Splunk Search

Splunk Search
Community Activity
agupta13
I have an ```index=xyz data.id=1```which gives me list of unique id's [1,2,3,4,5]Not sure how to store the above resu...
by agupta13 Engager in Splunk Search 10-18-2022
0 2
0
2
SplunkDash
Hello, How I would assign one source type to two different indexes, one after another. As an example: I assigned sour...
by SplunkDash Motivator in Splunk Search 10-18-2022
0 16
0
16
SplunkDash
Hello, I need to install ARUBA TA; do you have any recommendations on how to proceed.  Your recommendations will be h...
by SplunkDash Motivator in Splunk Search 10-18-2022
0 0
0
0
splunkcol
Hello,When I run a query I get the results as I need them in a table from Splunk but when I download the .csv file, t...
by splunkcol Builder in Splunk Search 10-18-2022
0 3
0
3
upranger101
Hi I am trying to capture all event="DcSyncs" from my index. This index also contains event="DcID". The event "DCSync...
by upranger101 Engager in Splunk Search 10-18-2022
0 2
0
2
Racer73b
Hi All, I'm trying to optimize the following search because it runs very slow.  Looking for some help w/it.  I've bee...
by Racer73b Explorer in Splunk Search 10-18-2022
0 10
0
10
adent
I am trying to add fields from a lookup table. However, the matching field is a multivalue field. I need to expand th...
by adent Explorer in Splunk Search 10-18-2022
0 3
0
3
Rithekakan
Hi Spelunker, I want to create a field "Credentialed checks:" with this field value. Please help. regards, Nessus ver...
by Rithekakan Path Finder in Splunk Search 10-18-2022
0 2
0
2
alakhotia
I have a query in a panel, that is being outputted in a table. Can I adjust the width of one of the columns, shrinkin...
by alakhotia Explorer in Splunk Search 10-18-2022
0 7
0
7
Mr_Data_2018
I have a list of IPs and want to check if they are sending data to Splunk but using a single query.The devices in thi...
by Mr_Data_2018 New Member in Splunk Search 10-18-2022
0 1
0
1
splkjk
Hello Team, I'm new to splunk, trying to get some insight/help for the below issue I'm trying to read data from 2 dif...
by splkjk Explorer in Splunk Search 10-18-2022
0 6
0
6
klim
I have a lookup table that I want to use in a search. So I load the lookup table and use format. However I noticed th...
by klim Path Finder in Splunk Search 10-18-2022
0 3
0
3
thejasplunk67
Hi there,Kindly help me on  Search to trigger an alert by scan the logs for scheduled job and check elapsed time (thr...
by thejasplunk67 Engager in Splunk Search 10-18-2022
0 2
0
2
lukas1
Hi,I have a lot of event data, where every instance can be idendified by a unique ID. Every instance contains several...
by lukas1 Explorer in Splunk Search 10-18-2022
0 6
0
6
acj
Splunk logs missing for few scheduler jobsIs there way to find the missing logs using some advanced search
by acj Observer in Splunk Search 10-18-2022
0 5
0
5
patpro
Hello, I'm trying to use ldapfilter to add some info to events I collect from MS Exchange but as soon as my ldapfilte...
by patpro Path Finder in Splunk Search 10-18-2022
0 6
0
6
lucky
please help I need to compare and display the last 30days data and last 15mnts data 
by lucky Explorer in Splunk Search 10-18-2022
0 10
0
10
pc1234
I need to create a search and subsearch to exclude results in a query.  the primary search is a lookup table. the sub...
by pc1234 Explorer in Splunk Search 10-17-2022
0 1
0
1
dfphere
I'm attempting to utilize a lookup to pass static strings to create 'stats' commands. The result is sent to the searc...
by dfphere Explorer in Splunk Search 10-17-2022
0 3
0
3
Zarack
I tried to do it this way, but the results don't match.How can i show the result of the first search and then the sec...
by Zarack Engager in Splunk Search 10-17-2022
0 1
0
1
user33
I have two events where in order to get a response time, I need to subtract the two timestamps. However, this needs t...
by user33 Path Finder in Splunk Search 10-17-2022
0 3
0
3
alakhotia
I have a field with data like this: loggingObject.methodName="WXYX.MNOController.myMethodName". loggingObject.methodN...
by alakhotia Explorer in Splunk Search 10-17-2022
0 3
0
3
loganseth
I have two streams of data coming into a HEC.  one has call direction (i.e. inbound) and the other has call dispositi...
by loganseth Path Finder in Splunk Search 10-17-2022
0 9
0
9
neerajs_81
Hi All,  Before i post here i have tried everything under https://community.splunk.com/t5/Splunk-Search/How-to-join-2...
by neerajs_81 Builder in Splunk Search 10-17-2022
0 5
0
5
dritjon
I've done a simple search like this:index=fw_cisco | stats dc(dest_ip) as NrDestIp by src_ipI have defined a lookup f...
by dritjon Path Finder in Splunk Search 10-17-2022
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...