Splunk Search

Splunk Search
Community Activity
actionabledata
Do the resulting files from a "dump" command have a TTL? I think they must since the files I created on Friday no lon...
by actionabledata Path Finder in Splunk Search 06-10-2022
0 2
0
2
aikn061
Hi Guys, I already have a query below that gives me a table similar to the one on bottom.  I was wondering if there i...
by aikn061 Explorer in Splunk Search 06-09-2022
0 2
0
2
spitchika
Hi,I want to store earliest and latest times of my search in variables to use them in further operations. But I am un...
by spitchika Path Finder in Splunk Search 06-09-2022
0 1
0
1
xoamanda12xo
Basically my data is formatted as a message and then info in parentheses on the right. Example:" LL - VPN Activity (l...
by xoamanda12xo Explorer in Splunk Search 06-09-2022
0 1
0
1
ashidhingra
| eval hours= if (day="Monday", hours=(a+b), hours) So basically if day=monday, i wants hours to add up a+b
by ashidhingra Path Finder in Splunk Search 06-09-2022
0 3
0
3
trent6
I have a collection of log files that I am trying to parse. Quick summary:From Apache/Tomcat using logback I don't ha...
by trent6 Explorer in Splunk Search 06-09-2022
0 1
0
1
ositaumeozulu
hello team please i need solution to these question i have three column fields, startDate,endDate, ARTstartDate. i wa...
by ositaumeozulu Explorer in Splunk Search 06-09-2022
0 4
0
4
Julia1231
Hi,  I have several model id: 12310, 12320, 12330. If the suffixes = "10", "20", "30", I define the typemachine accor...
by Julia1231 Communicator in Splunk Search 06-09-2022
0 2
0
2
KyleMcDougall
Hi all, I've been working on this query for the last few days and still can't seem to crack it. (Appreciate the perso...
by KyleMcDougall Path Finder in Splunk Search 06-09-2022
0 1
0
1
rstankus
Our IIS logs contain a "time_taken" field which indicates the number of milliseconds each event took. I'd like to use...
by rstankus Explorer in Splunk Search 06-09-2022
0 12
0
12
bolopez
I want to create an alert that pops up when the events match at least 500 times the same source IP address, same dest...
by bolopez Explorer in Splunk Search 06-09-2022
0 2
0
2
mihir_hardas
  I need a list of only those jobName which start with letter a though m - anycase. The below does not work index=log...
by mihir_hardas Explorer in Splunk Search 06-09-2022
0 2
0
2
CarbonCriterium
What is the is the best approach to creating a field that shows the number of incomplete requests in a given period o...
by CarbonCriterium Path Finder in Splunk Search 06-09-2022
0 3
0
3
kpavan
Hi All, I have logs which is from db_inputs/custom_script where owner not indexing custom time field as _time and the...
by kpavan Path Finder in Splunk Search 06-09-2022
0 2
0
2
johanhakim
Hi, I have a custom Python script developed in Splunk where it will translate Chinese characters to English. The cust...
by johanhakim Explorer in Splunk Search 06-09-2022
0 3
0
3
splunkfriend123
Hi Team,   I would like to retrieve following info through Splunk search    1. List of all splunk searches performed ...
by splunkfriend123 Engager in Splunk Search 06-08-2022
0 6
0
6
griffins
For context, I'm creating a dashboard where a user can search activity of all hosts in an environment or one host in ...
by griffins Explorer in Splunk Search 06-08-2022
0 3
0
3
dstaulcu
Has anyone figured a way to make kv-store lookups NOT case sensitive on field values? If so, how? We're about to mig...
by dstaulcu Builder in Splunk Search 06-08-2022
0 14
0
14
test2001
Can you create a query that search for all the logs that got entered in an index for the last 24hours and group it by...
by test2001 Observer in Splunk Search 06-08-2022
0 4
0
4
test2001
Hey everyone and I hope your having a great day!I have configured a custom field extraction in the Splunk search app ...
by test2001 Observer in Splunk Search 06-08-2022
0 0
0
0
R_M
Data looks like  src:10.124.4.151] and i want to remove this bracket and data should look like 10.124.4.151 I am try ...
by R_M Loves-to-Learn in Splunk Search 06-08-2022
0 2
0
2
KyleMcDougall
I'm trying to count the number of sessions (known as sessionId) that have more than 2 intents. (An intent is a field ...
by KyleMcDougall Path Finder in Splunk Search 06-08-2022
0 9
0
9
troy44112
Hello,How would I specify the time frame in a search to provide me the events between 7am - 5pm weekdays and all resu...
by troy44112 Explorer in Splunk Search 06-07-2022
0 2
0
2
stucky101
Gurus I have an infoblox query that simply measures total amount of queries over a certain period by host for a given...
by stucky101 Engager in Splunk Search 06-07-2022
0 10
0
10
dzyfer
I need to exclude events from a timechart only if they fulfill 2 conditions:the field returns 0 for ALL events in the...
by dzyfer Path Finder in Splunk Search 06-07-2022
0 1
0
1
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...
Top Solution Authors