Splunk Search

Splunk Search
Community Activity
kiddsupreme
Not sure if I am putting this in the correct area; my apologies ahead of time. I wanted to know if it would be possib...
by kiddsupreme Explorer in Splunk Search 10-06-2022
0 1
0
1
manderson7
I'm really bad when it comes to join searches, though I've been doing this for years.  I'm able to find the list of o...
by manderson7 Contributor in Splunk Search 10-06-2022
0 2
0
2
alakdam
I have two two columns of data, One is Expected box and another is Actual box.  I would like to make Percentage/Avera...
by alakdam Path Finder in Splunk Search 10-06-2022
0 7
0
7
JykkeDaMan
Isn't hyphen a minor breaker so I'm wondering why the values with hyphen get double quoted when doing summary indexin...
by JykkeDaMan Path Finder in Splunk Search 10-06-2022
0 3
0
3
metylkinandrey
Prompt as I can make arithmetic comparison of two fields. Comparison: more, less.The first field consists of numbers:...
by metylkinandrey Communicator in Splunk Search 10-06-2022
0 7
0
7
POR160893
Hi, I am trying to concatenate 3 fields into 1 field but I am unable to do so.I tried: and this: Can someone help? ...
by POR160893 Builder in Splunk Search 10-06-2022
0 4
0
4
metylkinandrey
Tell me, what should I do in my case, I need from the field: 1.SAPS-SIS.TO.LSP.SEND, or: "12.SAPS-SIS.TO.LSP.RECEIVEG...
by metylkinandrey Communicator in Splunk Search 10-06-2022
0 2
0
2
NizanCohen
Hi all. It might sound weird but I need assistance converting Azure Sentinel queries to SPL. The main goal is to use ...
by NizanCohen Explorer in Splunk Search 10-06-2022
0 0
0
0
chq_alanf
I'm not sure I asked the right question, but I'd like to use substr to extract the first 3 letters of a field and use...
by chq_alanf Explorer in Splunk Search 10-06-2022
2 9
2
9
alakdam
I have total 17 orders.  Box Estimates is wrong 6 out of 17 orders. What is the average wrong box estimate in total?T...
by alakdam Path Finder in Splunk Search 10-06-2022
0 17
0
17
LogUx
Hello Splunker! I created below regex from the raw events. And I want to create an alert which show the event in one ...
by LogUx Motivator in Splunk Search 10-06-2022
0 5
0
5
alakdam
One dashboard was made by me. I'm showing my colleagues my dashboard. Problem: When my coworkers or I access that Spl...
by alakdam Path Finder in Splunk Search 10-06-2022
0 2
0
2
san112491
Static data with one common field app Name as splunk query.
by san112491 New Member in Splunk Search 10-06-2022
0 2
0
2
alakdam
I have a data where I got empty object. I would like count in total how many empty object in one table data and also ...
by alakdam Path Finder in Splunk Search 10-05-2022
0 10
0
10
akshayinnamuri
HiI am looking for query where say for example user=xyz which is present in multiple watchlists [watchlist_A.csv, wat...
by akshayinnamuri Loves-to-Learn Lots in Splunk Search 10-05-2022
0 1
0
1
rkoster
| makeresults count=1| eval list_split_failure_1 = "fail:,searching old data:,searching new"| eval list_split_failure...
by rkoster Explorer in Splunk Search 10-05-2022
0 1
0
1
username13
Hi guys,I need to evaluate a disruption.  It can last multiple hours, so I need to use data which is at least 4h old....
by username13 Explorer in Splunk Search 10-05-2022
0 3
0
3
reed_kelly
I would like to send a search with a specific time range to people in different time zones. I can use earliest and la...
by reed_kelly Contributor in Splunk Search 10-05-2022
0 6
0
6
Julia1231
Hi everybody, I am creating a Dashboard using Splunk and I'm searching for a solution. I have a list machine accordin...
by Julia1231 Communicator in Splunk Search 10-05-2022
0 2
0
2
Rajaion
Hello community, I am having a problem with a dashboard that I am setting up based on Splunk OnCall data, in order to...
by Rajaion Path Finder in Splunk Search 10-05-2022
0 6
0
6
monicateja
Hi, How can we calculate milli seconds to seconds for this field -> transactionDuration=20058?
by monicateja Explorer in Splunk Search 10-05-2022
0 3
0
3
leon12
Hey Guys, I have the following data in Splunk. Each eventdata has 4 lines (which are seperated through newLines) and ...
by leon12 Loves-to-Learn in Splunk Search 10-05-2022
0 1
0
1
jip31
Hello as you can see "type" field as 3 values : stand, vd or xe if the "type" field is "vd" or "xe", I need to gather...
by jip31 Motivator in Splunk Search 10-05-2022
0 6
0
6
untitledman27
i All   There are query splunk like this :  (index=Prod sourcetype=ProdApp (host=Prod01 OR Prod02) source="/prodlib/S...
by untitledman27 Loves-to-Learn Everything in Splunk Search 10-05-2022
0 24
0
24
monicateja
How can i convert timestamp to date for below timestamp to just date 2022-10-04. timestamp: 2022-10-04 19:52:00.151 ...
by monicateja Explorer in Splunk Search 10-05-2022
0 3
0
3
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors