Splunk Search

Splunk Search
Community Activity
sundarrajan
Hello Splunkers!I have an issue in grouping multivalued field after extracting fields from nested xml. The sample is ...
by sundarrajan Path Finder in Splunk Search 05-24-2022
0 2
0
2
pj
We often create daily lookups from our search results, which are then used for several other key searches. On occasio...
by pj Contributor in Splunk Search 05-24-2022
5 8
5
8
HattrickNZ
Can I press enter in a splunk search and not do a search it just moves the text to a new line. In excel it is to pr...
by HattrickNZ Motivator in Splunk Search 05-24-2022
0 4
0
4
Tomten72
Hi forum! I have a couple of tricky questions on working with same indata and same type of graphs... I am currently w...
by Tomten72 Loves-to-Learn in Splunk Search 05-24-2022
0 0
0
0
kranthimutyala
Hi Team, I'm looking for a query to compare Splunk ingestion volume between the current date and a week ago i.e compa...
by kranthimutyala Path Finder in Splunk Search 05-24-2022
0 4
0
4
coldwolf2000
Hello,   I need some help. I am new to Splunk and have run into an issue. I want to have table that will display Comp...
by coldwolf2000 Explorer in Splunk Search 05-24-2022
0 5
0
5
JohnF
Hello folks,  Been busting my head here.. trying to pull data from multiple sourcetypes which I thought would run lik...
by JohnF Engager in Splunk Search 05-24-2022
0 3
0
3
loganjwb
I am using imported CSV data to search throughout Splunk and the CSV file defines the column TIME and only includes t...
by loganjwb Engager in Splunk Search 05-24-2022
0 5
0
5
dzyfer
Hi, I have a column timechart with numerical values, and I would like to add strings, or characters, after these valu...
by dzyfer Path Finder in Splunk Search 05-24-2022
0 4
0
4
splkjk
Hello Splunkers, @SPL , Was working on some of the development activity, got stuck at some level. We have a scenario ...
by splkjk Explorer in Splunk Search 05-23-2022
0 3
0
3
EvansB
Working with this query, I'm hoping to get only results where field values are greater than the other.     index="ind...
by EvansB Path Finder in Splunk Search 05-23-2022
0 4
0
4
tonygpe
I believe that we have computers on our domain that are not actively being used by users and I would like to highligh...
by tonygpe New Member in Splunk Search 05-23-2022
0 3
0
3
Italy1358
It says that my eval is malformed, any suggestions?   | inputlookup US.csv | eval current_date=strftime(time(),"%Y-%m...
by Italy1358 Path Finder in Splunk Search 05-23-2022
0 10
0
10
ft_kd02
Hi all,I'm in the process of setting up performance reporting for services provided for a client. The logic in questi...
by ft_kd02 Path Finder in Splunk Search 05-23-2022
0 1
0
1
marnee
Can you alter the Splunk search used for an alert? I don't see any way to alter it. I am being asked to choose a pr...
by marnee Explorer in Splunk Search 05-23-2022
2 8
2
8
Italy1358
When a user is added i need the time to be recorded and displayed in a field called used_added. I created the field n...
by Italy1358 Path Finder in Splunk Search 05-23-2022
0 1
0
1
vrmandadi
I am trying to  create a search  which will give the difference in count for a field called "id" and show what are th...
by vrmandadi Builder in Splunk Search 05-23-2022
0 5
0
5
dezmadi
I have below query as query returning  null   <search id="dfLatencyOverallProcessingDelayBaseSearch"> <query>index="d...
by dezmadi Path Finder in Splunk Search 05-23-2022
0 1
0
1
dezmadi
I want to hide columName from 2nd row onwards for below table <row><panel><title>STATS : SLI/SLO Dashboard count</tit...
by dezmadi Path Finder in Splunk Search 05-23-2022
1 1
1
1
TB
Hi,I am trying to create a table but how do I  extract these information in my query? I tried double quote " " but it...
by TB New Member in Splunk Search 05-22-2022
0 1
0
1
RiberaJoice
I have a query to fetch account create endpoint and errors after   (index=foo "account/create") OR (index=bar ERROR) ...
by RiberaJoice Splunk Employee Splunk Employee in Splunk Search 05-21-2022
0 1
0
1
seajay1221
I have an index with ~200 fields and need to know the single most common non-null value for each field. How do I unco...
by seajay1221 Engager in Splunk Search 05-20-2022
0 2
0
2
Rodrigo_Larios
Hi guys,  This is one example of my data: Optional("{\"operationName\":\"createCart\",\"variables\":{\"customerId\":\...
by Rodrigo_Larios Explorer in Splunk Search 05-20-2022
0 1
0
1
fatsug
Hi, if someone could help me out with, or point me in a nice direction to, producing a search which shows if/when a t...
by fatsug Builder in Splunk Search 05-20-2022
0 5
0
5
Pat
When doing an extracted field can the regex named capture group be based on a back reference.  The idea is I would ha...
by Pat Path Finder in Splunk Search 05-20-2022
0 1
0
1
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors