Splunk Search

Splunk Search
Community Activity
Damek
Hello, I am currently using the |append method for some queries, but was curious if there is a better way for me to b...
by Damek Engager in Splunk Search 11-07-2022
0 2
0
2
dmbrcx
Dumb question I cannot find a simple answer to. 藍 If I run a simple timechart search for 7 days, 30 days or 90 days -...
by dmbrcx Explorer in Splunk Search 11-07-2022
0 3
0
3
nabeel652
Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both...
by nabeel652 Builder in Splunk Search 11-07-2022
0 2
0
2
ff170a
I have a dataset with a multiline field called Logs. The field typically has values like the below,     "mId": "Nul...
by ff170a Explorer in Splunk Search 11-07-2022
0 3
0
3
sh254087
I have a table with 1 column and 6 rows which I'll be changing to 1 row and 6 columns using transpose and eventually ...
by sh254087 Communicator in Splunk Search 11-07-2022
0 6
0
6
iamtheclient20
I have a SPL, when first running the result is appearing but once the query is finished the error have shown below: |...
by iamtheclient20 Explorer in Splunk Search 11-07-2022
1 8
1
8
Aryc090908
 Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _...
by Aryc090908 Explorer in Splunk Search 11-07-2022
0 3
0
3
Hisham
Hi, I have generated a search which return list of hosts and the count of events for these host. sometime the host va...
by Hisham Engager in Splunk Search 11-07-2022
0 1
0
1
lennys26
On an existing dashboard I have a rather complex query that generates a timechart on which I am looking to use annota...
by lennys26 Communicator in Splunk Search 11-07-2022
0 2
0
2
jhilton90
I am using the following rex command to extract an id number, which is in the following format: 1e4gd5g7-4fy6-fg567-3...
by jhilton90 Path Finder in Splunk Search 11-07-2022
0 7
0
7
nihvk
I am looking for an alert when any search in (rest /services/saved/searches splunk_server=local) is being modified.
by nihvk Explorer in Splunk Search 11-07-2022
0 1
0
1
AKG11
Hi, I am looking to create timeseries graph based on multiple fields.we could have multiple hosts and each host have ...
by AKG11 Path Finder in Splunk Search 11-07-2022
0 5
0
5
karjsim
Hi,I have events which are received when action is finished on my system. Event contains start and stop time for acti...
by karjsim Loves-to-Learn Lots in Splunk Search 11-07-2022
0 9
0
9
sidtalup27
Hello, I have installed an App, and the data in APP is written to "MAIN" index. When I am search for DATA from the AP...
by sidtalup27 Explorer in Splunk Search 11-07-2022
0 3
0
3
anuhya_b
Hello Everyone, I have a field in this format and this information is fetched from a json array.Label apple 1apple 2a...
by anuhya_b Observer in Splunk Search 11-07-2022
0 1
0
1
mkshah
Hi ,how to do i display number of blocked and allowed threats with different severities in a timeframe(e.g monthly).S...
by mkshah New Member in Splunk Search 11-06-2022
0 1
0
1
user33
Hello, I am very new to Splunk. I am wondering how to split these two values into separate rows. The "API_Name" value...
by user33 Path Finder in Splunk Search 11-06-2022
0 7
0
7
priya1926
NONPROD:abcd123456_DBSERVERNeed to extract abcd123456 from the string...
by priya1926 Path Finder in Splunk Search 11-06-2022
0 1
0
1
jaycetan
The following is my ideal final query to be used in a dashboard.  index=cdn_app httpMessage.host=taxes* | eval _env=...
by jaycetan New Member in Splunk Search 11-05-2022
0 4
0
4
talktulika
How can I find an exact string which has double code in it. I want to find exact string HTTP/1.1" 500
by talktulika Observer in Splunk Search 11-04-2022
0 2
0
2
ilhwan
I have a search that writes to a lookup table.  I would like to run this search once a month and update (overwrite) t...
by ilhwan Path Finder in Splunk Search 11-04-2022
0 4
0
4
giolapid911
I have query that  returns successful logins and a profile ID. Then from the result of those I want to create another...
by giolapid911 New Member in Splunk Search 11-04-2022
0 1
0
1
vrmandadi
Hello Splunkers , I am using the following search which outputs the following fields   host ,Component  and output an...
by vrmandadi Builder in Splunk Search 11-04-2022
0 3
0
3
padrsri
Hello All,   The log has empty space before and after equal with semicolon separation. I’m unable to get the table re...
by padrsri Explorer in Splunk Search 11-04-2022
0 8
0
8
biju_babu
I want to achieve something like this: index=main servicetype="aws:accesslogs" (apps in ("app1","app2","app3")) note:...
by biju_babu Explorer in Splunk Search 11-04-2022
0 7
0
7
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...