Splunk Search

Splunk Search
Community Activity
babukumarreddy
Hi  For example  Using below query i can see  when we received the last log to splunk, based on that if I search for ...
by babukumarreddy Loves-to-Learn Lots in Splunk Search 10-21-2022
0 5
0
5
sjringo
Hi, I have the following SPL working fine when I have a starting event and ending event in my logs. If I have a start...
by sjringo Contributor in Splunk Search 10-21-2022
0 2
0
2
bosseres
Hello everyone! What is the best way to remove dots from domain in field? for example | eval field = lower(mvindex(sp...
by bosseres Contributor in Splunk Search 10-21-2022
0 4
0
4
dlcrooks
According to the docs for cron the Sunday code is 0.   When I try to run this cron for the first Sunday of the month ...
by dlcrooks Explorer in Splunk Search 10-21-2022
0 10
0
10
metylkinandrey
Good afternoon!I have a request based on which I create an aller: index="main" sourcetype="testsystem-script707" | ev...
by metylkinandrey Communicator in Splunk Search 10-21-2022
0 6
0
6
mv10
We have alerts for high Windows Server CPU usage, and we have automated vulnerability scanners which can trip these a...
by mv10 Path Finder in Splunk Search 10-21-2022
0 12
0
12
mnj1809
Hello, I need your help to find a way to achieve the following use case:in main search:I've to categories: Windows an...
by mnj1809 Path Finder in Splunk Search 10-21-2022
0 8
0
8
ChrisG
Beyond what's in the Search Reference and the Search Manual, are there other sites that have SPL examples available t...
by ChrisG Splunk Employee Splunk Employee in Splunk Search 10-21-2022
1 11
1
11
codeJesus
Hello,  please can someone assist with creating syntax to 1. know the numbers of desktop, laptops, servers and networ...
by codeJesus Engager in Splunk Search 10-21-2022
0 4
0
4
uagraw01
To provide further from yesterday's SPL query. I am facing huge events in multivalues. I want to break in a single ev...
by uagraw01 Motivator in Splunk Search 10-20-2022
0 1
0
1
klim
Is it possible to restrict a role to run a certain search or only be able to run saved searches?Ie a user can only ru...
by klim Path Finder in Splunk Search 10-20-2022
0 0
0
0
leeyounsoo
hello I have a question I have a data that access_log data and json data is mixed and my need is to extract field fr...
by leeyounsoo Path Finder in Splunk Search 10-20-2022
0 10
0
10
PawelKozy
Add "A" field from another index if "B" and ""C" are equal across indexesI have search that returns events with field...
by PawelKozy Loves-to-Learn Lots in Splunk Search 10-20-2022
0 5
0
5
napoleon182
Hello Splunk Ninjas! I will require your assistance with designing my regex expression. I need to filter for the valu...
by napoleon182 Explorer in Splunk Search 10-20-2022
0 2
0
2
mcaulsc
Hi, Any thoughts appreciated. I have some connection data captured at connection termination, it has connection start...
by mcaulsc Path Finder in Splunk Search 10-20-2022
0 6
0
6
usarios
The goal is to take all eventIds with "operation failed" and exclude events with "Duplicate key" and "Event processed...
by usarios Engager in Splunk Search 10-20-2022
0 2
0
2
uagraw01
Hello Splunkers !!   Last weekCurrent weekNew Error "enableEnhancedCheckout" "enableEnhancedCheckout" "error_in_pytho...
by uagraw01 Motivator in Splunk Search 10-20-2022
0 9
0
9
metylkinandrey
Good afternoon! I figured out how to set up alerts. Understood with the parameter: Cron Expression. Currently I am us...
by metylkinandrey Communicator in Splunk Search 10-20-2022
0 3
0
3
Manth
I have splunk logs as given below. However, I wanted display fields in between square brackets "[ ]" in a table as gi...
by Manth Explorer in Splunk Search 10-19-2022
0 3
0
3
restinlinux
i want to pass the input token to my base search. In the panel its shows no results found, but when try click on "ope...
by restinlinux Explorer in Splunk Search 10-19-2022
0 1
0
1
mnowaczy
Hi,I am struggling with the configuration pxGrid on Splunk for Rapid Threat Containment with ISE.I just installed a n...
by mnowaczy New Member in Splunk Search 10-19-2022
0 1
0
1
RichieH
Hi All, When running a search the following error will appear in the job inspector. Users get this message intermitte...
by RichieH Explorer in Splunk Search 10-19-2022
0 4
0
4
dj56
Hello, Assuming i have numbers, let's say 1-2-3-4-5-6. And each of those represent Ip adressnumber of requestmethod1....
by dj56 Explorer in Splunk Search 10-19-2022
0 9
0
9
wanda619
how to set an alert running every day hourly? ex - if new transactions /events occur alert the user
by wanda619 Path Finder in Splunk Search 10-19-2022
0 3
0
3
danutmatei
Hi, I have an inputlookup with wSender, wSubject and wRecipient. I want to whitelist some of the emails sent by an us...
by danutmatei Explorer in Splunk Search 10-19-2022
0 2
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors