Splunk Search

Splunk Search
Community Activity
jugarugabi
Hi,  I am having the following query:  index=* sourcetype=CustomAccessLog | table "host", "source"   The output is: h...
by jugarugabi Path Finder in Splunk Search 05-06-2022
0 2
0
2
bosseres
Hello, everyone! I get error "WARN: Search filters specified using splunk_server/splunk_server_group do not match any...
by bosseres Contributor in Splunk Search 05-06-2022
0 1
0
1
sarahnazzar
Hello Splunkers! Initially I added the monitor stanza for all the inputs from various time zones and then when I had ...
by sarahnazzar Explorer in Splunk Search 05-06-2022
0 4
0
4
ericvdhout
Hi, Am quite new to splunk, and coming from Elasticsearch, so my knowledge is biased. However I did notice that Elast...
by ericvdhout Path Finder in Splunk Search 05-06-2022
0 14
0
14
jip31
hi i add a + or a - sign before a percent result like this   | eval perc=if(s<2,"-","+").round((s/2)*100,1). "% "   ...
by jip31 Motivator in Splunk Search 05-06-2022
0 1
0
1
lost_alex
Dear community, I am using this community since years, so far I've found everything I needed. Now I am stuck!!! I am ...
by lost_alex Observer in Splunk Search 05-06-2022
0 2
0
2
spl10
Hi Team,I am trying to take the backup of lookups using search head console and for the same I have tried two ways.a)...
by spl10 Explorer in Splunk Search 05-06-2022
0 2
0
2
BT
2 events : request and response and unique id which binds this transaction. I have  issue where i have to calculate t...
by BT Path Finder in Splunk Search 05-06-2022
0 5
0
5
morgantay96
Hi all need help getting the trailing number from a field in a search. Examples of the fieldid = bdf73ad5-4499-4f70-b...
by morgantay96 Path Finder in Splunk Search 05-05-2022
0 3
0
3
trengginas
hi am newbie I have a duration time value with the format "1d hh:mm:ss"but I haven't gotten a thread that discusses s...
by trengginas Engager in Splunk Search 05-05-2022
0 2
0
2
jakeoftrades
hi,Can someone help to correct the query provided below which will send alert if detected a STOPPED status for 3 cons...
by jakeoftrades Explorer in Splunk Search 05-05-2022
0 11
0
11
cybersecnutant
We have a 3rd party pulling AWS logs as far back as AWS holds onto logs. However, we want to be able to go back furth...
by cybersecnutant Explorer in Splunk Search 05-05-2022
0 1
0
1
PatelAshish83
Is there a way to create a report using metadata or any other data to list all the fields that are available by index...
by PatelAshish83 Engager in Splunk Search 05-05-2022
0 5
0
5
p4085f9
Hi allI have a riddle. Query A and query B does not collect the same events and I don’t understand why.Query A) resul...
by p4085f9 Engager in Splunk Search 05-05-2022
0 2
0
2
secphilomath
Is there a way to do a search like this; If Eventid=1111     only do these  statements elseif Eventid=2222     only d...
by secphilomath New Member in Splunk Search 05-05-2022
0 3
0
3
Newser703
Hello I have data that looks like this :  Name | Type | Value ------------------------------------------ Name1 | Type...
by Newser703 Explorer in Splunk Search 05-05-2022
0 1
0
1
swengroeneveld
We are working to enhance our potential bot-traffic blocking and would like to see every IP that has hit AWS cloudfro...
by swengroeneveld Explorer in Splunk Search 05-05-2022
0 2
0
2
VijaySrrie
I have 2 events 1) request event 2) response event I need response time to be calculated (i.e) request event time - r...
by VijaySrrie Builder in Splunk Search 05-05-2022
0 6
0
6
doniv
Hi, I want to compare the count of calls obtained in a day with the target in lookup csv, for example: input csv: hea...
by doniv Loves-to-Learn Lots in Splunk Search 05-05-2022
0 6
0
6
srujana96
i have the 2 values let's sayexpected time= 6:00:00completion time= 08:32:44and the expected output should be the dif...
by srujana96 Explorer in Splunk Search 05-04-2022
0 2
0
2
sanjubaba
I am preparing a SNOW incident trend which should showcase the percentage of tickets reduced/increased in current mon...
by sanjubaba Path Finder in Splunk Search 05-04-2022
0 1
0
1
martin61
I want to get QID list from yesterday’s published data.  For that I'm using PUBLISHED_DATETIME field with yesterday’s...
by martin61 Engager in Splunk Search 05-04-2022
0 1
0
1
gfisbeck
I have a lookup table that lists all users along with their department like so:   email department -----...
by gfisbeck Explorer in Splunk Search 05-04-2022
0 7
0
7
bogdan_nicolesc
So i have this:     (index=* OR index=_*) (index="GA2014" EventCode=4625) | dedup RecordNumber | rename Account_Name ...
by bogdan_nicolesc Communicator in Splunk Search 05-04-2022
0 0
0
0
manhalmoussa
Hello my fellow Splunkers,i am trying to use a second index as a lookup for a field in the first index index=products...
by manhalmoussa Explorer in Splunk Search 05-04-2022
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...