Splunk Search

Splunk Search
Community Activity
amitru
I want to get an API usage report per user and I am struggling with the Splunk Query for this, can someone please hel...
by amitru Engager in Splunk Search 04-20-2022
0 1
0
1
Software-Simian
Hi All,the topic might sound very mystic but is actually rather straight forward.I have a timechart displaying the cu...
by Software-Simian Path Finder in Splunk Search 04-20-2022
0 7
0
7
neerajs_81
Hi All,In my raw events, there is a field called "dv_last_login_time" ( already indexed)  as shown below that shows t...
by neerajs_81 Builder in Splunk Search 04-20-2022
0 3
0
3
Liran
I'm attempting to run a query and I've run into a really weird situation where if I run a query with "head 10 | field...
by Liran Observer in Splunk Search 04-19-2022
0 3
0
3
SammyDavis
I am trying to display a duration result to a dashboard and when I try to use the function to convert seconds to HH:M...
by SammyDavis Explorer in Splunk Search 04-19-2022
3 13
3
13
dfurtaw
Good day all,I come to seek guidance from the experts My team and I have been tasked with creating an alert that wil...
by dfurtaw Path Finder in Splunk Search 04-19-2022
0 1
0
1
vrmandadi
Hello Splunkers, I have a query where I did a  |stats values(abc) as abc command over time .I got the below results ....
by vrmandadi Builder in Splunk Search 04-19-2022
0 13
0
13
SplunkDash
Hello, I have events with complex/inconsistence data structure. Need to extract field 2 values under 2 different fiel...
by SplunkDash Motivator in Splunk Search 04-19-2022
0 1
0
1
PavanSeerapu
To get the percentage increase of threshold value and to build a dashboard out of it to show as red if it is increase...
by PavanSeerapu Explorer in Splunk Search 04-19-2022
0 2
0
2
BernardEAI
We are trying to create a data model with a custom _time field. We created the data model, and added a calculated fie...
by BernardEAI Communicator in Splunk Search 04-19-2022
0 1
0
1
jbrenner
I have two Splunk queries, each of which uses the _rex command to extract the join field. Example:       QUERY 1 inde...
by jbrenner Path Finder in Splunk Search 04-19-2022
0 3
0
3
indeed_2000
Hi How can I monitor java applications with splunk, I try nmon but it only give whole java process, not specific pid!...
by indeed_2000 Motivator in Splunk Search 04-19-2022
0 3
0
3
arnavkumarsaxen
My logs are in the format: My-Application Log: Some-Key= 99, SomeOtherKey= 231, SomeOtherKey2= 1231, Some Different K...
by arnavkumarsaxen Explorer in Splunk Search 04-19-2022
0 6
0
6
jinishshah
Hello, so I have an input on my dashboard page of either month"01-2022,02-2022" and also quarter"Q1-2022". So dependi...
by jinishshah Explorer in Splunk Search 04-19-2022
0 9
0
9
gheribhai1234
Hey Team,I have Million records to search for.Record Structure is given below.My requirement is to get length of aVal...
by gheribhai1234 Engager in Splunk Search 04-19-2022
0 13
0
13
msg4sunil
index=app1 [search index=app1 "orderid"| fields id] How do I modify the above query wherein "search index=app1 "order...
by msg4sunil Path Finder in Splunk Search 04-18-2022
0 8
0
8
bapun18
I want to specify a field that contains time as earliest and another field as latest so that my spl will be executed ...
by bapun18 Communicator in Splunk Search 04-18-2022
0 2
0
2
neerajs_81
Gentlemen,We are on Splunk Cloud.In my raw events coming from AWS , splunk by default shows a field called "category"...
by neerajs_81 Builder in Splunk Search 04-18-2022
0 4
0
4
jking81
I’m receiving an error whenever I try to view any csv lookup tables I have uploaded into my search head cluster (v8.1...
by jking81 Explorer in Splunk Search 04-18-2022
0 2
0
2
bcwlk
Does anyone know of a way to reverse the order of the automatic start/end values used for bucket creation when workin...
by bcwlk Explorer in Splunk Search 04-18-2022
0 7
0
7
humblelearner
Hi all, I want to set a condition "credential.helper= ", notice there is a trailing space after the "=".  What I want...
by humblelearner Observer in Splunk Search 04-18-2022
0 2
0
2
ddrillic
I have a lookup table from which I need to remove a couple of lines. How can I do it?
by ddrillic Ultra Champion in Splunk Search 04-18-2022
0 3
0
3
Qerro
Don't show a result where the src_ip is X and dest_ip is Y  index=test    host=test  source=test conn_state=sf   | ev...
by Qerro Loves-to-Learn in Splunk Search 04-18-2022
0 2
0
2
POR160893
Hi, I need to use Linear Regression to predict network volumes at the moment.The index I am using has a number of cat...
by POR160893 Builder in Splunk Search 04-18-2022
0 0
0
0
danielbb
We have the following command that works well -    | transaction job_name startswith=STARTING keeporphans=true   Is i...
by danielbb Motivator in Splunk Search 04-18-2022
0 2
0
2
Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...
Top Solution Authors