Splunk Search

Splunk Search
Community Activity
surens
Hi all, My lead give some task .To create a table, we have lot of source type ... source type have the different stat...
by surens Explorer in Splunk Search 12-15-2022
0 3
0
3
mssoni
Hello Team,This is the first time I am posting a question and hope that I have explained it thoroughly. I am trying t...
by mssoni Loves-to-Learn in Splunk Search 12-15-2022
0 5
0
5
mikeyty07
I have an access logs which prints like thisserver - - [date& time] "GET /google/page1/page1a/633243463476/googlep1?s...
by mikeyty07 Communicator in Splunk Search 12-15-2022
0 4
0
4
mlm
hello guys, Is there any way that I could remove duplicate events that have same timestamp using this below search st...
by mlm Explorer in Splunk Search 12-15-2022
0 6
0
6
LHAYNES020
I'm trying to use where(isnotnull(mvfind(mvfield,field))) to search to see which records are part of a list. The fiel...
by LHAYNES020 Explorer in Splunk Search 12-15-2022
0 3
0
3
inesani
Hi Splunk Community,I am interested in parsing Splunk searches and I am hoping that somebody here can point me to an ...
by inesani Engager in Splunk Search 12-15-2022
1 0
1
0
bitnapper
Hi there,I created multiple field extractions, extracting values from different sourcetypes into the same field:sourc...
by bitnapper Path Finder in Splunk Search 12-15-2022
0 6
0
6
M28
Hi All, Below is the sample data looks like. sourcetype_1 s1_field1: 123 s1_field2: {<!-- --> {<!-- --> ID: 2 Name: ABC }, {<!-- --> ID: 1 Na...
by M28 Explorer in Splunk Search 12-15-2022
0 15
0
15
duncan
Gudde Muergen!I'm quite new to Splunk, so I'm having difficulties figuring out how to do this search properly. Here's...
by duncan Observer in Splunk Search 12-15-2022
0 0
0
0
chandankr
100 * sum([x]) / sum([y] - [z])  
by chandankr Path Finder in Splunk Search 12-15-2022
0 2
0
2
SENG10
Salut vous allez bien j esper alors j'aimerai avoir des conseils ou des uggestion pour un projet qui porte sur la mis...
by SENG10 New Member in Splunk Search 12-14-2022
0 1
0
1
sekhar463
hi all,i have some events with a field called RUNTIME for each job.how can i get the average value of RUNTIME for eac...
by sekhar463 Path Finder in Splunk Search 12-14-2022
0 3
0
3
jahziah952
Hi  When i'm searching the top users who logged into a host, I'm getting event data along with the user when i'm usin...
by jahziah952 Engager in Splunk Search 12-14-2022
0 1
0
1
balu1211
Hi.. I have to find the ip address hitting fw for that i have to implement the whois lookup for the hitting ips but n...
by balu1211 Path Finder in Splunk Search 12-14-2022
0 1
0
1
matthewg
I want to strip certain results by time from my search. I eventually plen to place a dedup command between the first ...
by matthewg Explorer in Splunk Search 12-14-2022
0 3
0
3
ACyber
Hi, I am a new Splunk user and this is my first post on the community forum.  If I am not following guidelines please...
by ACyber Engager in Splunk Search 12-14-2022
0 1
0
1
SSwaminathan90
Hi Team,  Considering the image shared below:-  x1 is my x-axis and y1 is my y-axis.  I would like to interpolate va...
by SSwaminathan90 Explorer in Splunk Search 12-14-2022
0 6
0
6
junster
Hi,  I am a beginner here in Splunk. I am trying to search multiple lines in the log and generate an alert if certain...
by junster Explorer in Splunk Search 12-14-2022
0 2
0
2
ShaneReddy
I am using Python SDK to run Splunk queries at 10 minute interval to collect data for my application. I have nearly 3...
by ShaneReddy New Member in Splunk Search 12-14-2022
0 0
0
0
tomapatan
Hi Everyone,I have a field called "User" that contains similar values and I was wondering how to remove or merge simi...
by tomapatan Contributor in Splunk Search 12-14-2022
0 2
0
2
ravir_jbp
EventAgentLogin &#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;&#61;   2022-12-14 06:39:03.875 TRACE 12632 --- [New I/O client worker #1-6] c.i.e.g.wor...
by ravir_jbp Explorer in Splunk Search 12-14-2022
0 1
0
1
leagawa
I want to write the rex command for the following regex and give it a new field where the findings will be dumped int...
by leagawa New Member in Splunk Search 12-14-2022
0 1
0
1
indeed_2000
Hi Is it possible to feed opentelemetry log to "splunk enterprise" and draw trace and span without use Splunk APM?   ...
by indeed_2000 Motivator in Splunk Search 12-14-2022
0 4
0
4
alissan
I have daily user login/logout data like this: date,user,action2020-04-14 01:00:00,user1,login2020-04-14 01:05:00,use...
by alissan Explorer in Splunk Search 12-14-2022
0 4
0
4
GaetanVP
Hello Splunkers,I recently created a custom alerts on my Search Head, and for this alert to run I needed to install a...
by GaetanVP Contributor in Splunk Search 12-14-2022
0 3
0
3
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...