Splunk Search

Splunk Search
Community Activity
Ashwini_5
I would like to count the multifield in the table where it has similar values. For Ex:  I need output like below for ...
by Ashwini_5 Explorer in Splunk Search 01-21-2022
0 2
0
2
nate_washburn
Hi, in my index I have a couple time fields that are returned via a simple search_time = 1/20/2022 1:38:55.000 PM (th...
by nate_washburn Engager in Splunk Search 01-21-2022
0 2
0
2
danielbb
We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.H...
by danielbb Motivator in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log entries, I wanted to extract uri in a specific format:log: a_level="INFO", a_time="null", a_t...
by nbhat Explorer in Splunk Search 01-21-2022
0 1
0
1
alexandrebas
I need help regarding comparise a ISO 8601 date field with a specific date.Below is a simple example:index=devices | ...
by alexandrebas Explorer in Splunk Search 01-21-2022
0 1
0
1
zacksoft_wf
I have,sourcetype_A  (fields : ID, age, city, state)sourcetype_B  (fields : ID, job, salary, gender)The fields "ID" i...
by zacksoft_wf Contributor in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log, I wanted to extract Url, Method, ResponseTimeMs, StatusCode as a table:log: a_level="INFO", ...
by nbhat Explorer in Splunk Search 01-21-2022
0 2
0
2
robertlynch2020
Is Type=Left the same as type=outer in Splunk? If so why do they list it as three options?https://docs.splunk.com/Doc...
by robertlynch2020 Influencer in Splunk Search 01-20-2022
0 2
0
2
jasonmhamilton
Hello,I was wondering if it is possible to use Splunk to query IIS logs for a monthly application hit count for multi...
by jasonmhamilton New Member in Splunk Search 01-20-2022
0 3
0
3
zebulajams
Hey all,Newbie here learning Splunk. I'm starting to get into dashboards and want to create either a pie chart or jus...
by zebulajams Explorer in Splunk Search 01-20-2022
0 5
0
5
awmorris
I've been trying to resolve this since October and not getting traction.  Turning to the community for help:I have se...
by awmorris Path Finder in Splunk Search 01-20-2022
0 0
0
0
EvansB
   I would like to get the list of those items in the properties field, like appName, levelId, etc.  
by EvansB Path Finder in Splunk Search 01-20-2022
0 4
0
4
majid87
Hello,Looks like the action field is not returning results for almost all of the indexes. This is only impacting one ...
by majid87 Engager in Splunk Search 01-20-2022
0 4
0
4
Flaxamax
Hello Splunk Community,I'm fairly new to splunk and am using it to search and alert me for testing failures in my man...
by Flaxamax Engager in Splunk Search 01-20-2022
0 3
0
3
anooshac
I have created a bar graph. The following is the query.index= "cx_metrics_analysis" sourcetype="cx_metrics_httpevent"...
by anooshac Communicator in Splunk Search 01-20-2022
0 4
0
4
figuringthings
Hey,Can anyone help me convert Age to Days? Have trouble parsing and calculating. Sample DataAge2 years 3 months 2 da...
by figuringthings New Member in Splunk Search 01-19-2022
0 2
0
2
willsy
hello, Our physical servers had to restart and as such the splunk servers dropped. we are now having issues on ou...
by willsy Communicator in Splunk Search 01-19-2022
0 2
0
2
lucas4394
I am using "sendresults" command and pass the search results to an email body template; however, the search results d...
by lucas4394 Path Finder in Splunk Search 01-19-2022
0 0
0
0
eranhauser
I am trying to assign a value to a parameter in a macro that is based on a calculation of a value being sent to the m...
by eranhauser Path Finder in Splunk Search 01-19-2022
0 3
0
3
amask38
I have been trying to figure out why this doesn't work.|inputlookup ioc_domain.csv | table query | search NOT [inputl...
by amask38 Engager in Splunk Search 01-19-2022
0 6
0
6
drezanka
I am using Splunk Enterprise V8.2.3.2. I am trying to alert when a scheduled search becomes disabled. The problem is ...
by drezanka Explorer in Splunk Search 01-19-2022
0 4
0
4
wangkevin1029
Hi,Splunkers,I have a dashboard with 2 Panels, which share one droplist  input.droplist has  name/values  as  ALL/*, ...
by wangkevin1029 Communicator in Splunk Search 01-19-2022
0 16
0
16
cmccartneyocto
I've been having difficulty with this for a while and looking for some help. I'm attempting to find users logging and...
by cmccartneyocto Engager in Splunk Search 01-19-2022
1 0
1
0
indeed_2000
HiHow can I extract duration with below condition? (it is important to check these condition to find correct match)1)...
by indeed_2000 Motivator in Splunk Search 01-19-2022
0 5
0
5
Ab_Splunk
Can someone help me to get ServiceNow to create an event ticket every time my Splunk alert gets triggered? I had foll...
by Ab_Splunk Engager in Splunk Search 01-19-2022
0 2
0
2
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors