Splunk Search

Splunk Search
Community Activity
jialiu907
I am looking to extract this section of an event and have it as a field that I am able to manipulate with. I am unfam...
by jialiu907 Path Finder in Splunk Search 02-19-2025
0 4
0
4
phant0m
Hello all, new poster here. I have a csv file with a column full of Splunk queries. I am trying to enrich my Splunk i...
by phant0m Observer in Splunk Search 02-19-2025
0 2
0
2
splunklearner
Please help me in extracting only compression values from this raw event - "response_time_last_byte":5,"compression_p...
by splunklearner Communicator in Splunk Search 02-18-2025
0 1
0
1
rbhatta99
Hello,I have this search query   index=app iNumber IN (72061271737983, 72061271737983, 72061274477906, 7206127721516...
by rbhatta99 Engager in Splunk Search 02-18-2025
0 1
0
1
mbasharat
Hi. I have below raw event/s.Highlighted Syntax:{ [-]   body: {"isolation": "isolation","device_classification": "Net...
by mbasharat Builder in Splunk Search 02-18-2025
0 2
0
2
benUnicoSplunk
I am trying to remove specific strings and their values from Splunk events at index time as they are not needed in th...
by benUnicoSplunk New Member in Splunk Search 02-18-2025
0 7
0
7
tdavison76
Hello,Thanks in advance for any help and Karma will be on the way :).So I'm trying to create a Table that uses a "Sum...
by tdavison76 Path Finder in Splunk Search 02-18-2025
0 6
0
6
pedropiin
Hi everyone.I'm really new to Splunk, so I'm confused with what seems to be a simple problem. I'm using "where row_nu...
by pedropiin Path Finder in Splunk Search 02-18-2025
0 2
0
2
pedropiin
Hi everyoneI just started working with Splunk and I have a query in which one of the steps is to count the number of ...
by pedropiin Path Finder in Splunk Search 02-17-2025
0 5
0
5
tdavison76
Hello,I really appreciate any help on this one, I can't figure it out.  I am using the following to show only the "Cr...
by tdavison76 Path Finder in Splunk Search 02-17-2025
0 10
0
10
smoir_splunk
I am able to graph the duration calculation while it is in seconds, but I want to display the human-readable string v...
by smoir_splunk Splunk Employee Splunk Employee in Splunk Search 02-17-2025
0 7
0
7
rrovers
I made a savedsearch with a simple search in it. As a condition I selected "if number of events""is greater than"with...
by rrovers Contributor in Splunk Search 02-16-2025
0 2
0
2
ravikumar_sri20
Hi Experts,The file ACF2DS_Data.csv contains columns including TIMESTAMP, DS_NAME, and JOBNAME.I need to match the DS...
by ravikumar_sri20 Engager in Splunk Search 02-16-2025
0 6
0
6
dtaylor
I've been smashing my head against this issue for the past few hours. I need to check a multivalue field to see if it...
by dtaylor Path Finder in Splunk Search 02-16-2025
0 7
0
7
MichalG1
Hello Team,9.4.0, thsooting prod, replicated the issue in staging, i have 1 indexer only. Performing all searches on ...
by MichalG1 Path Finder in Splunk Search 02-16-2025
0 1
0
1
silversides
Trying to build a search that will leverage ldapsearch to pull a current list of users that are members of a specific...
by silversides Loves-to-Learn in Splunk Search 02-15-2025
0 7
0
7
pedropiin
Hi everyone.I have a query that calculates a number of metrics, such as average, max value, etc, for a specific date,...
by pedropiin Path Finder in Splunk Search 02-15-2025
0 4
0
4
pedropiin
Hi everyone.I'm doing a query in which I sort it by time according to a variable and then calculate some metrics over...
by pedropiin Path Finder in Splunk Search 02-14-2025
0 1
0
1
eandres
Running a lookup where I have verified the fields exist and match and its not returning an output field. So, I verifi...
by eandres Explorer in Splunk Search 02-13-2025
0 3
0
3
Roy_9
Hello,I have the below SPL where I am looking to fetch the user accounts that have not logged in for 30 days or more ...
by Roy_9 Motivator in Splunk Search 02-13-2025
0 3
0
3
davidaj
HelloI'm looking to modify this search I've found and using. I like the result set but would like to limit the host c...
by davidaj Explorer in Splunk Search 02-13-2025
0 4
0
4
harishsplunk7
I am want to get the list of dashboard which is not used by anyone for more than 90 days. i have tired to use the bel...
by harishsplunk7 Explorer in Splunk Search 02-13-2025
0 3
0
3
splunkermack
What is the definition of large? Is it measured in total bytes? Number of records? And in either case how much?
by splunkermack New Member in Splunk Search 02-12-2025
0 2
0
2
tungpx
Hello, I need help with a search query, that at first seem easy but suprising difficult to execute. I have a money tr...
by tungpx Explorer in Splunk Search 02-12-2025
0 6
0
6
DavidGuarneri
How much syntax has changed from splunklib (which ran on Python 2.x) to splunk-sdk (which runs on Python 3.x)? Just s...
by DavidGuarneri Path Finder in Splunk Search 02-12-2025
0 1
0
1
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...