Splunk Search

Splunk Search
Community Activity
saurav47
Hi All, i am using IF function like |eval xxx= if ( status =="1","A", if(status =="2","A", if(status =="3","A","0") i...
by saurav47 Loves-to-Learn Lots in Splunk Search 05-13-2022
0 5
0
5
sanket4147
Hi All, I want to view all the dashboards which we have configured in Splunk. While I am trying with the below comman...
by sanket4147 Loves-to-Learn Lots in Splunk Search 05-13-2022
0 7
0
7
csahoo
We have a  service for which we have splunk dashboard is in place and right now the dashboard have the limitation tha...
by csahoo Explorer in Splunk Search 05-13-2022
0 1
0
1
SMM10
I am looking through our current alerts and we have a few evaluations that occur like below.Total_Trade: 129Total_Val...
by SMM10 Explorer in Splunk Search 05-13-2022
0 1
0
1
csahoo
0
3
bosseres
Hello, everyone I need help from community. I want to make search that will find two+ events from same host, for exam...
by bosseres Contributor in Splunk Search 05-13-2022
0 1
0
1
payyachamy
I have a query that calculates a certain value when a particular condition is met. | eval Other_Failures = Total_requ...
by payyachamy Observer in Splunk Search 05-12-2022
0 2
0
2
paritoshs24
Hi Team, Following is my data: SSTTDTDALTLATOTAaxxx432376ayyy222345bxxx111133byyy111111   following is the graph i ca...
by paritoshs24 Path Finder in Splunk Search 05-12-2022
0 2
0
2
jip31
hello From the dropdown list below, I need to update search events with an eval case command     <input type="dro...
by jip31 Motivator in Splunk Search 05-12-2022
0 12
0
12
mistydennis
Hello Splunkers - I am struggling to create a table that shows distinct events that sometimes have the same timestamp...
by mistydennis Communicator in Splunk Search 05-12-2022
0 4
0
4
kevinjacks
I need help reformatting a MAC address field which doesn't have colons to add them. MAC=123456781122desired format = ...
by kevinjacks Explorer in Splunk Search 05-12-2022
0 6
0
6
nicolocervo
I am importing in splunk many tables of data of 500 to 10000 events each and I need to use them to enrich events with...
by nicolocervo Engager in Splunk Search 05-12-2022
0 1
0
1
mjemi
I want to filter eventcode 4624 and user_type=computer using transforms and props.conf Transforms.conf [setnule]REGEX...
by mjemi Loves-to-Learn Everything in Splunk Search 05-12-2022
0 0
0
0
uagraw01
How to use spath command for the below logs i have attached in the screenshot.
by uagraw01 Motivator in Splunk Search 05-12-2022
0 6
0
6
prateedshetty
I've uploaded the same log twice(using drag and drop option in add data) and now when I query I see duplicate results...
by prateedshetty Path Finder in Splunk Search 05-12-2022
0 6
0
6
johanhakim
Hi,I have 2 separate queries as below:Query1: (normal splunk search e.g. index=* host=abcde | table Message1,Message2...
by johanhakim Explorer in Splunk Search 05-12-2022
0 6
0
6
HattrickNZ
Can you do conditional formatting, like in Excel, in Splunk? For example, can I have conditional formatting on the p...
by HattrickNZ Motivator in Splunk Search 05-12-2022
0 4
0
4
greekleo89
Hi,   I receive data from a particular product that is installed on various customers, that data is received every 5 ...
by greekleo89 Loves-to-Learn Everything in Splunk Search 05-12-2022
0 16
0
16
sanket4147
Hi Team, We are using Splunk Enterprise SIEM tool. we want to check all the source type which is configured for all a...
by sanket4147 Loves-to-Learn Lots in Splunk Search 05-11-2022
0 1
0
1
snandaku
Sample Data: {<!-- -->{"device_id":"a1c842ef8c0545f48e8e61d3e03c68bb","ip":"192.168.193.162","topic":"DEVICE","event":"device...
by snandaku Engager in Splunk Search 05-11-2022
0 10
0
10
k31453
Hi, I have following data which I use search to find from last 30 days and save it into lookup: CustomersOld Acquired...
by k31453 Explorer in Splunk Search 05-11-2022
0 3
0
3
amarmnrao
Hi - I want to list API's and its latencies / response times and want to compare the latencies in a table like below,...
by amarmnrao New Member in Splunk Search 05-11-2022
0 3
0
3
XOJ
I have a sourcetype the provides results for dst if it has one result or dst{} with multiple results. I am attempting...
by XOJ Path Finder in Splunk Search 05-11-2022
0 0
0
0
XOJ
I'm trying to extract fields out of the winevent IIS logs. My regex works in regex101 perfectly. Also I can do someth...
by XOJ Path Finder in Splunk Search 05-11-2022
0 8
0
8
doweaver
I have a dataset where each event summarizes a workflow, using the fields Foo-&gt;Bar-&gt;Baz, and I'm looking to create a ...
by doweaver Path Finder in Splunk Search 05-11-2022
1 15
1
15
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...