Splunk Search

Splunk Search
Community Activity
coreyCLI
I recently migrated a clustered index.  We wanted to rename the index.  I created the new index as your normally woul...
by coreyCLI Communicator in Splunk Search 11-14-2022
0 0
0
0
adam_reber
I have a use case that uses an indexed field that is configured at input time: [monitor:///my/input/file1] _meta = n...
by adam_reber Path Finder in Splunk Search 11-13-2022
0 3
0
3
jbrenner
Let's say I have data in an event that looks like this:       NAME: John NAME: Mary NAME: Sue       Assuming I have ...
by jbrenner Path Finder in Splunk Search 11-13-2022
0 3
0
3
JLopez
Hi Guys,I'm trying to create a table with the count emails sent and emails received from a given emails addressesColu...
by JLopez Explorer in Splunk Search 11-13-2022
0 6
0
6
joe06031990
Hi, on our Splunk instance I have set a report using a time chart with a span of 1h and time frame of a day and the r...
by joe06031990 Communicator in Splunk Search 11-13-2022
0 5
0
5
Paul
Hello: I am trying to get fields from different events in the same table. I have two different events, and let's say ...
by Paul Explorer in Splunk Search 11-12-2022
0 3
0
3
indeed_2000
Hi I have challenge that need to know how with splunk, math, statistics, ... able to solve it. Here is the log: sampl...
by indeed_2000 Motivator in Splunk Search 11-11-2022
0 5
0
5
SumanPalisetty
Hi, I am facing an issue with the eval if condition. Please help.   index=main, source=ls.csv | eval new_field = if(e...
by SumanPalisetty Path Finder in Splunk Search 11-11-2022
0 1
0
1
brcox9090
I am trying to get a wildcard to work with a where clause. Not sure if I'm doing something wrong altogether or just m...
by brcox9090 New Member in Splunk Search 11-11-2022
0 2
0
2
manojchacko78
Hi, I am using the following script in Splunk query. Here i am trying having multiple values in field AdditionalData ...
by manojchacko78 Path Finder in Splunk Search 11-11-2022
0 3
0
3
Splunk_321
I have data something like below.  msg: {<!-- -->      application: test-app     correlationid: 0.59680117.1667864418.7d2b8d5...
by Splunk_321 Path Finder in Splunk Search 11-11-2022
0 1
0
1
thoma1
Can't seem to get this lookup(KVstore) to function.The dataset is from active directory in some cases in the same eve...
by thoma1 Explorer in Splunk Search 11-11-2022
0 11
0
11
Fleety
Hello,I have a collection of logs (same source type) but some of them have different or additional fields. In order t...
by Fleety Loves-to-Learn Lots in Splunk Search 11-11-2022
0 1
0
1
Berfomet96
Hello everybody, I'm trying to join two different sourcetypes from the same index that both have a field with the sam...
by Berfomet96 Explorer in Splunk Search 11-11-2022
0 2
0
2
wvsgo215
splunk data: 2022-01-01T02:06:12.182Z 7c3edf29-c081-4cca-ae9b-0f79ef7d1c8d INFO {"InfoLogInformation":{"MethodName":"...
by wvsgo215 Engager in Splunk Search 11-11-2022
0 2
0
2
sreesuresh545
Hi All, Having issue in identifying the correct blacklist regex expression to skip the few logs which are loading to ...
by sreesuresh545 New Member in Splunk Search 11-10-2022
0 4
0
4
SplunkDash
Hello  I have a quick question. are there any ways we can find a specific index name that was used within which App? ...
by SplunkDash Motivator in Splunk Search 11-10-2022
0 2
0
2
uagraw01
Hello Team, I have used to ask the same question in my previous ask :https://community.splunk.com/t5/Splunk-Search/Ho...
by uagraw01 Motivator in Splunk Search 11-10-2022
0 6
0
6
vrmandadi
I have the following query with multiple joins and using max&#61;0 which is not giving me all results as I think the size...
by vrmandadi Builder in Splunk Search 11-10-2022
0 3
0
3
shreyp
Hi all, Pls consider this subset of data,... - Date - Fruit - Seller - Bad_count - ...11/8 - Apple - X - 311/8 - Appl...
by shreyp Explorer in Splunk Search 11-10-2022
0 13
0
13
mlevsh
Hi,We are running Splunk on 3 EnvironmentsEnv#1 is Splunk Cloud v 8.2.2112.1Env#2 is Splunk Cloud v 9.0.2208.3Env#3 i...
by mlevsh Builder in Splunk Search 11-10-2022
0 2
0
2
aymane96
Hello community,I have a query returning result with an IP address value (src_ip).I used to add a line to match some ...
by aymane96 Engager in Splunk Search 11-10-2022
0 2
0
2
HeinzWaescher
Hi, let's say there is a field like this: FieldA &#61; product.country.price Is it possible to extract this value into 3 ...
by HeinzWaescher Motivator in Splunk Search 11-10-2022
2 9
2
9
faguilar
Hi Splunkers! Some days ago, one of my colleagues told me that "if you want to delete duplicates on your search, usi...
by faguilar Path Finder in Splunk Search 11-10-2022
5 5
5
5
mihir_hardas
Hi All, I have a SPL query that runs on an index , sourcetype which has milions of jobnames. I want to my SPL to read...
by mihir_hardas Explorer in Splunk Search 11-10-2022
0 10
0
10
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Solution Authors