Splunk Search

Splunk Search
Community Activity
hasegawaarte
If I want to use a field(alarm_time) from the main search as a search criteria for a sub-search, what code should I w...
by hasegawaarte Explorer in Splunk Search 03-26-2022
0 1
0
1
alexspunkshell
Can someone help with Splunk Placeholder? What is Placeholder? How to create it? How does it work in lookup? How to m...
by alexspunkshell Contributor in Splunk Search 03-26-2022
0 6
0
6
fredv44
Hello. Given these logs: 2022-03-16 16:08:43.991 traceId="7890" svc="Service1" duration=1322022-03-16 16:10:43.279 tr...
by fredv44 Explorer in Splunk Search 03-26-2022
0 4
0
4
rsahoo
I have a data set from where I am trying to apply the group by function on multiple columns. I tried stats with list ...
by rsahoo Engager in Splunk Search 03-25-2022
0 1
0
1
aj_54321
Hi! I have unstructured log in the following format, and I can't seem to figure out how I can count the number of occ...
by aj_54321 Explorer in Splunk Search 03-25-2022
0 1
0
1
JoeHubner
I am looking to search in one Index for a specific field name and then use a second field from that Index to search a...
by JoeHubner Explorer in Splunk Search 03-25-2022
0 2
0
2
kr5345
Hey there, pretty new to Splunk searching. I am trying to get a table created that will combine search results based ...
by kr5345 Engager in Splunk Search 03-25-2022
0 2
0
2
anthonyb90
I'm looking to set a variable (customerLabel) depending on whether the user selects "framework" or "team" from a drop...
by anthonyb90 New Member in Splunk Search 03-25-2022
0 1
0
1
Woodpecker
Hi,I have 3 indexes. I need to extract hash_values from index 3 and do a search to see if similar files exists in ind...
by Woodpecker Path Finder in Splunk Search 03-25-2022
0 1
0
1
troy44112
What do I need to add to this search, to make this search  | where Need >= 60min | tstats max(_indextime) AS Late whe...
by troy44112 Explorer in Splunk Search 03-25-2022
0 8
0
8
BenWilliamson1
My data consists of individual messages, tagged with the userID of the user who sent them. I want to count the number...
by BenWilliamson1 New Member in Splunk Search 03-25-2022
0 2
0
2
dex31337
I want to create alert when user approve MFA from different IP than the one he used prior to connection to VPN. So I'...
by dex31337 Loves-to-Learn Lots in Splunk Search 03-25-2022
0 8
0
8
raduand
Hi guys, I have a Splunk scheduled search which is producing a list of URLs that need to be used by another system. T...
by raduand Explorer in Splunk Search 03-25-2022
1 4
1
4
Mattjj
Hi all, We have events in a single index for flows into and out of a gateway, I’m trying to link an incoming event wi...
by Mattjj Explorer in Splunk Search 03-25-2022
0 2
0
2
huan_an
Hi, I would like to get the average of multiple fields in the same row but not all, would anyone be able to advise on...
by huan_an Explorer in Splunk Search 03-25-2022
0 2
0
2
SonakshiRaiTH
Hi,   I have to do gap analysis on splunk  in order to check which all logs are getting ingested and if there are any...
by SonakshiRaiTH New Member in Splunk Search 03-25-2022
0 1
0
1
edwinmae
I have a log events (each about 260 lines) related to our AWS EMR Cluster 'performance' metrics. It seems it's just a...
by edwinmae Path Finder in Splunk Search 03-24-2022
0 2
0
2
rally0321
With below setup, we can setup the single value dashboard with dynamic coloring change while trendValue change.  "tre...
by rally0321 Path Finder in Splunk Search 03-24-2022
0 0
0
0
jip31
Hello Is it possible to use a cron that runs a seach every hour ten minutes after hour and just between 7 AM and 19PM...
by jip31 Motivator in Splunk Search 03-24-2022
0 1
0
1
testnoob
Hi All ,The requirement is to get all usernames , username created date and email associated to it as belowusername  ...
by testnoob New Member in Splunk Search 03-24-2022
0 5
0
5
adamsmith47
I have a search I can compose using multiple appends and sub-searches to accomplish, but I assume there's an easier w...
by adamsmith47 Communicator in Splunk Search 03-24-2022
0 1
0
1
Saikat001
What is the location of Splunk commands like inputlookup,lookup,mvexpand,multikv,split,stats,eval,chart,tstats in spl...
by Saikat001 Explorer in Splunk Search 03-24-2022
0 1
0
1
andrew_burnett
I need an alert where you get this message "Attempting to send email to:<email>" but you don't ever get the message "...
by andrew_burnett Path Finder in Splunk Search 03-24-2022
0 3
0
3
bsg273
I'm trying to create a column chart (bar graph) in my Splunk (v8.1.3) dashboard that shows the availabilities of a gi...
by bsg273 Path Finder in Splunk Search 03-24-2022
0 2
0
2
sercankarvar
I am seraching as below but my join operation is not bringing results from the join for only couple of imei/records. ...
by sercankarvar Observer in Splunk Search 03-24-2022
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...