Splunk Search

Splunk Search
Community Activity
jobamnavarro
I want to search file by range of size assigned in the input but I'm not sure how.Example: I pick 50M in the choices ...
by jobamnavarro Loves-to-Learn Lots in Splunk Search 07-28-2022
0 7
0
7
SShalaka
Hello everyone, I want to be able to have  a dynamic timewrap option on my dashboard. Based on the user input (of spe...
by SShalaka Engager in Splunk Search 07-27-2022
0 7
0
7
msage
Looking to create a chart that can separate results into groups of how often they appear in a time range.  We're look...
by msage Path Finder in Splunk Search 07-27-2022
0 1
0
1
Cuyose
Not sure why this is so perplexing, but or the life of me I can't get this to sort how I want. The following chart...
by Cuyose Builder in Splunk Search 07-27-2022
0 4
0
4
bradw2021
Have a search that returns emails of interest (possibly malicious). Trying to add a subsearch that will return a coun...
by bradw2021 Engager in Splunk Search 07-27-2022
0 5
0
5
Surhol
I have two host. I need to compare the fields values. Field names are same for both the host.
by Surhol New Member in Splunk Search 07-27-2022
0 1
0
1
scaparelli
First, let me explain my intention:I am attempting to create a query that would notify our team of a “stuck order”.  ...
by scaparelli Explorer in Splunk Search 07-27-2022
1 7
1
7
robertlynch2020
Hi I am producing a table with time as the column header. However i can only use hour not the full date as i have to ...
by robertlynch2020 Influencer in Splunk Search 07-27-2022
0 13
0
13
Santosh2
Splunk data retention period is for 7 days. But i could still see 2 years back data now. I am not sure why?  Can anyo...
by Santosh2 Path Finder in Splunk Search 07-26-2022
0 7
0
7
Hoekb03
Hi, I've created this rather complicated piece of SPL. To make it a bit more understandable I added some comment line...
by Hoekb03 Explorer in Splunk Search 07-26-2022
1 3
1
3
SShalaka
Hello everyone,  The time modifiers don't seem seem to work for this search, am I doing something wrong?  |union [sea...
by SShalaka Engager in Splunk Search 07-26-2022
0 1
0
1
mykol_j
What happened to the date_wday, date_hour,  and the others?  Am I going nuts, waking from a dream where they used to ...
by mykol_j Communicator in Splunk Search 07-26-2022
1 5
1
5
gn694
I am searching a new source of json data sent to Splunk (over HEC), and it is very, very slow. Searching over just th...
by gn694 Communicator in Splunk Search 07-26-2022
0 4
0
4
ERFFFFF
Hello everyone !I'm trying to split a single multivalue event into multiple multivalue events. Here is my base search...
by ERFFFFF Explorer in Splunk Search 07-26-2022
0 4
0
4
din98
Hey all,I have a summary table that shows these values. Each error log and log in the 'Total logs' column (which cont...
by din98 Explorer in Splunk Search 07-26-2022
0 5
0
5
nowakgft
Hello everyone, I have following type of data to analyze: timestampendpointexecutionTime08:12/products0.308:20/produc...
by nowakgft Engager in Splunk Search 07-26-2022
0 2
0
2
Bleepie
Hello Splunk Community, I have the following search command:   index="myIndex" host="myHost" myScript Running OR Sto...
by Bleepie Communicator in Splunk Search 07-26-2022
0 4
0
4
hichem_khalfi
  Good morning allplease i'm in a big das that i can't solve it: i'm a student and i'm preparing my graduation projec...
by hichem_khalfi Path Finder in Splunk Search 07-26-2022
0 11
0
11
DanAlexander
Hello All, I would like to be able to track down any and every configuration change on our monitored DC, AD etc. I ne...
by DanAlexander Communicator in Splunk Search 07-26-2022
0 6
0
6
Vikasreddys
Hi Everyone,I need to migrate the report from sumo logic to splunk . In sumo logic report we have time compare option...
by Vikasreddys Engager in Splunk Search 07-25-2022
0 1
0
1
likejudo
I only want to know for field methodName=XYZAll the methodNames that occurred. I do not want the timestamps for each ...
by likejudo Loves-to-Learn in Splunk Search 07-25-2022
0 6
0
6
scottrudy
I have a very large Oracle database table that is being used as a log sink for an application. There is high transact...
by scottrudy Engager in Splunk Search 07-25-2022
0 1
0
1
JohnnyTsunami
rex command im using:  (?:\w+\s\:\s)(?<command>[^\;]+)?\;\s(?<Datainput>[^\s]+)\s\;\s(?<Extra>[^\s]+) Data 1) command...
by JohnnyTsunami New Member in Splunk Search 07-25-2022
0 1
0
1
GersonGarcia
Hello, I am trying to create dashboard input based on lookup table. I have simple lookup with monitor name and list o...
by GersonGarcia Path Finder in Splunk Search 07-25-2022
0 5
0
5
rbal_splunk
Is there any controls to limit the size of a user search? The use case is Splunk Cloud and limiting a search, if it d...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 07-25-2022
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...