Splunk Search

Splunk Search
Community Activity
maheswari
we are using ocp-4.10 deploying splunk/splunk:7.2.2 image but pod is going into crashbakloopoff state and in logs we ...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
maheswari
we are doing splunk integartion with ocp-4.10 so need to install splunk but After installation of splunk getting erro...
by maheswari New Member in Splunk Search 09-23-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the average response times for the below data using tstats command. Need he...
by dsenapaty Explorer in Splunk Search 09-23-2022
0 5
0
5
kranthimutyala
Hi Team,I have a field which has the values in the below string format:  HH:MM:SS.3N 0:00:43.096 22:09:50.174 1:59:54...
by kranthimutyala Path Finder in Splunk Search 09-23-2022
0 3
0
3
linspec9721
Hello folks, we have some linux machines with UF installed on that connect to our search head. We haven't access to t...
by linspec9721 Explorer in Splunk Search 09-23-2022
0 2
0
2
Altoid17
Hi, I am looking to grab a hand at turning 8 product charts into one table with Sparkline's if possible for trend tra...
by Altoid17 Explorer in Splunk Search 09-22-2022
0 0
0
0
dsenapaty
Hello All, I need help trying to generate the P95,P99,P75, mean and median response times for the below data using ts...
by dsenapaty Explorer in Splunk Search 09-22-2022
0 1
0
1
pwilson
I want no results of a search to display until the search has completed. The search I am running displays any users w...
by pwilson Explorer in Splunk Search 09-22-2022
0 3
0
3
sarit_s
Hello I have a query that running a rest command, one of the fields is "action.email.to"also i have a lookup table wi...
by sarit_s Communicator in Splunk Search 09-22-2022
0 7
0
7
yshen
I see an interesting Simple XML idiom below:<input type="multiselect" token="multiselect_lines" searchWhenChanged="tr...
by yshen Communicator in Splunk Search 09-22-2022
0 0
0
0
timgren
I'm looking for a way to set a token when the column exists (regardless of value).  Tried these with no luck.  <eval ...
by timgren Path Finder in Splunk Search 09-22-2022
0 3
0
3
thenormalone
I have a dropdown whose value once input needs to be used in two different ways in the same search query. One of the ...
by thenormalone Path Finder in Splunk Search 09-22-2022
0 4
0
4
Jeet
My rex search is returning all the rows instead of the one being searched. What am I doing wrong? index=cloudwatchlog...
by Jeet Explorer in Splunk Search 09-22-2022
0 3
0
3
shashank_24
Hi, I have a scenario where I receive multiple requests which contain same field value basically OrderNumber. So the ...
by shashank_24 Path Finder in Splunk Search 09-22-2022
0 1
0
1
ravir_jbp
Currently I am trying to extract the crossReferenceId value using below rex query.  Its working fine and I can extrac...
by ravir_jbp Explorer in Splunk Search 09-22-2022
0 3
0
3
Basavaraj
A notable event triggered 30000 notables how can i delete them all?
by Basavaraj Engager in Splunk Search 09-22-2022
0 3
0
3
Abhineet
Want to create search to get info from lookup file if event field contains data from two field in lookup file. log ev...
by Abhineet Loves-to-Learn Everything in Splunk Search 09-22-2022
0 3
0
3
Ange
Hi, everyone.Need some help for detection exclusion setting. Want to exclude detections of  the files which are appli...
by Ange Explorer in Splunk Search 09-22-2022
0 5
0
5
siriosus
Hello dear Splunk experts!I've stuck with one search and can't figure how to do this. Did a lot of searching here on ...
by siriosus Engager in Splunk Search 09-21-2022
0 3
0
3
kc_prane
Hello  - I am getting the below error. I am trying to add pipe "|"  for all the results.  Error : Failed to parse tem...
by kc_prane Communicator in Splunk Search 09-21-2022
0 3
0
3
hartfoml
Here is my search: source="WinEventLog:Security" EventCode=540 | timechart span=1h count by User This gives me the co...
by hartfoml Motivator in Splunk Search 09-21-2022
2 13
2
13
NickGrava
Hi Team! Someone please explain to me what each parameter is responsible for in such a search tag: <search><query>sys...
by NickGrava Engager in Splunk Search 09-21-2022
0 2
0
2
alexspunkshell
I want to exclude duration results if greater than 7 days. So i used search NOT but it is not working. Can someone he...
by alexspunkshell Contributor in Splunk Search 09-21-2022
0 1
0
1
charming_fish
I have a query which results in a table: "some words" | stats dc(host) as host_count by zone, region My end goal is...
by charming_fish New Member in Splunk Search 09-21-2022
0 1
0
1
Anud
HI Team,I am getting 2 hr time span only if i mentioned the 1 or 3 or 4 hours span too in the visualization line char...
by Anud Path Finder in Splunk Search 09-21-2022
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...