Splunk Search

Splunk Search
Community Activity
maverick
In Splunk GUI, after I create a real time report and put it on my dashboard, it eventually times out. Wondering if th...
by maverick Splunk Employee Splunk Employee in Splunk Search 11-02-2022
6 9
6
9
smanojkumar
My requirement is to utilize the results of the sub-search and use it with the results of the main search results, bu...
by smanojkumar Contributor in Splunk Search 11-02-2022
0 1
0
1
jkang117
Hello everyone. I am trying to track office and remote logins using multiple indexes with the transaction command. On...
by jkang117 Loves-to-Learn Everything in Splunk Search 11-02-2022
0 4
0
4
NizanCohen
Hi all. I currently experiencing an issue where simple strings won't provide any events while two weeks ago I had. Do...
by NizanCohen Explorer in Splunk Search 11-02-2022
0 3
0
3
NizanCohen
Hi all. I use Splunk on my workplace and recently I feel like it's performance is decreasing. Basic search queries li...
by NizanCohen Explorer in Splunk Search 11-02-2022
0 5
0
5
greekleo89
Hi   I have a search  index=main sourcetype=data2 type=policythat gives me the following in json: customerId: man0000...
by greekleo89 Loves-to-Learn Everything in Splunk Search 11-02-2022
0 7
0
7
ejohn
I'm trying to do something pretty straightforward, and have looked at  practically every "average" answer on Splunk C...
by ejohn Path Finder in Splunk Search 11-02-2022
0 5
0
5
Said7
Hi, I have an issue with about a searching, someone know about it, this is the issue: Error in search: "Configura...
by Said7 Explorer in Splunk Search 11-01-2022
1 7
1
7
sidtalup27
Hello,In the events, the severity is captured as values between 1 to 10. I want to represent them as High, Low, Mediu...
by sidtalup27 Explorer in Splunk Search 11-01-2022
0 1
0
1
queryboy
I need to add multiple values from a CSV to a main Search I have, I used the lookup command but I think that will jus...
by queryboy Explorer in Splunk Search 11-01-2022
0 3
0
3
karu0711
I use  index= main | lookup test1.csv Severity1 | stats  count by Severity  The lookup table have 5 value ( Veryhigh,...
by karu0711 Communicator in Splunk Search 11-01-2022
0 18
0
18
fpedrosa
Hello y'all!I'm trying to use the Single Value object, and build a search which count the number of the records and s...
by fpedrosa Engager in Splunk Search 11-01-2022
0 7
0
7
cpm003
Hello all! I´m so lost trying to get full process tree to visualize it in dendogram https://splunkbase.splunk.com/app...
by cpm003 Path Finder in Splunk Search 11-01-2022
0 1
0
1
SumanPalisetty
Hi, I have used eval with multiple if conditions and it's failing. Kindly help.   source = "2access_30DAY.log" | eva...
by SumanPalisetty Path Finder in Splunk Search 11-01-2022
0 7
0
7
loki
Hi, I have been tasked to design an alert to trigger whenever there is a modification of the "search query" of an ale...
by loki New Member in Splunk Search 11-01-2022
0 1
0
1
boxmetal
Hi Splunk Community, I need help to check whether my directory field match the regex The regex I used is ^\w+:\\root_...
by boxmetal Path Finder in Splunk Search 11-01-2022
0 3
0
3
syloee
hello index=_audit user=admin action=search info=granted search=* | table search_id search| replace "'search *" WITH ...
by syloee Explorer in Splunk Search 11-01-2022
0 3
0
3
metylkinandrey
Good afternoon!The infrastructure command gave me permissions so that I can add a dashboard tab to my application. I ...
by metylkinandrey Communicator in Splunk Search 11-01-2022
0 9
0
9
aa0
Hi all,I'm trying to create category based on host category: Lab,Personal,Staff and get workstations to be counted fo...
by aa0 Path Finder in Splunk Search 11-01-2022
0 2
0
2
paras
I need to be able to split multiple fields that have a delimiter of "|#|". The field name will differ depending on th...
by paras Explorer in Splunk Search 10-31-2022
0 2
0
2
SumanPalisetty
Hi, I wrote a eval command and its not working. Kindly help. source = "2access_30DAY.log" | eval "new_field" = case('...
by SumanPalisetty Path Finder in Splunk Search 10-31-2022
0 7
0
7
AK_Splunk
SPL to extract field and field value when data seems like belowscreenshot attached.I need help in extracting field as...
by AK_Splunk Explorer in Splunk Search 10-31-2022
0 3
0
3
tobiasboone1
I have a unique query that I think I have a general logical approach to solving, but the syntax and most efficient ro...
by tobiasboone1 Explorer in Splunk Search 10-31-2022
0 10
0
10
SumanPalisetty
Hi, Can we concatenate a string with a number using eval with '.' operator? I got to know that from a video, but when...
by SumanPalisetty Path Finder in Splunk Search 10-31-2022
0 3
0
3
andrew_burnett
I have a distributed Splunk environment, meaning a SHC and IDX cluster connected via distributed search as outlined i...
by andrew_burnett Path Finder in Splunk Search 10-31-2022
0 1
0
1
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors