Splunk Search

Splunk Search
Community Activity
directtv999
sample json: Hosts: { [-]   Nodepool1: { [-]       Cluster: xyz1       Accountid: idxyz   Nodepool3: { [-]      Clust...
by directtv999 Loves-to-Learn Lots in Splunk Search 11-17-2022
0 7
0
7
sc_admin11
i am trying to create a custom field like host and source by making changes in atteched  photos of entrypoint.sh and ...
by sc_admin11 Explorer in Splunk Search 11-16-2022
0 0
0
0
JyotiP
I have the following query :sourcetype="docker" AppDomain=Eos Level=INFO Message="Eos request calculated" | eval Val_...
by JyotiP Path Finder in Splunk Search 11-16-2022
0 3
0
3
YatMan
Sample event   { durationMs: 83 properties: { url: https://mywebsite/v1/organization/41547/bui...
by YatMan Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunky21
Hi all, I'm attempting to develop a regex that will pick up on a value contained in [ ] brackets (see below): Log val...
by Splunky21 Explorer in Splunk Search 11-16-2022
0 2
0
2
judges88
Trying to get these UUID/GUIDs to extract from the message field. Hoping to create a rex to extract everything after ...
by judges88 Explorer in Splunk Search 11-16-2022
0 5
0
5
JohnnyMnemonic
I have read all the posts about "merging fields" and none of the options work for me. I have events where the same va...
by JohnnyMnemonic Explorer in Splunk Search 11-16-2022
0 3
0
3
Splunkstart
Hi All, these are the logger info counts which are generated in splunk  Total numner where inds-a 20Total numner wher...
by Splunkstart Explorer in Splunk Search 11-16-2022
0 4
0
4
jip31
hi I want to not display the week end in my chart for example, if i use a time picler range of 7 days, I just want to...
by jip31 Motivator in Splunk Search 11-16-2022
0 11
0
11
anu41
I am having issue with "Status" values as below and screenshot, please find below json and search query. Please advis...
by anu41 Explorer in Splunk Search 11-16-2022
0 2
0
2
SumanPalisetty
Hi,Sometimes if we are doing base search, if not handled properly, you will see page loading, how do you handle it?Re...
by SumanPalisetty Path Finder in Splunk Search 11-16-2022
0 1
0
1
Abdullah
Dears,   We need your support to convert below search to tstats search. (index=os_windows OR index=workstation*) tag=...
by Abdullah Explorer in Splunk Search 11-16-2022
0 3
0
3
neerajs_81
Hello,  We have been using this query to list out hosts that are not sending logs since past 24h.  It has been workin...
by neerajs_81 Builder in Splunk Search 11-16-2022
0 8
0
8
KMoryson
I have the following table of activities: InternalExternalDirection1.1.1.12.2.2.2Outbound3.3.3.34.4.4.4Inbound5.5.5.5...
by KMoryson Explorer in Splunk Search 11-16-2022
0 2
0
2
sivakumargik
sample event "USR_LOGIN","USR_EMP_NO","USR_LAST_NAME","USR_FIRST_NAME","USR_DISPLAY_NAME","USR_STATUS","USR_EMAIL","...
by sivakumargik New Member in Splunk Search 11-16-2022
0 6
0
6
MScottFoley
I want to add an annotation to a dashboard every time we switch from blue servers to green servers or green to blue. ...
by MScottFoley Path Finder in Splunk Search 11-15-2022
0 1
0
1
SumanPalisetty
Hi, What are the limitations on subsearch? Please give one or two, please? This is an interview question. Regards Sum...
by SumanPalisetty Path Finder in Splunk Search 11-15-2022
0 3
0
3
DGilbert91
Hi all,I have a timestamp in a format I havn't dealt with before and I am struggling to get it converted to my timezo...
by DGilbert91 Explorer in Splunk Search 11-15-2022
0 4
0
4
SumanPalisetty
Hi,How will search head know which index has data? It's an interview question. Kindly help me.RegardsSuman P.
by SumanPalisetty Path Finder in Splunk Search 11-15-2022
0 2
0
2
ben_r
I have some Phantom playbooks performing tasks that I want to monitor on a Splunk dashboard - runs/day, distinct task...
by ben_r Engager in Splunk Search 11-15-2022
0 0
0
0
KyleMcDougall
Hi all!I'm trying to create a table with case_number and session as the two columns. Any event without a case_number ...
by KyleMcDougall Path Finder in Splunk Search 11-15-2022
0 5
0
5
jerinvarghese
Hi Team, Thanks in advance, Need a quick help in Regex query, Input values:  KUL6LJBJ62YDBLR6LC7BLNJRHRI6M5G6KKPHKUL6...
by jerinvarghese Communicator in Splunk Search 11-15-2022
0 5
0
5
shivaguthi
sample data _timesourcenameappIdstate10/8/207:53:27.090 AMxyzTransform-x-2020-10-081001success10/8/207:53:16.890 AMxy...
by shivaguthi Explorer in Splunk Search 11-15-2022
0 10
0
10
Mayurmpatil
what is splunk search query to find the oldest ( first ) event generated on a index ?
by Mayurmpatil Path Finder in Splunk Search 11-15-2022
0 6
0
6
Log_wrangler
Hi I have index = A sourcetype = A and source = /tmp/A.app.log I want to find the earliest event (date and time...
by Log_wrangler Builder in Splunk Search 11-15-2022
0 6
0
6
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...