Splunk Search

Splunk Search
Community Activity
ravir_jbp
Currently I am trying to extract the crossReferenceId value using below rex query.  Its working fine and I can extrac...
by ravir_jbp Explorer in Splunk Search 09-22-2022
0 3
0
3
Basavaraj
A notable event triggered 30000 notables how can i delete them all?
by Basavaraj Engager in Splunk Search 09-22-2022
0 3
0
3
Abhineet
Want to create search to get info from lookup file if event field contains data from two field in lookup file. log ev...
by Abhineet Loves-to-Learn Everything in Splunk Search 09-22-2022
0 3
0
3
Ange
Hi, everyone.Need some help for detection exclusion setting. Want to exclude detections of  the files which are appli...
by Ange Explorer in Splunk Search 09-22-2022
0 5
0
5
siriosus
Hello dear Splunk experts!I've stuck with one search and can't figure how to do this. Did a lot of searching here on ...
by siriosus Engager in Splunk Search 09-21-2022
0 3
0
3
kc_prane
Hello  - I am getting the below error. I am trying to add pipe "|"  for all the results.  Error : Failed to parse tem...
by kc_prane Communicator in Splunk Search 09-21-2022
0 3
0
3
hartfoml
Here is my search: source="WinEventLog:Security" EventCode=540 | timechart span=1h count by User This gives me the co...
by hartfoml Motivator in Splunk Search 09-21-2022
2 13
2
13
NickGrava
Hi Team! Someone please explain to me what each parameter is responsible for in such a search tag: <search><query>sys...
by NickGrava Engager in Splunk Search 09-21-2022
0 2
0
2
alexspunkshell
I want to exclude duration results if greater than 7 days. So i used search NOT but it is not working. Can someone he...
by alexspunkshell Contributor in Splunk Search 09-21-2022
0 1
0
1
charming_fish
I have a query which results in a table: "some words" | stats dc(host) as host_count by zone, region My end goal is...
by charming_fish New Member in Splunk Search 09-21-2022
0 1
0
1
Anud
HI Team,I am getting 2 hr time span only if i mentioned the 1 or 3 or 4 hours span too in the visualization line char...
by Anud Path Finder in Splunk Search 09-21-2022
0 1
0
1
KyleMcDougall
Hi all, I'm trying to create a "Fallback escalation rate" for a chatbot. This rate would be calculated by users that ...
by KyleMcDougall Path Finder in Splunk Search 09-21-2022
0 7
0
7
PTIch
Hi All, I have a large number of Windows logs in directory. How can I automatically delete them from the disk space a...
by PTIch Engager in Splunk Search 09-21-2022
0 2
0
2
Neonbeeflash3
Greetings,I have been creating a search that collects all the sourcetypes that have not collected any information dur...
by Neonbeeflash3 New Member in Splunk Search 09-21-2022
0 3
0
3
dzyfer
Hi, I would like display values of variables from an event as a Table.  My data format is as follow: TimeEvent9/16/22...
by dzyfer Path Finder in Splunk Search 09-21-2022
0 6
0
6
baljkastr
On my attached picture these many events should become one event by ID instead of so many, how can I break those even...
by baljkastr Engager in Splunk Search 09-20-2022
0 1
0
1
eitangabay
  I want to create subsearch based on parent fields search. I want to show only rows from cor_inbox_entry that in...
by eitangabay New Member in Splunk Search 09-20-2022
0 2
0
2
pkumar9610
Hello Team,  I am running below query to get the stats but I am looking to get the Store numbers in serial order, can...
by pkumar9610 Explorer in Splunk Search 09-20-2022
0 2
0
2
olawalePS
Hello All,I am relatively new to splunk and I am trying to search using sets. Sets here refers to a group of values t...
by olawalePS Path Finder in Splunk Search 09-20-2022
0 3
0
3
cfloquet
Hello,  I'm working on creating automated alerts from an email security vendor and would like for them to only includ...
by cfloquet Path Finder in Splunk Search 09-20-2022
0 2
0
2
wanda619
Hi Folks,How can i display the results for 2022-09-02 in Result_Prev column and 2022-09-09 in Result column and keepi...
by wanda619 Path Finder in Splunk Search 09-20-2022
0 6
0
6
youngso
What's a good way to find user who logon to RDP with one user account then user another like privilege user account. ...
by SplunkTrust SplunkTrust in Splunk Search 09-20-2022
1 1
1
1
aprice_q
Hi, We are using both Splunk Cloud and Splunk Enterprise. We recently came across some issues/differences in search w...
by aprice_q Observer in Splunk Search 09-20-2022
0 2
0
2
kgiri253
I want to access an API and I can only use Bearer authentication to access that particular API. I searched a lot abou...
by kgiri253 Explorer in Splunk Search 09-20-2022
0 1
0
1
zsbbb
I have a splunk container running on docker, and was hoping to translate the splunk index data into json using a cli ...
by zsbbb Engager in Splunk Search 09-20-2022
0 1
0
1
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...