Splunk Search

Splunk Search
Community Activity
raysonjoberts
I am trying to create a logic to choose a value to use from multiple fields based on a priority I can define. I have ...
by raysonjoberts Path Finder in Splunk Search 07-28-2022
0 2
0
2
loganseth
Hi. I have a classic dashboard and am using a bar chart with       | timechart span=15m count       And I can pass th...
by loganseth Path Finder in Splunk Search 07-28-2022
0 3
0
3
Laya123
Hi,I need small to fill null values in search results I have search results like ID host country1 A CC2 A CC3 B AA4 C...
by Laya123 Communicator in Splunk Search 07-28-2022
0 5
0
5
nextpart
I am trying to use a search to find fields that I want to use in another search as a table field. The first search sh...
by nextpart Explorer in Splunk Search 07-28-2022
0 3
0
3
joock3r
Hi, I have about 100 rules and I want to count the number of logs are related to each rule. When I used "stats count"...
by joock3r Explorer in Splunk Search 07-28-2022
0 3
0
3
Veeru
I have the Field with idi want to  only  3 digits  id For example:if i take t0123-123 here i want remove t0t456-456 h...
by Veeru Path Finder in Splunk Search 07-28-2022
0 2
0
2
Jason
I have a CSV with numerous fields with bad field names. They have spaces and special characters such as up and down a...
by Jason Motivator in Splunk Search 07-28-2022
0 1
0
1
BorisT
I am trying to get my query to work correctly and display it in a table format for easy analysis. The fields I am usi...
by BorisT Observer in Splunk Search 07-28-2022
0 1
0
1
djacquens
Hi, I need to add a Role Restriction Search filter on a field which is only available in one index.My problem is tha...
by djacquens Path Finder in Splunk Search 07-28-2022
0 4
0
4
testman
Hello, I am currently testing Splunk for our Cisco backbone network and I would like to filter out two scenarios. 1.)...
by testman Engager in Splunk Search 07-28-2022
0 3
0
3
sagarpatil09
I am trying to extract the _time from the log Jul 28 12:00:49 104.128.100.1 420391: Jul 28 06:30:25.023: %Sample: Sam...
by sagarpatil09 Observer in Splunk Search 07-28-2022
0 2
0
2
jobamnavarro
I want to search file by range of size assigned in the input but I'm not sure how.Example: I pick 50M in the choices ...
by jobamnavarro Loves-to-Learn Lots in Splunk Search 07-28-2022
0 7
0
7
SShalaka
Hello everyone, I want to be able to have  a dynamic timewrap option on my dashboard. Based on the user input (of spe...
by SShalaka Engager in Splunk Search 07-27-2022
0 7
0
7
msage
Looking to create a chart that can separate results into groups of how often they appear in a time range.  We're look...
by msage Path Finder in Splunk Search 07-27-2022
0 1
0
1
Cuyose
Not sure why this is so perplexing, but or the life of me I can't get this to sort how I want. The following chart...
by Cuyose Builder in Splunk Search 07-27-2022
0 4
0
4
bradw2021
Have a search that returns emails of interest (possibly malicious). Trying to add a subsearch that will return a coun...
by bradw2021 Engager in Splunk Search 07-27-2022
0 5
0
5
Surhol
I have two host. I need to compare the fields values. Field names are same for both the host.
by Surhol New Member in Splunk Search 07-27-2022
0 1
0
1
scaparelli
First, let me explain my intention:I am attempting to create a query that would notify our team of a “stuck order”.  ...
by scaparelli Explorer in Splunk Search 07-27-2022
1 7
1
7
robertlynch2020
Hi I am producing a table with time as the column header. However i can only use hour not the full date as i have to ...
by robertlynch2020 Influencer in Splunk Search 07-27-2022
0 13
0
13
Santosh2
Splunk data retention period is for 7 days. But i could still see 2 years back data now. I am not sure why?  Can anyo...
by Santosh2 Path Finder in Splunk Search 07-26-2022
0 7
0
7
Hoekb03
Hi, I've created this rather complicated piece of SPL. To make it a bit more understandable I added some comment line...
by Hoekb03 Explorer in Splunk Search 07-26-2022
1 3
1
3
SShalaka
Hello everyone,  The time modifiers don't seem seem to work for this search, am I doing something wrong?  |union [sea...
by SShalaka Engager in Splunk Search 07-26-2022
0 1
0
1
mykol_j
What happened to the date_wday, date_hour,  and the others?  Am I going nuts, waking from a dream where they used to ...
by mykol_j Communicator in Splunk Search 07-26-2022
1 5
1
5
gn694
I am searching a new source of json data sent to Splunk (over HEC), and it is very, very slow. Searching over just th...
by gn694 Communicator in Splunk Search 07-26-2022
0 4
0
4
ERFFFFF
Hello everyone !I'm trying to split a single multivalue event into multiple multivalue events. Here is my base search...
by ERFFFFF Explorer in Splunk Search 07-26-2022
0 4
0
4
Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...
Top Solution Authors