Splunk Search

Splunk Search
Community Activity
bobojesus
The first time format is Fri Dec 21 11:17:30 2018 the other one is 2018-12-21T11:17:31.051061 I was wondering how...
by bobojesus Engager in Splunk Search 12-23-2024
0 14
0
14
StephenD1
I'm trying to create an alert that looks through a given list of indexes and triggers an alert for each index showing...
by StephenD1 Path Finder in Splunk Search 12-23-2024
0 8
0
8
Ste
Dear expertsWhy is the following line | where my_time>=relative_time(now(),"-1d@d") AND my_time<=relative_time(now(),...
by Ste Path Finder in Splunk Search 12-23-2024
0 6
0
6
t_splunk_d
I am trying to track file transfers from one location to another. Flow: Files are copied to File copy location -> Tar...
by t_splunk_d Path Finder in Splunk Search 12-22-2024
0 4
0
4
bcatwork
Hi all, I am looking for some help for the following use case. I have a series of endpoints represented by full URL...
by bcatwork Path Finder in Splunk Search 12-22-2024
0 6
0
6
hcastell
Hi all, as a splunk newbie I'm not sure what direction to go with the following. Basically I have two Interesting fi...
by hcastell Path Finder in Splunk Search 12-22-2024
0 5
0
5
karthi2809
index="testd" | rex field=_raw "Remote host:(?.*):" |dedup Remotehost |stats count by Remotehost My events: Remote...
by karthi2809 Builder in Splunk Search 12-22-2024
0 4
0
4
Ellen
After upgrading to 5.x, I noticed that some of my searches are taking a longer time to return results than prior. Sea...
by Ellen Splunk Employee Splunk Employee in Splunk Search 12-22-2024
1 2
1
2
devsru
Hi Everyone,I need to send a hard coded message to the users just before every daylight savings of the year saying "D...
by devsru Explorer in Splunk Search 12-21-2024
0 5
0
5
Sailesh6891
How can we concatenate values from one field and put it in a new variable with commas.e.g If I run a search , I get n...
by Sailesh6891 Engager in Splunk Search 12-20-2024
0 6
0
6
gcusello
Hi at all,I have a data structure like the following:  title1 title2 title3 title4 value  and I need to group by titl...
by SplunkTrust SplunkTrust in Splunk Search 12-20-2024
0 11
0
11
SN1
there is a user lets say ABC and I want to check why his AD account is locked .
by SN1 Path Finder in Splunk Search 12-20-2024
0 6
0
6
anooshac
I am using same index for both stats disctinctcount and timechart distinctcount. But the results from timechart is al...
by anooshac Communicator in Splunk Search 12-20-2024
0 1
0
1
t_splunk_d
I am trying to track file transfers from one location to another. Flow: Files are copied to File copy location -> Tar...
by t_splunk_d Path Finder in Splunk Search 12-19-2024
0 8
0
8
secure
Hi i have a below query where I'm calculating the total prod server count in first dataset and in second dataset I'm ...
by secure Path Finder in Splunk Search 12-19-2024
0 1
0
1
tdavison76
Hello,  I am just trying to do a regex to split a single field into two new fields.The original field is:alert.alias ...
by tdavison76 Path Finder in Splunk Search 12-19-2024
0 4
0
4
CCP_tech
I've piped a Splunk log query extract into a table showing disconnected and connected log entries sorted by time.NB r...
by CCP_tech Loves-to-Learn Lots in Splunk Search 12-18-2024
0 8
0
8
brglaze
I currently have 2 different tables where the first one shows the number of firewalls each location has (WorkDay_Loca...
by brglaze New Member in Splunk Search 12-18-2024
0 1
0
1
Ashish0405
Would anyone be able to help me on one more thing please !!! I have a Number display dashboard which represent the BG...
by Ashish0405 Path Finder in Splunk Search 12-18-2024
0 6
0
6
frankeke
I have created a lookup table in Splunk that contains a column with various regex patterns intended to match file pat...
by frankeke Loves-to-Learn in Splunk Search 12-17-2024
0 5
0
5
Ashish0405
Hi Team,  In below query I don't want to show up the result as "Up" in state_to field, I just want to see data with d...
by Ashish0405 Path Finder in Splunk Search 12-17-2024
0 10
0
10
s_s
Hello, I am experiencing intermittent log ingestion issues on some servers and have observed potential queue saturati...
by s_s Observer in Splunk Search 12-17-2024
0 1
0
1
dtaylor
I've been working on a search that I *finally* managed to get working that would look for events generated by a provi...
by dtaylor Path Finder in Splunk Search 12-17-2024
0 2
0
2
anoopambli
I have been going through several answers about how to get and track user logons and logoffs. Tried many of the searc...
by anoopambli Communicator in Splunk Search 12-17-2024
1 12
1
12
secure
Hi All i have a csv look up with below data Event_Code AUB01 AUB36 BUA12 i want to match it with a dataset which has ...
by secure Path Finder in Splunk Search 12-17-2024
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...