Splunk Search

Splunk Search
Community Activity
sekhar463
Hai all,Need help on to extract as new filed for user named after CORP\Message&#61;Task Scheduler started "{<!-- -->B9F5A32A-A340...
by sekhar463 Path Finder in Splunk Search 09-28-2022
0 7
0
7
drikusc
I have an issue where the logs aren't ingested regularly. The log file updates every 5 minutes with the same line ent...
by drikusc New Member in Splunk Search 09-28-2022
0 2
0
2
dmoberg
For the type of data I am trying to extract, Event Sampling really speeds up the query. This works fine when executin...
by dmoberg Path Finder in Splunk Search 09-28-2022
0 5
0
5
simon1524
For example, the "SUBMIT_DATE" is split by date and time. Then define some period of time as a value(A/B/C). Can this...
by simon1524 Explorer in Splunk Search 09-27-2022
0 8
0
8
ghostrider
I want to filter the search results based on tx_id that I extract in the 2nd rex. Meaning only those results that hav...
by ghostrider Path Finder in Splunk Search 09-27-2022
0 2
0
2
Sanjana
Hello, I have data like below.  {"property":"XYZ", "period":{ "start":"2022-09-16", "end":"2022-10-02" }, "nb-day":17...
by Sanjana Explorer in Splunk Search 09-27-2022
0 7
0
7
Sanjana
Hey all, I am trying to extract dynamic field from json . {"period":{"start":"2023-04-17","end":"2023-05-14"},"check-...
by Sanjana Explorer in Splunk Search 09-27-2022
0 5
0
5
dennis_u
Say, we have events like this: _timefwsrc_ipdest_ipdest_portfw_rule_action8/1/22 1:30:00.000 AMfw1192.168.50.518.8.8....
by dennis_u Observer in Splunk Search 09-27-2022
0 2
0
2
kevinb0011
Good morning, Curious to see if anyone has used a similar dataset in Splunk and/or any suggestions on the best way to...
by kevinb0011 Explorer in Splunk Search 09-27-2022
0 5
0
5
cbiraris
Hi Team,I have  several Dashboards that contain base searches data from reports  for example: &lt;search id&#61;"baseSearch"...
by cbiraris Path Finder in Splunk Search 09-27-2022
0 3
0
3
tomapatan
I have 2 fields: the values of fieldA are present in fieldB and I need to remove the first part of fieldB up to the v...
by tomapatan Contributor in Splunk Search 09-27-2022
0 3
0
3
ninja_panda
I want to create a Bar chart with the logs where the key would be the stats count field name and value would be the s...
by ninja_panda Engager in Splunk Search 09-27-2022
0 4
0
4
angadbagga
Here is my query. In final line chart when I hover, I am not getting different dates.  Rather only 26th Sept (Today's...
by angadbagga Explorer in Splunk Search 09-27-2022
0 9
0
9
asafd
Hi, I have multiple panels that need to run timecharts like these: something | table _time,A,B&lt;/query&gt; | search A&#61;"1"...
by asafd Explorer in Splunk Search 09-27-2022
0 1
0
1
anooshac
Hi all,I am calculating a value from data and i want to plot it in a timechart. | where status!&#61;"ABORTED" | streamsta...
by anooshac Communicator in Splunk Search 09-27-2022
0 7
0
7
dmoberg
I have a need to compare the average time for certain events with the 5 min bucket/bins of the same events. The idea ...
by dmoberg Path Finder in Splunk Search 09-27-2022
0 4
0
4
zacksoft_wf
How do I know if a TA is used by any user.I have a TA laying around, and I doubt is is been used. But before removing...
by zacksoft_wf Contributor in Splunk Search 09-27-2022
0 4
0
4
yuanliu
I'm trying to use the Splunk 9 addition in foreach iteration with ITEM, but it always returns "Failed to parse templa...
by SplunkTrust SplunkTrust in Splunk Search 09-26-2022
0 3
0
3
klischatb
Hello everyone!i have the following search:     index&#61;"xyz" "restart" | eval _time &#61; strftime(_time,"%F %H:%M:%S") | ...
by klischatb Path Finder in Splunk Search 09-26-2022
0 4
0
4
bapun18
I am running a query |tstats count latest(_time) where index&#61;abcd by host, my requirement is to create an alert when ...
by bapun18 Communicator in Splunk Search 09-26-2022
0 4
0
4
fpedrosa
Hi,I have this search:| stats count by application | eval application &#61; case( application&#61;&#61;"malware-detection",...
by fpedrosa Engager in Splunk Search 09-26-2022
0 1
0
1
KyleMcDougall
Hi all, I'm trying to get a list of phone numbers for each event by sessionId. I can't quite figure it out. I think I...
by KyleMcDougall Path Finder in Splunk Search 09-26-2022
0 3
0
3
vrmandadi
I am using the below search to first get the difference in time everytime I see an event which has boot timestamp in ...
by vrmandadi Builder in Splunk Search 09-26-2022
0 10
0
10
Julia1231
Hi everyone, I am searching data in Splunk, after different steps, I have now this table:   _timecountTypeMon Sep 12 ...
by Julia1231 Communicator in Splunk Search 09-26-2022
0 1
0
1
Julia1231
Hi everyone, I use dbxquery and get this result from database: idcount12312456244786   Also I have a csv file already...
by Julia1231 Communicator in Splunk Search 09-26-2022
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...