Splunk Search

Splunk Search
Community Activity
cmuesing
I am getting an integrity check error on /opt/splunk/bin/python2.7 that says present_but_shouldnt_be. I can find the ...
by cmuesing Explorer in Splunk Search 01-22-2025
0 8
0
8
Karthikeya
Hello,We have a field called client_ip which contains different IP addresses and in events different threat messages ...
by Karthikeya Communicator in Splunk Search 01-21-2025
0 6
0
6
SN1
i want to know in which index is microsoft defender logs getting stored , I know some important fields which are ther...
by SN1 Path Finder in Splunk Search 01-21-2025
0 2
0
2
poojak2579
Is there any way to search for similar strings dynamically in different  logs?I want to group unique error string com...
by poojak2579 Path Finder in Splunk Search 01-21-2025
0 13
0
13
JyPl4wNYu7GV1uL
Stupid form editor adds extra CRs.Having trouble getting this search to work as desired. I've tried these 2 methods a...
by JyPl4wNYu7GV1uL Explorer in Splunk Search 01-21-2025
0 2
0
2
Amit79
I need help with below splunk query   index=XXX_XXX_XXX | eval job_status=if( 'MSGTXT' = "*ABEND*","ko","ok") | where...
by Amit79 Loves-to-Learn Everything in Splunk Search 01-21-2025
0 1
0
1
Rajaion
Hello community,I am having a problem displaying a graph. I have an index that contains incidents from several monito...
by Rajaion Path Finder in Splunk Search 01-21-2025
0 3
0
3
LizAndy123
So I have an Index which contains the following"Starting iteration"on 1 event and "Stopping iteration" on another eve...
by LizAndy123 Path Finder in Splunk Search 01-21-2025
0 7
0
7
Obsidian_RS400
I have a lookup table with a bunch of IP addresses (ipaddress.csv) and a blank column called hostname. I would like t...
by Obsidian_RS400 New Member in Splunk Search 01-21-2025
0 1
0
1
woodman2
I have such a search and it works fine but not in Dashboard!    index=unis | search *sarch* | eval name = coalesce(C_...
by woodman2 Loves-to-Learn Everything in Splunk Search 01-21-2025
0 5
0
5
josephp
Hi, We recently migrated from a standalone Search Head to a clustered one. However, we are having some issue running ...
by josephp Loves-to-Learn Everything in Splunk Search 01-21-2025
0 3
0
3
deckard1984
Right now a have a table list with fields populated where one process_name is repeating across multiples hosts with s...
by deckard1984 Engager in Splunk Search 01-21-2025
0 3
0
3
bryhoffman
When I click on the raw log and back out of it it shows up as highlighted. How do I default the sourcetype/source to ...
by bryhoffman Explorer in Splunk Search 01-21-2025
0 4
0
4
splunkinator53
Hey,  lately i was working on an SPL and wondered why this aint working. This is simplified  index IN(anonymized_inde...
by splunkinator53 Explorer in Splunk Search 01-20-2025
0 4
0
4
jmartens
I have the following regex that I (currently) use at search time (it will be a field extraction once I get it ironed ...
by jmartens Path Finder in Splunk Search 01-20-2025
0 3
0
3
anmohan0
I want to get the below search executed and display the results in a table for all comma separated values that gets p...
by anmohan0 Explorer in Splunk Search 01-19-2025
0 3
0
3
patpro
Hello,I’m trying to tune Machine Learning Toolkit in order to detect authentication abuse on a web portal (based upon...
by patpro Path Finder in Splunk Search 01-19-2025
0 0
0
0
danielbb
We have a case where we can search and find events that match the search criteria. The client would like to see the e...
by danielbb Motivator in Splunk Search 01-19-2025
0 3
0
3
Afterimage
We have a custom dashboard in Splunk that has a few filters, one of which is a multiselect. This dashboard allows use...
by Afterimage Engager in Splunk Search 01-17-2025
0 3
0
3
tech_soul
Hi All, Could you please help me with " if "query to search a condition is true then need to display some values f...
by tech_soul New Member in Splunk Search 01-16-2025
0 4
0
4
esteban593
Hi,I'm trying to get a query for a table containing all the indexes that do not have a self storage attached, but I c...
by esteban593 Explorer in Splunk Search 01-16-2025
0 4
0
4
avoelk
I'm trying to create a search in which the following should be done:  - look for a user creation process (ID 4720) - ...
by avoelk Communicator in Splunk Search 01-16-2025
0 3
0
3
LIS
I am wondering why tstats command alters time stamps when I run it by _time. | tstats values(text_len) as text_len  v...
by LIS Path Finder in Splunk Search 01-16-2025
0 8
0
8
nonno_pinto
Hi everyone!My goal is to create an alert to monitor in ALL saved search if there's any email that no longer exist (m...
by nonno_pinto Explorer in Splunk Search 01-16-2025
0 1
0
1
Graham_Hanningt
I want the sort indicators (up/down arrowheads) in table visualization column headings to reflect the default sort or...
by Graham_Hanningt Builder in Splunk Search 01-16-2025
0 7
0
7
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors