Splunk Search

Splunk Search
Community Activity
jinishshah
Hello, I have 2 CSVs in my splunk: Alert.csv having below columns and data: Alert_Header   Alert_type   Date JNA/athe...
by jinishshah Explorer in Splunk Search 04-13-2022
0 3
0
3
fmcgheeSplunk
i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data ...
by fmcgheeSplunk Splunk Employee Splunk Employee in Splunk Search 04-13-2022
0 1
0
1
paulito
  I need to extract the Activity Score and Application UXI Average but only when the Application Name is a certain na...
by paulito Explorer in Splunk Search 04-13-2022
0 2
0
2
diegomedinar
Hello,   I would like to add values from a search in one index and then to the result of another search from a differ...
by diegomedinar New Member in Splunk Search 04-13-2022
0 3
0
3
SplunkDash
Hello,I have a text source file with header. Some sample events (first line is a header) and props that I wrote given...
by SplunkDash Motivator in Splunk Search 04-13-2022
0 11
0
11
kwy
Hello,I have the request which normally show 4 rows, I need to display only  one row with only the Status column. ind...
by kwy Loves-to-Learn in Splunk Search 04-13-2022
0 1
0
1
ND
Hi Everyone,   below is my query to use thousand comma separator: |inputlookup abc.csv | chart sum(field1) as field1 ...
by ND Path Finder in Splunk Search 04-13-2022
0 1
0
1
inkedia
    I have to extract the highlighted value as a single field in splunk. Any help.
by inkedia Explorer in Splunk Search 04-13-2022
0 4
0
4
ofer_s
I cant seem to find an example parsing a json array with no parent. Meaning, I need to parse: [{"key1":"value2}, {"ke...
by ofer_s Loves-to-Learn in Splunk Search 04-13-2022
0 1
0
1
splunkboob
i want to have an overview of malicious network traffic in my network and i decided to filter out all the "good" traf...
by splunkboob Explorer in Splunk Search 04-13-2022
0 1
0
1
yk010123
Considering a field like :  field=select id from table where id In ["123","12"] limit 1 field=select id from table wh...
by yk010123 Path Finder in Splunk Search 04-12-2022
0 2
0
2
vjsplunk
I am trying to set timestamp for the event : ======== Sat Mar 19 16:33:08 2022 -05:00 LENGTH : '228' ACTION :[7] 'CO...
by vjsplunk Loves-to-Learn Everything in Splunk Search 04-12-2022
0 5
0
5
karthi25
As shown below I have only two events present on my indexBut when i execute the below search queryindex = **** |rex f...
by karthi25 Path Finder in Splunk Search 04-12-2022
0 3
0
3
yk010123
I have the following data :  ServiceMessageService1Hello worldService2Another messageService1Hello worldService1Some ...
by yk010123 Path Finder in Splunk Search 04-12-2022
0 2
0
2
ojtoids
These are ticket platform logs with field 'lastupdated' which contains time and date [2022-04-12 12:12:17.160000+00:0...
by ojtoids Explorer in Splunk Search 04-12-2022
0 1
0
1
ahmed_aladwani
Hello everybody, This is actually my first post here so forgive me if I missed up or posted in the wrong section. I'm...
by ahmed_aladwani Engager in Splunk Search 04-12-2022
0 1
0
1
mrigs13
Hi, I am trying to write a query that would get me the average TPS and average response time for services in the same...
by mrigs13 Explorer in Splunk Search 04-12-2022
0 10
0
10
bheptinstall
I have a dashboard setup that returns a few searches for my organization. When I click the export button underneath t...
by bheptinstall Engager in Splunk Search 04-12-2022
0 2
0
2
jpfrancetic
Greetings Splunk Community, I am currently working on a search and I am trying to drop rows that have "NULL" in them....
by jpfrancetic Path Finder in Splunk Search 04-12-2022
0 1
0
1
saurav47
Hey Team, I have some 150+ ip addresses in CIDR format (IE 96.24.0.0/16, etc) , i am getting my search result with on...
by saurav47 Loves-to-Learn Lots in Splunk Search 04-12-2022
0 1
0
1
Allene139
I have 2 searches and I want to link 2 together in one table.The first search: index=very_big_index caseNumber=123456...
by Allene139 Explorer in Splunk Search 04-12-2022
0 4
0
4
neerajs_81
GentlemenMy raw events have a field called login_time which has values of format ( 2022-04-11 10:52:08 ) .  This is t...
by neerajs_81 Builder in Splunk Search 04-12-2022
0 6
0
6
bijodev1
Hi Team, when I use curl - I am able to get the output in JSON format. But when I am trying to use requests module, I...
by bijodev1 Communicator in Splunk Search 04-12-2022
0 7
0
7
greekleo89
Hi all, New to splunk and i have seen that this has been asked many times but most of the results are based on matchi...
by greekleo89 Loves-to-Learn Everything in Splunk Search 04-12-2022
0 9
0
9
neerajs_81
Hi All,  I have two sourcetypes in the same index, however the fields names are different but the value is same for t...
by neerajs_81 Builder in Splunk Search 04-12-2022
0 3
0
3
Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...