Splunk Search

Splunk Search
Community Activity
jmrtm44
Hello, using Splunk version 8.1.3.Would you know why there’s a Server Error when we input the below search expression...
by jmrtm44 Observer in Splunk Search 06-21-2022
0 3
0
3
paritoshs24
My search is  like  this index = idx source = src data_stamp = A  field1 = *lol* | table Field2   --> This generates ...
by paritoshs24 Path Finder in Splunk Search 06-21-2022
0 6
0
6
kiran007
Need to pass the result of query1 to as a input string for the second query. For the First query i'm getting output(x...
by kiran007 Explorer in Splunk Search 06-21-2022
0 4
0
4
_pravin
Hi Community,   I have two separate Splunk installs: one is the 8.1.0 version and another one is 8.2.5 The older vers...
by _pravin Contributor in Splunk Search 06-21-2022
0 8
0
8
SCSC
I created this data table by "mvappend" command. dont have "_time" column and have only 3months records. MONTH itemA ...
by SCSC Explorer in Splunk Search 06-20-2022
0 4
0
4
hungln9
Hi Team,  I have query, result returned for "dateofBirth" filed is "yyyymmdd" like "19911021", can I format the value...
by hungln9 Explorer in Splunk Search 06-20-2022
0 1
0
1
jomon_ng
Hi, I tried to filter events on version 2.30.0 based on v1.110.0 configuration, but it failed to dropped events in ve...
by jomon_ng Observer in Splunk Search 06-20-2022
0 0
0
0
morgantay96
Hi All, I have a mv field with a bunch of different values. I want to learn how to pull specific values based on stri...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 2
0
2
morgantay96
Hello I am a bit confused here but I have a search that runs and creates a multivalue  field called "tags{}.name". Th...
by morgantay96 Path Finder in Splunk Search 06-20-2022
0 4
0
4
jpfrancetic
Hi Splunk Community, I am having a problem with saved searches not saving the full results. I have a saved search tha...
by jpfrancetic Path Finder in Splunk Search 06-20-2022
0 2
0
2
nikhilmalkari18
index = "abc" required_field = "xx" | table date - gives me a single string in the table. How can I store this string...
by nikhilmalkari18 New Member in Splunk Search 06-20-2022
0 4
0
4
ashidhingra
| where like(RouteCode, "50%") AND !like(RouteCode, "503%")I am trying to show Routecode 501,2, -- anyother not 503.
by ashidhingra Path Finder in Splunk Search 06-20-2022
0 1
0
1
chandysir
Hello All, I am new to Splunk. My Splunk index is already getting data from a Kafka source   index=k_index sourcetype...
by chandysir Explorer in Splunk Search 06-20-2022
0 5
0
5
NewGhost
Please see this search - i'm trying to add missing field values from another index to this search. index=1 earliest=-...
by NewGhost Engager in Splunk Search 06-20-2022
0 4
0
4
IngmarHicoz
Hi all, so, on my es-security search head, this sourcetype is incorrectly parsing the user field. It is capturing all...
by IngmarHicoz Engager in Splunk Search 06-20-2022
0 2
0
2
smanojkumar
Query to find when host is stopped, Here as mentioned in picture, the field _time stopped at the time , when the host...
by smanojkumar Contributor in Splunk Search 06-20-2022
0 4
0
4
smanojkumar
I'm having a list of serve down and need to notify once its back to normal (up),  This is the requirement, once the s...
by smanojkumar Contributor in Splunk Search 06-20-2022
0 0
0
0
vn_g
( | stats count by app ) I have 30 apps to be displayed in a Piechart format. But in visualization i can view only 14...
by vn_g Path Finder in Splunk Search 06-20-2022
0 11
0
11
Dolfing
I have my Sonicwall logfiles coming into Splunk. By searching this index I want to replace "dst" (Destination IP addr...
by Dolfing Explorer in Splunk Search 06-20-2022
0 4
0
4
neerajs_81
Hi All,  I am using transaction to group my DDOS appliance events based on a field called status which has values lik...
by neerajs_81 Builder in Splunk Search 06-20-2022
0 1
0
1
nmarun
Hi, I'm able to get the response in a tabular format using the command: table clientName, apiMethod, sourceSystem, ht...
by nmarun Explorer in Splunk Search 06-19-2022
0 6
0
6
mschaaf
In the code below, i want the explicit {5} to be replaced with a variable like {$session_length$}. Is this possible? ...
by mschaaf Path Finder in Splunk Search 06-19-2022
1 18
1
18
Mrig342
Hi All, I have logs like below in splunk. log1: "count":1, log2: gcg.gom.esb_159515.rg.APIMediation.Disp1.3.Rs.APIM3 ...
by Mrig342 Contributor in Splunk Search 06-19-2022
0 4
0
4
runiyal
I have two Searches and following are its result individually - index="myindex" <my search 1> | table App Size Count ...
by runiyal Path Finder in Splunk Search 06-19-2022
0 4
0
4
badrinath
Hi, I am working on logs so the logs can be of just one line or multiple lines and if it is of one line I wanted to t...
by badrinath Path Finder in Splunk Search 06-19-2022
0 1
0
1
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...