput or instability new instances/ho...
by Stephcg Explorer in Splunk Search 01-21-2023
0 2
0
2
nikonjd
Hello, We have migrated from an app called Mirth to Splunk. With Mirth we used a tool called Interface Explorer for H...
by nikonjd New Member in Splunk Search 01-20-2023
0 1
0
1
cwl
間違ったデータがインデックスされてしまいましたが、どのようにインデックス内のデータを削除すれば良いでしょうか?
by cwl Contributor in Splunk Search 01-20-2023
3 3
3
3
DEADBEEF
I have a dashboard with a table with 6 headers.  I would like to bold the text of the second, fourth, and fifth colum...
by DEADBEEF Path Finder in Splunk Search 01-20-2023
0 15
0
15
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...