Splunk Search

Splunk Search
Community Activity
dmbrcx
Dumb question I cannot find a simple answer to. 藍 If I run a simple timechart search for 7 days, 30 days or 90 days -...
by dmbrcx Explorer in Splunk Search 11-07-2022
0 3
0
3
nabeel652
Could someone please show the difference between nomv and mvcombine with some examples? What I have seen is that both...
by nabeel652 Builder in Splunk Search 11-07-2022
0 2
0
2
ff170a
I have a dataset with a multiline field called Logs. The field typically has values like the below,     "mId": "Nul...
by ff170a Explorer in Splunk Search 11-07-2022
0 3
0
3
sh254087
I have a table with 1 column and 6 rows which I'll be changing to 1 row and 6 columns using transpose and eventually ...
by sh254087 Communicator in Splunk Search 11-07-2022
0 6
0
6
iamtheclient20
I have a SPL, when first running the result is appearing but once the query is finished the error have shown below: |...
by iamtheclient20 Explorer in Splunk Search 11-07-2022
1 8
1
8
Aryc090908
 Index=dev log-severity=INFO app name=abcd | rex “tv counts for indicator S = (?<Count>\d+)” | stats count by _...
by Aryc090908 Explorer in Splunk Search 11-07-2022
0 3
0
3
Hisham
Hi, I have generated a search which return list of hosts and the count of events for these host. sometime the host va...
by Hisham Engager in Splunk Search 11-07-2022
0 1
0
1
lennys26
On an existing dashboard I have a rather complex query that generates a timechart on which I am looking to use annota...
by lennys26 Communicator in Splunk Search 11-07-2022
0 2
0
2
jhilton90
I am using the following rex command to extract an id number, which is in the following format: 1e4gd5g7-4fy6-fg567-3...
by jhilton90 Path Finder in Splunk Search 11-07-2022
0 7
0
7
nihvk
I am looking for an alert when any search in (rest /services/saved/searches splunk_server=local) is being modified.
by nihvk Explorer in Splunk Search 11-07-2022
0 1
0
1
AKG11
Hi, I am looking to create timeseries graph based on multiple fields.we could have multiple hosts and each host have ...
by AKG11 Path Finder in Splunk Search 11-07-2022
0 5
0
5
karjsim
Hi,I have events which are received when action is finished on my system. Event contains start and stop time for acti...
by karjsim Loves-to-Learn Lots in Splunk Search 11-07-2022
0 9
0
9
sidtalup27
Hello, I have installed an App, and the data in APP is written to "MAIN" index. When I am search for DATA from the AP...
by sidtalup27 Explorer in Splunk Search 11-07-2022
0 3
0
3
anuhya_b
Hello Everyone, I have a field in this format and this information is fetched from a json array.Label apple 1apple 2a...
by anuhya_b Observer in Splunk Search 11-07-2022
0 1
0
1
mkshah
Hi ,how to do i display number of blocked and allowed threats with different severities in a timeframe(e.g monthly).S...
by mkshah New Member in Splunk Search 11-06-2022
0 1
0
1
user33
Hello, I am very new to Splunk. I am wondering how to split these two values into separate rows. The "API_Name" value...
by user33 Path Finder in Splunk Search 11-06-2022
0 7
0
7
priya1926
NONPROD:abcd123456_DBSERVERNeed to extract abcd123456 from the string...
by priya1926 Path Finder in Splunk Search 11-06-2022
0 1
0
1
jaycetan
The following is my ideal final query to be used in a dashboard.  index=cdn_app httpMessage.host=taxes* | eval _env=...
by jaycetan New Member in Splunk Search 11-05-2022
0 4
0
4
talktulika
How can I find an exact string which has double code in it. I want to find exact string HTTP/1.1" 500
by talktulika Observer in Splunk Search 11-04-2022
0 2
0
2
ilhwan
I have a search that writes to a lookup table.  I would like to run this search once a month and update (overwrite) t...
by ilhwan Path Finder in Splunk Search 11-04-2022
0 4
0
4
giolapid911
I have query that  returns successful logins and a profile ID. Then from the result of those I want to create another...
by giolapid911 New Member in Splunk Search 11-04-2022
0 1
0
1
vrmandadi
Hello Splunkers , I am using the following search which outputs the following fields   host ,Component  and output an...
by vrmandadi Builder in Splunk Search 11-04-2022
0 3
0
3
padrsri
Hello All,   The log has empty space before and after equal with semicolon separation. I’m unable to get the table re...
by padrsri Explorer in Splunk Search 11-04-2022
0 8
0
8
biju_babu
I want to achieve something like this: index=main servicetype="aws:accesslogs" (apps in ("app1","app2","app3")) note:...
by biju_babu Explorer in Splunk Search 11-04-2022
0 7
0
7
jhilton90
I am trying to use the rex command to extract an id number, which is a mixture of letters and numbers separated by a ...
by jhilton90 Path Finder in Splunk Search 11-04-2022
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...