Splunk Search

Splunk Search
Community Activity
Splunk_321
I have a scenario where i want to expand the field and show as individual events. Below is my query, which works fine...
by Splunk_321 Path Finder in Splunk Search 11-25-2022
0 1
0
1
CyberMage
I'm trying to create table with the top 5 results split into columns, so that I can have multiple results per line, g...
by CyberMage Engager in Splunk Search 11-25-2022
0 1
0
1
dural_yyz
We are spending a tremendous amount of time tuning our search structures lately. One thing we have run across in our ...
by dural_yyz Motivator in Splunk Search 11-25-2022
0 2
0
2
alpeen_splunk
Hello,I use Splunk as Indexer and deployment server und I have one universal forwarder installed. I'm getting an erro...
by alpeen_splunk Explorer in Splunk Search 11-25-2022
0 3
0
3
splunk_enjoyer
Hello splunk lovers!i want help with date field and i want fast. i have field, format example: data_started  01.01.20...
by splunk_enjoyer Explorer in Splunk Search 11-25-2022
0 1
0
1
SabariRajanT
Hi All, I have a hostname stating \\sent134 I need to remove this \\ using regex and it should be like this:  sent134...
by SabariRajanT Path Finder in Splunk Search 11-25-2022
0 2
0
2
guywood13
I have the following data:     { "remote_addr": "1.2.3.4", "remote_user": "-", "time_local": "24/Nov/2022:09:55...
by guywood13 Path Finder in Splunk Search 11-25-2022
0 3
0
3
innoce
Hi,My datasets are much larger but these represent the crux of my hurdle...     Sourcetype= transaction fields= trans...
by innoce Path Finder in Splunk Search 11-24-2022
0 1
0
1
matcad81
HI All, I would like to visualize all the search fields/content I mentioned using the command search: index=*  | sear...
by matcad81 New Member in Splunk Search 11-24-2022
0 2
0
2
Ash
I want to implement this correlation search:   `sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* O...
by Ash Engager in Splunk Search 11-24-2022
0 1
0
1
ayu2375
Hello,I am looking for the equivalent of performing SQL like such:SELECT transaction_id, vendorFROM ordersWHERE trans...
by ayu2375 Engager in Splunk Search 11-24-2022
0 2
0
2
singlinet
We have api requests that I want to create statistics by the request but to do this I need to remove variable identif...
by singlinet Engager in Splunk Search 11-24-2022
0 2
0
2
stong2351
I have an eval query. The details object returned looks like this: {<!-- --> status: 404, code: ERROR } "details...
by stong2351 New Member in Splunk Search 11-24-2022
0 2
0
2
indeed_2000
Hi need to generate current date like this "20201123" and use as a search filter on metadata. AFAIK there is no "_tim...
by indeed_2000 Motivator in Splunk Search 11-24-2022
0 6
0
6
dougburdan
I have a saved search running every few minutes to append data to a 15 day csv log file within Splunk.  I'm trying to...
by dougburdan Explorer in Splunk Search 11-24-2022
0 2
0
2
xiaoming
Hi all,  I am attempting to convert data extracted as a field containing combination of hex and ascii data. Was wonde...
by xiaoming New Member in Splunk Search 11-23-2022
0 3
0
3
ansif
Is there a way to achieve this?   I have  a lookup table with 2 columns alert_type and short_description.   alert_typ...
by ansif Motivator in Splunk Search 11-23-2022
0 5
0
5
MikeyD100
Hi, I want to display the error details in the last 30 mins, so they can be investigated, when the amount of errors h...
by MikeyD100 Explorer in Splunk Search 11-23-2022
0 4
0
4
PrisonMike
0
10
simo
Hi, I have a lookup as follow ipidname111.111.111.111111simone*222marco in the index I have  ipid 111.111.111.1111112...
by simo Path Finder in Splunk Search 11-23-2022
0 2
0
2
splunkuser320
I have a job that runs multiple times if it failed. I need to create a dashboard with a table that shows all the atte...
by splunkuser320 Path Finder in Splunk Search 11-23-2022
0 3
0
3
sphiwee
i have below result, how can I do a regex to extract the fields, first being DateTime, username, Action, Entity2022-1...
by sphiwee Contributor in Splunk Search 11-22-2022
0 2
0
2
renangomes
How do I check which major destinations generate the most logs on a specific firewall host &#61; 10.22.44.254? I would li...
by renangomes New Member in Splunk Search 11-22-2022
0 1
0
1
itsmevic70
Is it possible to create a Pie Chart from three fields? If so, how?   Thanks a million in advance! 
by itsmevic70 Explorer in Splunk Search 11-22-2022
0 2
0
2
Praveenrocky
Hi All,   i have events like below and i want to extract the fields as TotalRecords, SuccessRecords, FailedRecords, B...
by Praveenrocky New Member in Splunk Search 11-22-2022
0 2
0
2
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...