Splunk Search

Splunk Search
Community Activity
Anud
Hi team, I have a query related to splunk alert msg send to WebEx chat to individual person. If there is any process,...
by Anud Path Finder in Splunk Search 04-25-2022
0 5
0
5
aahmad
Hey, I am working on making a dashboard and wanted to know how can I subtract two dates that are in iso 8601 format. ...
by aahmad Loves-to-Learn Everything in Splunk Search 04-25-2022
0 3
0
3
Jackiifilwhh
Hi everyone! We want to get the new errors that don't appear yesterday. For example, if an action named A. Its yester...
by Jackiifilwhh Path Finder in Splunk Search 04-25-2022
0 5
0
5
marcosjags
index=xt DONT_MATCH | spath input=log path=message.extra.dj output=dj | spath input=log output=fname path=message.msg...
by marcosjags Explorer in Splunk Search 04-25-2022
0 14
0
14
Jackiifilwhh
Background informationIn our system, every visit consists of one or more actions. Every action has its own name and i...
by Jackiifilwhh Path Finder in Splunk Search 04-25-2022
0 9
0
9
thomasmuellergr
If I query with a wildcard, I get the expected result, but if I query with the actual field value, I get no results. ...
by thomasmuellergr Engager in Splunk Search 04-25-2022
0 4
0
4
denissotoacc
Let's suppose I have the following search:   | makeresults | eval name="Denis", age=34 | append [| makeresults ...
by denissotoacc Path Finder in Splunk Search 04-25-2022
0 3
0
3
alexspunkshell
I have " threatInfo.updatedAt" information in my logs. I want to get an alert if the time difference between "threatI...
by alexspunkshell Contributor in Splunk Search 04-25-2022
0 3
0
3
corehan
Hello dears, How can i change timechart _time axis y to x ? <base search> | timechart span=1h sum(REQUESTNAME) as Si...
by corehan Explorer in Splunk Search 04-25-2022
0 6
0
6
sudhir_norway
I wanted to add this chaining command with my search and display total of the values under fields(columns) "a-b-1"  a...
by sudhir_norway Engager in Splunk Search 04-25-2022
0 5
0
5
marcosjags
Hello Everyone,  I am new to splunk. I am searching the logs and I am getting my url like this /api/sns/exts/djs/3102...
by marcosjags Explorer in Splunk Search 04-25-2022
0 6
0
6
jip31
helloIn my search I use an eval command like below in order to identify character string in web url| eval Kheo=case( ...
by jip31 Motivator in Splunk Search 04-24-2022
0 5
0
5
dbroggy
Hi there, Is it possible to search for windows interactive logons from the Authentication data model? eg. I can do it...
by dbroggy Path Finder in Splunk Search 04-24-2022
0 2
0
2
ajdyer2000
Hi was wondering if possible, how to convert a date field into an abbreviate Month (Jan , Feb, Mar, Apr) So the 2 fie...
by ajdyer2000 Path Finder in Splunk Search 04-24-2022
0 2
0
2
XPGoD
Okay, so this is quite theorectical.... the nature of this search is to basically count the Incoming Domains when the...
by XPGoD Loves-to-Learn Lots in Splunk Search 04-24-2022
0 9
0
9
damucka
Hello, I would like to achieve following:- I have dashboard with the timeline vizualization and would like to get the...
by damucka Builder in Splunk Search 04-23-2022
0 16
0
16
splunkcol
Hello everyone,A query, I have the following problem where a query is made to a specific index and sourcetype at a ce...
by splunkcol Builder in Splunk Search 04-22-2022
0 1
0
1
madhuragujarath
Hi I am trying to automate alert set up for splunk alerts . I am using splunk tf provider : https://registry.terrafor...
by madhuragujarath New Member in Splunk Search 04-22-2022
0 0
0
0
jip31
Hi I need to count time events between now() and now() - 10 minutes Something like this : eval delta =now() - 10 minu...
by jip31 Motivator in Splunk Search 04-22-2022
0 5
0
5
jc28187
I'm trying to create a search macro which accepts a field to match on and enriches the results with matches and outpu...
by jc28187 Engager in Splunk Search 04-22-2022
0 3
0
3
wvalente2
Hi all,I need your help with a query to extract the values of fields with multiple values.The problem I'm facing is t...
by wvalente2 Explorer in Splunk Search 04-22-2022
0 3
0
3
rrovers
I have created a field transformatie via the gui of splunk. I want to add a field in this transformation.If I open th...
by rrovers Contributor in Splunk Search 04-22-2022
0 3
0
3
JChris_
I have the following log in Splunk: { "tags":{ "app":"foobar", "ou":"internal" }, "log":"...
by JChris_ Path Finder in Splunk Search 04-21-2022
0 4
0
4
i_am_manish
I am unable to find my script for my current dashboard and also not getting my data into dashboard so is there any me...
by i_am_manish New Member in Splunk Search 04-21-2022
0 1
0
1
jedatt01
I need to create a report that shows max indexed volume per day by month per index. The following search gives me the...
by jedatt01 Builder in Splunk Search 04-21-2022
1 10
1
10
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...