Splunk Search

Splunk Search
Community Activity
Callum_f
I have a sub query that gives the output example below  Sub Query [ search index=prod_diamond sourcetype=CloudWatch_...
by Callum_f Explorer in Splunk Search 06-21-2022
0 3
0
3
HansNL
Hi, am working on a lookup in a lookup. i have the following search: index=* source="*WinEventLog:Security" EventCode...
by HansNL Loves-to-Learn in Splunk Search 06-21-2022
0 5
0
5
bdunstan
Hi,Is there a way to target which application lookup you want to use?Lets say there are 3 applications, A, B and C,  ...
by bdunstan Path Finder in Splunk Search 06-21-2022
0 2
0
2
kc_prane
Hi Team -  Need your expertise in Regex. The below is the rawlog i need to extract the Date and time  the only unique...
by kc_prane Communicator in Splunk Search 06-21-2022
0 7
0
7
BLACKBEARCO
We are about to open up a Splunk ticket for this issue, but figured we'd check with the community first. Problem: The...
by BLACKBEARCO Explorer in Splunk Search 06-21-2022
0 3
0
3
mistydennis
When I add this case statement to my search, all results for Severity are "Other". What did I miss?| eval Severity=ca...
by mistydennis Communicator in Splunk Search 06-21-2022
0 10
0
10
jmrtm44
Hello, using Splunk version 8.1.3.Would you know why there’s a Server Error when we input the below search expression...
by jmrtm44 Observer in Splunk Search 06-21-2022
0 3
0
3
paritoshs24
My search is  like  this index = idx source = src data_stamp = A  field1 = *lol* | table Field2   --> This generates ...
by paritoshs24 Path Finder in Splunk Search 06-21-2022
0 6
0
6
kiran007
Need to pass the result of query1 to as a input string for the second query. For the First query i'm getting output(x...
by kiran007 Explorer in Splunk Search 06-21-2022
0 4
0
4
_pravin
Hi Community,   I have two separate Splunk installs: one is the 8.1.0 version and another one is 8.2.5 The older vers...
by _pravin Contributor in Splunk Search 06-21-2022
0 8
0
8
SCSC
I created this data table by "mvappend" command. dont have "_time" column and have only 3months records. MONTH itemA ...
by SCSC Explorer in Splunk Search 06-20-2022
0 4
0
4
hungln9
Hi Team,  I have query, result returned for "dateofBirth" filed is "yyyymmdd" like "19911021", can I format the value...
by hungln9 Explorer in Splunk Search 06-20-2022
0 1
0
1
jomon_ng
Hi, I tried to filter events on version 2.30.0 based on v1.110.0 configuration, but it failed to dropped events in ve...
by jomon_ng Observer in Splunk Search 06-20-2022
0 0
0
0
morgantay96
Hi All, I have a mv field with a bunch of different values. I want to learn how to pull specific values based on stri...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 2
0
2
morgantay96
Hello I am a bit confused here but I have a search that runs and creates a multivalue  field called "tags{}.name". Th...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 4
0
4
jpfrancetic
Hi Splunk Community, I am having a problem with saved searches not saving the full results. I have a saved search tha...
by jpfrancetic Path Finder in Splunk Search 06-20-2022
0 2
0
2
nikhilmalkari18
index = "abc" required_field = "xx" | table date - gives me a single string in the table. How can I store this string...
by nikhilmalkari18 New Member in Splunk Search 06-20-2022
0 4
0
4
ashidhingra
| where like(RouteCode, "50%") AND !like(RouteCode, "503%")I am trying to show Routecode 501,2, -- anyother not 503.
by ashidhingra Path Finder in Splunk Search 06-20-2022
0 1
0
1
chandysir
Hello All, I am new to Splunk. My Splunk index is already getting data from a Kafka source   index=k_index sourcetype...
by chandysir Explorer in Splunk Search 06-20-2022
0 5
0
5
NewGhost
Please see this search - i'm trying to add missing field values from another index to this search. index=1 earliest=-...
by NewGhost Engager in Splunk Search 06-20-2022
0 4
0
4
IngmarHicoz
Hi all, so, on my es-security search head, this sourcetype is incorrectly parsing the user field. It is capturing all...
by IngmarHicoz Engager in Splunk Search 06-20-2022
0 2
0
2
smanojkumar
Query to find when host is stopped, Here as mentioned in picture, the field _time stopped at the time , when the host...
by smanojkumar Contributor in Splunk Search 06-20-2022
0 4
0
4
smanojkumar
I'm having a list of serve down and need to notify once its back to normal (up),  This is the requirement, once the s...
by smanojkumar Contributor in Splunk Search 06-20-2022
0 0
0
0
vn_g
( | stats count by app ) I have 30 apps to be displayed in a Piechart format. But in visualization i can view only 14...
by vn_g Path Finder in Splunk Search 06-20-2022
0 11
0
11
Dolfing
I have my Sonicwall logfiles coming into Splunk. By searching this index I want to replace "dst" (Destination IP addr...
by Dolfing Explorer in Splunk Search 06-20-2022
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...