Splunk Search

Splunk Search
Community Activity
stepheneardley
We're summary indexing events from one index into another.  The original index contains JSON events e.g.{"field1": "v...
by stepheneardley Path Finder in Splunk Search 08-15-2022
0 1
0
1
rockzers
i created a custom python api script and it works fine and i want to import in splunk so i put my script. "C:\\Progra...
by rockzers Path Finder in Splunk Search 08-15-2022
0 3
0
3
Mick_OBrien
I have raw message of the form... 2022-08-15T10:41:54.266337+00:00 microService 9bc7520a-4f8d-4edc-a4cd-b08c0fae8992[...
by Mick_OBrien Path Finder in Splunk Search 08-15-2022
0 4
0
4
mehmetarpa
We are getting the error below for all indexes, but there is no detail in all search. Rawdata journal is missing in t...
by mehmetarpa Observer in Splunk Search 08-14-2022
0 0
0
0
rockzers
new splunk useri installed my splunk on my windows machine and i want to receive logs and how to find a logon event?i...
by rockzers Path Finder in Splunk Search 08-14-2022
0 9
0
9
Cs80
Hi there, I am new to splunk and  struggling to join two searches based on conditions .eg. left join  with field 1 fr...
by Cs80 Loves-to-Learn Lots in Splunk Search 08-13-2022
0 4
0
4
scaparelli
For some reason there are entries that are not grouped together, but obviously look like they should be. In the follo...
by scaparelli Explorer in Splunk Search 08-13-2022
1 2
1
2
SplunkDash
Hello, I have done field extraction for the nested JSON event using props.conf file.  Everything is working as expect...
by SplunkDash Motivator in Splunk Search 08-12-2022
0 3
0
3
akarivaratharaj
I am using the below search query which contains multiple fields. All the fields (DATA_MB, INDEX_MB, DB2_INDEX_MB, et...
by akarivaratharaj Communicator in Splunk Search 08-12-2022
0 14
0
14
vgiri8
Latest data within a time span. I have a query as below, but I would like to get the latest data for a field within s...
by vgiri8 Path Finder in Splunk Search 08-12-2022
0 14
0
14
mananzeh
how can solve this ::: (Create a new field called "StartTime" and set the value to seven days ago from today, snapped...
by mananzeh New Member in Splunk Search 08-12-2022
0 2
0
2
NicolásMilans
Hello, i need to de  delete some old logs on my cloud instance because i run out of space    is there any way to rem...
by NicolásMilans Explorer in Splunk Search 08-12-2022
0 4
0
4
HarperWCurran
I am new to splunk and still wokring out the kinks however im wondering as to why i have the iplocation of clients an...
by HarperWCurran Engager in Splunk Search 08-12-2022
0 2
0
2
jmohan1984
I have created Splunk query with time modifiers "earliest" and "latest" ( for eg. earliest="15/01/2022 8 am" latest="...
by jmohan1984 New Member in Splunk Search 08-12-2022
0 1
0
1
tankhanandita
Hi, I have a log file in which I have two things functionality and different repositories which use this functionalit...
by tankhanandita Explorer in Splunk Search 08-12-2022
0 2
0
2
msg4sunil
Hello All, I have data like below.  How do I extract the field names like prefix:field1, prefix:field2, prefix:field3...
by msg4sunil Path Finder in Splunk Search 08-11-2022
0 9
0
9
labaningombam
Hi, I have a bunch of failure events of different api endpoints. The field is called RequestPath and some examples ar...
by labaningombam Explorer in Splunk Search 08-11-2022
0 7
0
7
alexspunkshell
How to remove duplicate values in a different field |stats count by src dest  
by alexspunkshell Contributor in Splunk Search 08-11-2022
0 5
0
5
karlpena
Hello Team,   Trying to exclude NULL fields from results to avoid gaps in table.  Currently using this query:<my base...
by karlpena Loves-to-Learn in Splunk Search 08-11-2022
0 1
0
1
ahartge
I have searched answers high & low to try and extract the timestamp from my filename at index-time, but I'm still una...
by ahartge Path Finder in Splunk Search 08-11-2022
2 18
2
18
uchoavaz
Hello! I am trying to use makeresults + eval inside a sendalert parameters, but it doesn't return what i need. Follow...
by uchoavaz Explorer in Splunk Search 08-11-2022
0 1
0
1
bmohammadi
Dear Community, I am new to Splunk so apologies for the newbie question: Basic Problem I have a field which holds an ...
by bmohammadi Explorer in Splunk Search 08-11-2022
0 2
0
2
SK_
Hello Community,We have 2 target groups to route events.(2 indexers, one is ours and other 3rd party)i want to config...
by SK_ New Member in Splunk Search 08-11-2022
0 0
0
0
hakusama1024
Hi Thanks for your time. Im using splunk to parse the log. I have two search. the columns i got from A is as below...
by hakusama1024 New Member in Splunk Search 08-11-2022
0 7
0
7
shariz
I am trying to download vulnerability report for a 1000 hosts. Instead of providing them in the splunk query. I thoug...
by shariz New Member in Splunk Search 08-11-2022
0 1
0
1
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...