Splunk Search

Splunk Search
Community Activity
karina25
Hello All, I have a problem with my search. The following search works:   index=test_index sourcetype=test_sourcetype...
by karina25 Engager in Splunk Search 07-04-2022
0 2
0
2
324981
Hi, I am new in Splunk,  if I want to remove the display of all column field for T9_LotID_LaneA,T9_LotID_LaneB,T9_Lot...
by 324981 Explorer in Splunk Search 07-03-2022
0 5
0
5
Mrig342
Hi All, I have two set of logs in two different sources in splunk, one containing the predefined list of VPNs and Que...
by Mrig342 Contributor in Splunk Search 07-02-2022
0 3
0
3
tdismukes
I have two indexed fields, FieldX and FieldY. I want to search for all instances of FieldX that contain 'ABC' where F...
by tdismukes Engager in Splunk Search 07-02-2022
2 7
2
7
nlxtasy69
I have an index: an_index , there's a field with URLs - URL/folder/folder   I only want to list the records that cont...
by nlxtasy69 Engager in Splunk Search 07-02-2022
0 4
0
4
zhenqi
Hi,I want to extract judgments to a fields from "37.0.10.15" and "47.105.153.104",Is there any way it can do that?{"d...
by zhenqi Explorer in Splunk Search 07-02-2022
0 4
0
4
SplunkAdmin69
In going through the SplunkCloud SPL tutorial, we are told to upload California drought data into Splunk, and we crea...
by SplunkAdmin69 Engager in Splunk Search 07-01-2022
0 5
0
5
perryd
Hi everyone, i need help to understand why i'm wrong and how to fix the problem. I've a lookup table in which is stor...
by perryd Engager in Splunk Search 07-01-2022
0 4
0
4
rpecka
I have rows in the form: IDField1Field2Field3   And I would like to create a histogram that shows the values of all t...
by rpecka Explorer in Splunk Search 07-01-2022
0 3
0
3
FBachelin
Hi everyone, I have a search on approval success rates : stats count as TOTAL,count(eval(criteria)) as APPROVED | eva...
by FBachelin Engager in Splunk Search 07-01-2022
0 3
0
3
ballen1
Command:rex mode=sed "s/\"name":\s\"[^\"]+\"/"name":"###############"/g"Regex seems to work fine in Regex101 However,...
by ballen1 Explorer in Splunk Search 07-01-2022
0 4
0
4
timo258
Hi!I have 3 multivalue fields (max. 3 values per field) and I want to expand/extract them to single values. Data look...
by timo258 Explorer in Splunk Search 07-01-2022
0 8
0
8
Italy1358
Can someone help me pull out these data points:cw.pptx;text.html;text.txtI need it to split at the ; mark but have th...
by Italy1358 Path Finder in Splunk Search 07-01-2022
0 1
0
1
phamxuantung
Hello,I have an alert that output a csv file that look like thisPersonNumber_of_loginLogin_failPerson A1 Person B62Pe...
by phamxuantung Communicator in Splunk Search 07-01-2022
0 3
0
3
james_n
Hi experts, I have a filed called names as shown below, if i search with first line of strings then search returning ...
by james_n Path Finder in Splunk Search 07-01-2022
0 4
0
4
zsaf
  I have two columns per event I am trying to use. Well call these col1 and UknownRandomColumnName (urcn for short...
by zsaf Explorer in Splunk Search 07-01-2022
0 5
0
5
lmonahan
I want to run a query where: 1. Query1 returns resultset1containing myEvent1.uid 2. Query2 returns resultset2 contain...
by lmonahan Path Finder in Splunk Search 06-30-2022
0 2
0
2
simon1524
There is something wrong with the data output by using apendcols. The data of Total_Actual is blank from 02-2022. But...
by simon1524 Explorer in Splunk Search 06-30-2022
0 2
0
2
fereze
Hi I have a table similar to this: Brand ID_EMP Nike 123 Adidas 456 Lotto 123   other table like this: code name 123 ...
by fereze Engager in Splunk Search 06-30-2022
0 1
0
1
Seawheels51
Greetings Community ExpertsI have a group of devices that each should report state to a portal every 10 seconds. If a...
by Seawheels51 Path Finder in Splunk Search 06-30-2022
0 1
0
1
dmuley
2022-06-12 21:51:42.274 threadId=L4C9D6WIYK2K eventType="RESPONSE" data="<TestRQ>sometestdata</TestRQ>"2022-06-12 21:...
by dmuley Explorer in Splunk Search 06-30-2022
0 4
0
4
sajalbansal2
Hi Everyone, There's a small problem I'm having while using the ltrim function.Query: | makeresults | eval username="...
by sajalbansal2 Explorer in Splunk Search 06-30-2022
0 2
0
2
Splunkee
Hi, I would like to return the rex "field" from a subquery so I can print it out. How do I do that?index=... "some te...
by Splunkee Loves-to-Learn in Splunk Search 06-30-2022
0 8
0
8
splunknoob2
Hello, I have a question regarding the indexing of search results. So, I have an alert that's currently active perfor...
by splunknoob2 Observer in Splunk Search 06-30-2022
0 3
0
3
lboro_garyp
I'm struggling to create a search using an inputlookup and multiple NOT searches. Background: I have an inputlookup t...
by lboro_garyp Path Finder in Splunk Search 06-30-2022
0 3
0
3
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...
Top Solution Authors