Splunk Search

Splunk Search
Community Activity
NizanCohen
Hi all. I use Splunk on my workplace and recently I feel like it's performance is decreasing. Basic search queries li...
by NizanCohen Explorer in Splunk Search 11-02-2022
0 5
0
5
greekleo89
Hi   I have a search  index=main sourcetype=data2 type=policythat gives me the following in json: customerId: man0000...
by greekleo89 Loves-to-Learn Everything in Splunk Search 11-02-2022
0 7
0
7
ejohn
I'm trying to do something pretty straightforward, and have looked at  practically every "average" answer on Splunk C...
by ejohn Path Finder in Splunk Search 11-02-2022
0 5
0
5
Said7
Hi, I have an issue with about a searching, someone know about it, this is the issue: Error in search: "Configura...
by Said7 Explorer in Splunk Search 11-01-2022
1 7
1
7
sidtalup27
Hello,In the events, the severity is captured as values between 1 to 10. I want to represent them as High, Low, Mediu...
by sidtalup27 Explorer in Splunk Search 11-01-2022
0 1
0
1
queryboy
I need to add multiple values from a CSV to a main Search I have, I used the lookup command but I think that will jus...
by queryboy Explorer in Splunk Search 11-01-2022
0 3
0
3
karu0711
I use  index= main | lookup test1.csv Severity1 | stats  count by Severity  The lookup table have 5 value ( Veryhigh,...
by karu0711 Communicator in Splunk Search 11-01-2022
0 18
0
18
fpedrosa
Hello y'all!I'm trying to use the Single Value object, and build a search which count the number of the records and s...
by fpedrosa Engager in Splunk Search 11-01-2022
0 7
0
7
cpm003
Hello all! I´m so lost trying to get full process tree to visualize it in dendogram https://splunkbase.splunk.com/app...
by cpm003 Path Finder in Splunk Search 11-01-2022
0 1
0
1
SumanPalisetty
Hi, I have used eval with multiple if conditions and it's failing. Kindly help.   source = "2access_30DAY.log" | eva...
by SumanPalisetty Path Finder in Splunk Search 11-01-2022
0 7
0
7
loki
Hi, I have been tasked to design an alert to trigger whenever there is a modification of the "search query" of an ale...
by loki New Member in Splunk Search 11-01-2022
0 1
0
1
boxmetal
Hi Splunk Community, I need help to check whether my directory field match the regex The regex I used is ^\w+:\\root_...
by boxmetal Path Finder in Splunk Search 11-01-2022
0 3
0
3
syloee
hello index=_audit user=admin action=search info=granted search=* | table search_id search| replace "'search *" WITH ...
by syloee Explorer in Splunk Search 11-01-2022
0 3
0
3
metylkinandrey
Good afternoon!The infrastructure command gave me permissions so that I can add a dashboard tab to my application. I ...
by metylkinandrey Communicator in Splunk Search 11-01-2022
0 9
0
9
aa0
Hi all,I'm trying to create category based on host category: Lab,Personal,Staff and get workstations to be counted fo...
by aa0 Path Finder in Splunk Search 11-01-2022
0 2
0
2
paras
I need to be able to split multiple fields that have a delimiter of "|#|". The field name will differ depending on th...
by paras Explorer in Splunk Search 10-31-2022
0 2
0
2
SumanPalisetty
Hi, I wrote a eval command and its not working. Kindly help. source = "2access_30DAY.log" | eval "new_field" = case('...
by SumanPalisetty Path Finder in Splunk Search 10-31-2022
0 7
0
7
AK_Splunk
SPL to extract field and field value when data seems like belowscreenshot attached.I need help in extracting field as...
by AK_Splunk Explorer in Splunk Search 10-31-2022
0 3
0
3
tobiasboone1
I have a unique query that I think I have a general logical approach to solving, but the syntax and most efficient ro...
by tobiasboone1 Explorer in Splunk Search 10-31-2022
0 10
0
10
SumanPalisetty
Hi, Can we concatenate a string with a number using eval with '.' operator? I got to know that from a video, but when...
by SumanPalisetty Path Finder in Splunk Search 10-31-2022
0 3
0
3
andrew_burnett
I have a distributed Splunk environment, meaning a SHC and IDX cluster connected via distributed search as outlined i...
by andrew_burnett Path Finder in Splunk Search 10-31-2022
0 1
0
1
vinceisvince
I can control the data sent to the fields.  All fields on the deafult search allow you include/exclude in search resu...
by vinceisvince Observer in Splunk Search 10-31-2022
0 1
0
1
SumanPalisetty
Hi,I have a question for my understanding. Kindly help.You had data in the past, one fine day if you see there is no ...
by SumanPalisetty Path Finder in Splunk Search 10-31-2022
0 4
0
4
GaetanVP
Hello Splunkers,I am facing some errors every time I relaunch my Splunk service on my HF.Inside splunkd.log I have th...
by GaetanVP Contributor in Splunk Search 10-31-2022
0 2
0
2
Woodpecker
Hey Splunkers,Can someone please help me with the logic, how can I finetune the search below to detect DNS tunnelling...
by Woodpecker Path Finder in Splunk Search 10-31-2022
0 1
0
1
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors