Splunk Search

Splunk Search
Community Activity
wjz
Hi, I'd like to count the number of responses by the following status codes: 2xx, 4xx and 5xx. I'm basically countin...
by wjz New Member in Splunk Search 01-11-2023
0 3
0
3
amitrinx
I have two lookupsRLQuotas: Endpoint, Endpoint Name, filter, quota, WindowRLFilters: Attribute, filterI want to loop ...
by amitrinx Explorer in Splunk Search 01-10-2023
0 1
0
1
sjs
My data looks something like this The status can be either SUCCESS or FAILED, I want to count the total number of ev...
by sjs Path Finder in Splunk Search 01-10-2023
0 2
0
2
sharsmail
I'm trying to implement a search query in splunk to get anomalous values around a particular field in the service eve...
by sharsmail Engager in Splunk Search 01-10-2023
0 3
0
3
nikhil29
could someone please let me know where I'm going wrong in my query ?| spath service_roles{} output=service_role| stat...
by nikhil29 Loves-to-Learn Everything in Splunk Search 01-10-2023
0 2
0
2
Rapidz
I am setting up an alert to notify when a message is received more than a 100 times in a week. I figured it out for t...
by Rapidz Explorer in Splunk Search 01-10-2023
0 5
0
5
Vivekmishra01
I am trying to find few strings in my search query and count occurrences of them and I want to put them in a two colu...
by Vivekmishra01 Explorer in Splunk Search 01-10-2023
0 2
0
2
Ker_splunk
Hi Splunk Community,   I wondered if there was any way to match a keyword against a string in a lookup.  For example:...
by Ker_splunk Engager in Splunk Search 01-10-2023
0 2
0
2
evallja
Hello everyone, I have the following results when running my search: _time                                        use...
by evallja Path Finder in Splunk Search 01-10-2023
0 1
0
1
anjuliwyles
When I place event.code into an if statement, it will not evaluate as true   Currently I have this code: index = wind...
by anjuliwyles Engager in Splunk Search 01-10-2023
0 2
0
2
neilmac64
My current project polls a device every 15 minutes to pull a counter which is then charted. Thanks to members here, I...
by neilmac64 Path Finder in Splunk Search 01-10-2023
0 16
0
16
kpavan
Hi All, Greetings! Need help on splunk query, I have 2 indexes assets and vulns, am trying to build report to analyze...
by kpavan Path Finder in Splunk Search 01-10-2023
0 3
0
3
robertisimos
Currently we are ingesting a big amount of AWS VPC FlowLogs in to the Splunk and I am wondering if there is any usage...
by robertisimos Observer in Splunk Search 01-10-2023
0 2
0
2
finnpalm
Hello. I'm fairly new to Splunk and SPL so bear with me here. I have the following scenario: I have an existing looku...
by finnpalm Explorer in Splunk Search 01-10-2023
0 4
0
4
Erilope
Hello everyone, I have a search for after hour logins between 6pm and 6am. Right now I have event codes 4625 and 4624...
by Erilope Explorer in Splunk Search 01-10-2023
0 3
0
3
MrIncredible
In few logs I can see escape character is also printed. My rex is working fine when i am testing it on regex101.com b...
by MrIncredible Explorer in Splunk Search 01-10-2023
0 4
0
4
ramanan
Hi All, I need to collect "Thread Dump" and "Heap Dump" of the application into Splunk.  What are all the possibiliti...
by ramanan Engager in Splunk Search 01-10-2023
0 1
0
1
jmr44
I have Splunk UF 7.0.3 that I want to send logs from to Splunk Cloud.  However, the UF doesn't support httpout so I a...
by jmr44 Explorer in Splunk Search 01-09-2023
0 1
0
1
Jackiifilwhh
I want to get the last index of my target value for a multi-value field. For example, idchain1SendMessageCheckMessage...
by Jackiifilwhh Path Finder in Splunk Search 01-09-2023
0 12
0
12
siksaw33
please help extract adsId,offerName, currentProductDescription, offerAccountToken, offerType, offerIdentifiermessage=...
by siksaw33 Path Finder in Splunk Search 01-09-2023
0 7
0
7
satish
Hi Experts,   I would like to compare values in same field (vlan_ids) for equality based on a machine serial (hyp_ser...
by satish Explorer in Splunk Search 01-09-2023
0 4
0
4
evallja
Hello, I have created and imported a lookup file ex. "hashes.csv" and I have pasted there a list of 500+ hashes. I wa...
by evallja Path Finder in Splunk Search 01-09-2023
0 2
0
2
aa0
Hi all,I want to extract the following word with rex expression:ABC\qq1234 expected result: qq1234Please note that th...
by aa0 Path Finder in Splunk Search 01-09-2023
0 2
0
2
niks987
Happy New Year to all of you. So I have syslog in which we have details of the devices and switches. The requirement ...
by niks987 Explorer in Splunk Search 01-09-2023
0 0
0
0
vineela
i need to extract fields which are in json format i have been trying using spath command for extracting the following...
by vineela Path Finder in Splunk Search 01-09-2023
0 8
0
8
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...