Splunk Search

Splunk Search
Community Activity
RJDev
Hi, I am new to Splunk. I just started using it last month. For me the below " | eval error=substr(msg, 0, 1000) |  t...
by RJDev Loves-to-Learn in Splunk Search 06-27-2022
0 8
0
8
zacksoft_wf
I am investigating a customer's concern that this  particular search is not writing summary to 'stash' sourcetype. Th...
by zacksoft_wf Contributor in Splunk Search 06-27-2022
0 3
0
3
glpadilla_sol
Hello everyone, I have an issue with one field let say foo These are the scenarios: 1. If I run a search just with t...
by glpadilla_sol Path Finder in Splunk Search 06-27-2022
0 9
0
9
kackerman7
Hi, I have fields from a JSON file that are getting parsed like this:  I'm struggling to find a way to turn those fi...
by kackerman7 Loves-to-Learn in Splunk Search 06-27-2022
0 4
0
4
bosseres
Hello, team! I need your help with my search.  I have a search which collects the list of ip-addresses, and next I ne...
by bosseres Contributor in Splunk Search 06-27-2022
0 2
0
2
vprunera
Hi, I'm trying to remove blanks in a field when adding a csv file.  In heavy-forwarder I have tried to use a regex in...
by vprunera New Member in Splunk Search 06-27-2022
0 1
0
1
sbsinha04
This is the log i am getting in splunk msg: 2022-01-22 03:00:00.143 INFO 15 --- [ scheduling-1PurgeProcessCountTask :...
by sbsinha04 New Member in Splunk Search 06-27-2022
0 4
0
4
_gkollias
Hi All, I might be over thinking this one, but since I've already used _time--> ...| stats earliest(_time) as first_...
by _gkollias Builder in Splunk Search 06-27-2022
0 7
0
7
resparis
Hi I have created a custom Event type and I would like to perform some field extraction based on the new event type, ...
by resparis New Member in Splunk Search 06-27-2022
0 3
0
3
SplunkDash
Hello,I extracted a few numbers of fields through SPLUNK web interface (see below) using REGEX/REX (see below), all f...
by SplunkDash Motivator in Splunk Search 06-27-2022
0 7
0
7
splunkfriend123
Hi Team,We had couple of dashboards who created by ex-employees and existing team is unable to access them.Even we do...
by splunkfriend123 Engager in Splunk Search 06-26-2022
0 4
0
4
spencerneal
Hello,   I am trying to get a list of values using max_match=5.  However I need the results to only return unique val...
by spencerneal Explorer in Splunk Search 06-26-2022
0 3
0
3
john_dem8
Does anybody know why while I am able to get results when running query with any field in Splunk, I am  getting empty...
by john_dem8 Observer in Splunk Search 06-26-2022
0 8
0
8
SplunkDash
Hello,I have some issues with field extractions and getting error messages. Sample data, extraction codes (REGEX), an...
by SplunkDash Motivator in Splunk Search 06-26-2022
0 3
0
3
Bob2k
Hi all, day1 splunker here.  I'd like to use an ingested start and stop time in index BLUE and use it to range-filter...
by Bob2k New Member in Splunk Search 06-26-2022
0 2
0
2
paritoshs24
Hi  All, I have this data in index 1 inputactive IdleadgbehcfiI have this  data in index 2 inputTESTpwrad1be2cf3ag4bh...
by paritoshs24 Path Finder in Splunk Search 06-26-2022
0 4
0
4
ut89shukla
i need to combine the country count on daily bases  If i am using count  If i am using time series  in time series ...
by ut89shukla New Member in Splunk Search 06-25-2022
0 1
0
1
akotwale
Hi Users, I have to create a gauge component to show the available memory in the system. As we know the gauge compone...
by akotwale Engager in Splunk Search 06-25-2022
0 2
0
2
indeed_2000
Hi how can I find events that contain non english words? e.g i have log file that some lines contain germany or arabi...
by indeed_2000 Motivator in Splunk Search 06-25-2022
0 11
0
11
splunkfriend123
Hi Team, Is there any way to use REST syntax and retrieve the following.1. Rest Query to retrieve all unique searches...
by splunkfriend123 Engager in Splunk Search 06-25-2022
0 4
0
4
navb
Hello,I have logs in two index, Index=flow_logFields required,src_ip, src_port, dest_ip, dest_port, network interface...
by navb Loves-to-Learn in Splunk Search 06-24-2022
0 5
0
5
kml_uvce
How can we find out volume of logs queried in Splunk
by kml_uvce Builder in Splunk Search 06-24-2022
0 3
0
3
jason0
Hello, I am digging through my _audit index to see what searches people are running over time, but I am confused by t...
by jason0 Path Finder in Splunk Search 06-24-2022
0 3
0
3
JacobWrdz
Hello, I couldn't find sufficient solution at documentation nor community. I have to setup timechart, where span=1w, ...
by JacobWrdz Explorer in Splunk Search 06-24-2022
0 2
0
2
zacksoft_wf
I have doubts that this Saved Search may not be properly engineered  and very taxing in terms of how time range is sp...
by zacksoft_wf Contributor in Splunk Search 06-24-2022
0 4
0
4
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...