Splunk Search

Splunk Search
Community Activity
coldwolf2000
Hello,   I need some help. I am new to Splunk and have run into an issue. I want to have table that will display Comp...
by coldwolf2000 Explorer in Splunk Search 05-24-2022
0 5
0
5
JohnF
Hello folks,  Been busting my head here.. trying to pull data from multiple sourcetypes which I thought would run lik...
by JohnF Engager in Splunk Search 05-24-2022
0 3
0
3
loganjwb
I am using imported CSV data to search throughout Splunk and the CSV file defines the column TIME and only includes t...
by loganjwb Engager in Splunk Search 05-24-2022
0 5
0
5
dzyfer
Hi, I have a column timechart with numerical values, and I would like to add strings, or characters, after these valu...
by dzyfer Path Finder in Splunk Search 05-24-2022
0 4
0
4
splkjk
Hello Splunkers, @SPL , Was working on some of the development activity, got stuck at some level. We have a scenario ...
by splkjk Explorer in Splunk Search 05-23-2022
0 3
0
3
EvansB
Working with this query, I'm hoping to get only results where field values are greater than the other.     index="ind...
by EvansB Path Finder in Splunk Search 05-23-2022
0 4
0
4
tonygpe
I believe that we have computers on our domain that are not actively being used by users and I would like to highligh...
by tonygpe New Member in Splunk Search 05-23-2022
0 3
0
3
Italy1358
It says that my eval is malformed, any suggestions?   | inputlookup US.csv | eval current_date=strftime(time(),"%Y-%m...
by Italy1358 Path Finder in Splunk Search 05-23-2022
0 10
0
10
ft_kd02
Hi all,I'm in the process of setting up performance reporting for services provided for a client. The logic in questi...
by ft_kd02 Path Finder in Splunk Search 05-23-2022
0 1
0
1
marnee
Can you alter the Splunk search used for an alert? I don't see any way to alter it. I am being asked to choose a pr...
by marnee Explorer in Splunk Search 05-23-2022
2 8
2
8
Italy1358
When a user is added i need the time to be recorded and displayed in a field called used_added. I created the field n...
by Italy1358 Path Finder in Splunk Search 05-23-2022
0 1
0
1
vrmandadi
I am trying to  create a search  which will give the difference in count for a field called "id" and show what are th...
by vrmandadi Builder in Splunk Search 05-23-2022
0 5
0
5
dezmadi
I have below query as query returning  null   <search id="dfLatencyOverallProcessingDelayBaseSearch"> <query>index="d...
by dezmadi Path Finder in Splunk Search 05-23-2022
0 1
0
1
dezmadi
I want to hide columName from 2nd row onwards for below table <row><panel><title>STATS : SLI/SLO Dashboard count</tit...
by dezmadi Path Finder in Splunk Search 05-23-2022
1 1
1
1
TB
Hi,I am trying to create a table but how do I  extract these information in my query? I tried double quote " " but it...
by TB New Member in Splunk Search 05-22-2022
0 1
0
1
RiberaJoice
I have a query to fetch account create endpoint and errors after   (index=foo "account/create") OR (index=bar ERROR) ...
by RiberaJoice Splunk Employee Splunk Employee in Splunk Search 05-21-2022
0 1
0
1
seajay1221
I have an index with ~200 fields and need to know the single most common non-null value for each field. How do I unco...
by seajay1221 Engager in Splunk Search 05-20-2022
0 2
0
2
Rodrigo_Larios
Hi guys,  This is one example of my data: Optional("{\"operationName\":\"createCart\",\"variables\":{\"customerId\":\...
by Rodrigo_Larios Explorer in Splunk Search 05-20-2022
0 1
0
1
fatsug
Hi, if someone could help me out with, or point me in a nice direction to, producing a search which shows if/when a t...
by fatsug Builder in Splunk Search 05-20-2022
0 5
0
5
Pat
When doing an extracted field can the regex named capture group be based on a back reference.  The idea is I would ha...
by Pat Path Finder in Splunk Search 05-20-2022
0 1
0
1
g_paternicola
Hi everyone,  I'm trying to get the following search work, but for some reason I'm doing something wrong: inputlookup...
by g_paternicola Path Finder in Splunk Search 05-20-2022
0 3
0
3
denissotoacc
I have the following _raw field in my index: _raw Response Headers: {'Date': 'Fri, 13 May 2022 02:59:3...
by denissotoacc Path Finder in Splunk Search 05-20-2022
0 3
0
3
JoeHubner
I would like to add a column to a chart that is the difference of the two columns before it in an application where I...
by JoeHubner Explorer in Splunk Search 05-20-2022
0 2
0
2
Gzuluaga
Hi, I'm pretty new in splunk, I've been reading a lot of documentation and other questions here, but I don't find the...
by Gzuluaga Explorer in Splunk Search 05-20-2022
0 7
0
7
crucifier_0
Hey, i want a regex result from 10.66.189.62 -- -- -[17/May/2022:05:59:16--0400]--502- "POST /astra/sliceHTTP/1.1" re...
by crucifier_0 Explorer in Splunk Search 05-20-2022
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...