Splunk Search

Splunk Search
Community Activity
omera
When we are doing searches on Splunk we are encountering a strange issue. For example, when I add sc4s_fromhostip=......
by omera Explorer in Splunk Search 03-29-2022
0 2
0
2
Borntowin
Hi Team,    I have two reports where one report(report1)has timestamp field where other report(report2) doesn't have ...
by Borntowin Loves-to-Learn Everything in Splunk Search 03-29-2022
0 1
0
1
neerajs_81
Hi, how do i craft a search to match 2 fields from my raw events with  2 fields from a CSV file and output if one of ...
by neerajs_81 Builder in Splunk Search 03-29-2022
0 9
0
9
splunknewbie81
Hi Guys, I am trying to do a search and also at the same time drop certain information from showing up.As seen from t...
by splunknewbie81 Engager in Splunk Search 03-28-2022
0 4
0
4
Glasses
Hi,Let's say I have a Company directory lookup (e.g. Company_Directory) and I want to lookup the entire hierarchy of ...
by Glasses Builder in Splunk Search 03-28-2022
0 3
0
3
ARaman77
Hi we have a microservices based system and have several services running , the developers put unti a lookup table th...
by ARaman77 Explorer in Splunk Search 03-28-2022
0 1
0
1
kishan2356
Hello,   I need to build a search where I can subtract a token from the previous value in a row. Example I know how t...
by kishan2356 Explorer in Splunk Search 03-28-2022
0 3
0
3
Silviya_brayano
Hi colleagues, I am trying to create index using the Java SDK for Splunk and to reset the "FrozenTimePeriodInSecs" pr...
by Silviya_brayano New Member in Splunk Search 03-28-2022
0 4
0
4
arun_kant_sharm
Hello Experts, I am facing difficulty at index time fields extraction. My sample log file format: Time stamp: Fri Mar...
by arun_kant_sharm Path Finder in Splunk Search 03-28-2022
0 3
0
3
klim
Is it possible to create a custom script that is a search command that can take in the search's results, do something...
by klim Path Finder in Splunk Search 03-28-2022
0 6
0
6
Srikanth1131
  payload: Message { channel=EMAIL , type=security_event_postinfection_admin , locale=it_IT , recipientAddress=LIOU...
by Srikanth1131 Explorer in Splunk Search 03-28-2022
0 3
0
3
Borntowin
Hi Team,    I have indexed the file as current timestamp but would like to execute the query by taking the filename t...
by Borntowin Loves-to-Learn Everything in Splunk Search 03-28-2022
0 3
0
3
HWalk1
So I am looking for the number of a specific event (sign-ins)  deduped by a user, which is simple. The challenge I am...
by HWalk1 Explorer in Splunk Search 03-28-2022
0 3
0
3
BME1
Following the override documentation, I am confused... When creating an override, and the pop up box appears, do you ...
by BME1 Explorer in Splunk Search 03-28-2022
0 4
0
4
zacksoft
My query essentially goes thru every event and picks a field with response_time. And then calculates the average val...
by zacksoft Contributor in Splunk Search 03-28-2022
0 5
0
5
innoce
Hi,I need to extract host values from one index (index=1) and see if there are similar matches that exists in other i...
by innoce Path Finder in Splunk Search 03-28-2022
0 4
0
4
sh254087
The predefined table names in the add-on doesn't list the service ticket related table name, hence wanted to know the...
by sh254087 Communicator in Splunk Search 03-28-2022
0 0
0
0
tehong
Hi Experts When using the following eval, I would like to declare a variable in macro as in create_var(3). | eval var...
by tehong Explorer in Splunk Search 03-27-2022
0 3
0
3
jip31
Hello I use an input text token in my search like this town=$town$ By defaut, town = * The problem is that sometimes ...
by jip31 Motivator in Splunk Search 03-27-2022
0 2
0
2
jakeoftrades
hi,can anyone help me how should I query the counts of kafka_datatype  of those stream_type which Im going to set an ...
by jakeoftrades Explorer in Splunk Search 03-27-2022
0 0
0
0
ravi1234
I want a if else condition in which i need to pass address(path) . Suppose: If (condition==something) {Go to this pa...
by ravi1234 New Member in Splunk Search 03-27-2022
0 1
0
1
elijahputz
Hello, I am trying to setup a search where we look for single source IP's hitting multiple destination IP's on our fi...
by elijahputz Explorer in Splunk Search 03-26-2022
0 11
0
11
hasegawaarte
If I want to use a field(alarm_time) from the main search as a search criteria for a sub-search, what code should I w...
by hasegawaarte Explorer in Splunk Search 03-26-2022
0 1
0
1
alexspunkshell
Can someone help with Splunk Placeholder? What is Placeholder? How to create it? How does it work in lookup? How to m...
by alexspunkshell Contributor in Splunk Search 03-26-2022
0 6
0
6
fredv44
Hello. Given these logs: 2022-03-16 16:08:43.991 traceId="7890" svc="Service1" duration=1322022-03-16 16:10:43.279 tr...
by fredv44 Explorer in Splunk Search 03-26-2022
0 4
0
4
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...