Splunk Search

Splunk Search
Community Activity
alakdam
Short description:When a consumer orders groceries online, I provide the picker—the individual who picked the foods b...
by alakdam Path Finder in Splunk Search 10-07-2022
0 3
0
3
eng3
I'm trying to export raw linux audit logs to a file.  For example:       splunk.exe "sourcetype=linux:audit _time>xxx...
by eng3 New Member in Splunk Search 10-06-2022
0 2
0
2
Sanjana
Hello , I have splunk logger line like below: Address: XXX HttpMethod: POST  Headers: {<!-- -->Ama-Internal-REST-Service&#61;hote...
by Sanjana Explorer in Splunk Search 10-06-2022
0 2
0
2
TBH0
I have a lookup which has a field with time values (in 24 hr time; i.e. 00:30, 13:45, 23:15), which tells my dashboar...
by TBH0 Explorer in Splunk Search 10-06-2022
0 6
0
6
sjringo
I am performing a search for two events. A start event and a stop event for a specific job Name. I have ran into an i...
by sjringo Contributor in Splunk Search 10-06-2022
0 12
0
12
kcheek_umich
I'm trying to use eval within stats to work with data from tstats, but it doesn't seem to work the way I expected it ...
by kcheek_umich New Member in Splunk Search 10-06-2022
0 8
0
8
thahir
When conducting searches, we have observed that the SPL searches were not working based on the "earliest" time range ...
by thahir Contributor in Splunk Search 10-06-2022
0 3
0
3
Hugues
hello all, My problem is I thing Splunk have max character accepted for stats command, when i perform this search ind...
by Hugues Path Finder in Splunk Search 10-06-2022
0 15
0
15
kiddsupreme
Not sure if I am putting this in the correct area; my apologies ahead of time. I wanted to know if it would be possib...
by kiddsupreme Explorer in Splunk Search 10-06-2022
0 1
0
1
manderson7
I'm really bad when it comes to join searches, though I've been doing this for years.  I'm able to find the list of o...
by manderson7 Contributor in Splunk Search 10-06-2022
0 2
0
2
alakdam
I have two two columns of data, One is Expected box and another is Actual box.  I would like to make Percentage/Avera...
by alakdam Path Finder in Splunk Search 10-06-2022
0 7
0
7
JykkeDaMan
Isn't hyphen a minor breaker so I'm wondering why the values with hyphen get double quoted when doing summary indexin...
by JykkeDaMan Path Finder in Splunk Search 10-06-2022
0 3
0
3
metylkinandrey
Prompt as I can make arithmetic comparison of two fields. Comparison: more, less.The first field consists of numbers:...
by metylkinandrey Communicator in Splunk Search 10-06-2022
0 7
0
7
POR160893
Hi, I am trying to concatenate 3 fields into 1 field but I am unable to do so.I tried: and this: Can someone help? ...
by POR160893 Builder in Splunk Search 10-06-2022
0 4
0
4
metylkinandrey
Tell me, what should I do in my case, I need from the field: 1.SAPS-SIS.TO.LSP.SEND, or: "12.SAPS-SIS.TO.LSP.RECEIVEG...
by metylkinandrey Communicator in Splunk Search 10-06-2022
0 2
0
2
NizanCohen
Hi all. It might sound weird but I need assistance converting Azure Sentinel queries to SPL. The main goal is to use ...
by NizanCohen Explorer in Splunk Search 10-06-2022
0 0
0
0
chq_alanf
I'm not sure I asked the right question, but I'd like to use substr to extract the first 3 letters of a field and use...
by chq_alanf Explorer in Splunk Search 10-06-2022
2 9
2
9
alakdam
I have total 17 orders.  Box Estimates is wrong 6 out of 17 orders. What is the average wrong box estimate in total?T...
by alakdam Path Finder in Splunk Search 10-06-2022
0 17
0
17
uagraw01
Hello Splunker! I created below regex from the raw events. And I want to create an alert which show the event in one ...
by uagraw01 Motivator in Splunk Search 10-06-2022
0 5
0
5
alakdam
One dashboard was made by me. I'm showing my colleagues my dashboard. Problem: When my coworkers or I access that Spl...
by alakdam Path Finder in Splunk Search 10-06-2022
0 2
0
2
san112491
Static data with one common field app Name as splunk query.
by san112491 New Member in Splunk Search 10-06-2022
0 2
0
2
alakdam
I have a data where I got empty object. I would like count in total how many empty object in one table data and also ...
by alakdam Path Finder in Splunk Search 10-05-2022
0 10
0
10
akshayinnamuri
HiI am looking for query where say for example user&#61;xyz which is present in multiple watchlists [watchlist_A.csv, wat...
by akshayinnamuri Loves-to-Learn Lots in Splunk Search 10-05-2022
0 1
0
1
rkoster
| makeresults count&#61;1| eval list_split_failure_1 &#61; "fail:,searching old data:,searching new"| eval list_split_failure...
by rkoster Explorer in Splunk Search 10-05-2022
0 1
0
1
username13
Hi guys,I need to evaluate a disruption.  It can last multiple hours, so I need to use data which is at least 4h old....
by username13 Explorer in Splunk Search 10-05-2022
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...