Splunk Search

Splunk Search
Community Activity
steen
Hi,In the past (Splunk Enterprise v 7.x.x) I used the below search to run a report every few min. There were so many ...
by steen Explorer in Splunk Search 01-21-2022
0 5
0
5
parkertctr
I am trying to use the case match command with more than one option. I keep getting an error message regarding the pa...
by parkertctr Path Finder in Splunk Search 01-21-2022
0 2
0
2
andres
I have a raw where each event looks like this (simplified for this exampel):{"time": "2022-01-20 16:40:02.325216", "n...
by andres Loves-to-Learn Lots in Splunk Search 01-21-2022
0 2
0
2
Ashwini_5
I would like to count the multifield in the table where it has similar values. For Ex:  I need output like below for ...
by Ashwini_5 Explorer in Splunk Search 01-21-2022
0 2
0
2
nate_washburn
Hi, in my index I have a couple time fields that are returned via a simple search_time = 1/20/2022 1:38:55.000 PM (th...
by nate_washburn Engager in Splunk Search 01-21-2022
0 2
0
2
danielbb
We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.H...
by danielbb Motivator in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log entries, I wanted to extract uri in a specific format:log: a_level="INFO", a_time="null", a_t...
by nbhat Explorer in Splunk Search 01-21-2022
0 1
0
1
alexandrebas
I need help regarding comparise a ISO 8601 date field with a specific date.Below is a simple example:index=devices | ...
by alexandrebas Explorer in Splunk Search 01-21-2022
0 1
0
1
zacksoft_wf
I have,sourcetype_A  (fields : ID, age, city, state)sourcetype_B  (fields : ID, job, salary, gender)The fields "ID" i...
by zacksoft_wf Contributor in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log, I wanted to extract Url, Method, ResponseTimeMs, StatusCode as a table:log: a_level="INFO", ...
by nbhat Explorer in Splunk Search 01-21-2022
0 2
0
2
robertlynch2020
Is Type=Left the same as type=outer in Splunk? If so why do they list it as three options?https://docs.splunk.com/Doc...
by robertlynch2020 Influencer in Splunk Search 01-20-2022
0 2
0
2
jasonmhamilton
Hello,I was wondering if it is possible to use Splunk to query IIS logs for a monthly application hit count for multi...
by jasonmhamilton New Member in Splunk Search 01-20-2022
0 3
0
3
zebulajams
Hey all,Newbie here learning Splunk. I'm starting to get into dashboards and want to create either a pie chart or jus...
by zebulajams Explorer in Splunk Search 01-20-2022
0 5
0
5
awmorris
I've been trying to resolve this since October and not getting traction.  Turning to the community for help:I have se...
by awmorris Path Finder in Splunk Search 01-20-2022
0 0
0
0
EvansB
   I would like to get the list of those items in the properties field, like appName, levelId, etc.  
by EvansB Path Finder in Splunk Search 01-20-2022
0 4
0
4
majid87
Hello,Looks like the action field is not returning results for almost all of the indexes. This is only impacting one ...
by majid87 Engager in Splunk Search 01-20-2022
0 4
0
4
Flaxamax
Hello Splunk Community,I'm fairly new to splunk and am using it to search and alert me for testing failures in my man...
by Flaxamax Engager in Splunk Search 01-20-2022
0 3
0
3
anooshac
I have created a bar graph. The following is the query.index= "cx_metrics_analysis" sourcetype="cx_metrics_httpevent"...
by anooshac Communicator in Splunk Search 01-20-2022
0 4
0
4
figuringthings
Hey,Can anyone help me convert Age to Days? Have trouble parsing and calculating. Sample DataAge2 years 3 months 2 da...
by figuringthings New Member in Splunk Search 01-19-2022
0 2
0
2
willsy
hello, Our physical servers had to restart and as such the splunk servers dropped. we are now having issues on ou...
by willsy Communicator in Splunk Search 01-19-2022
0 2
0
2
lucas4394
I am using "sendresults" command and pass the search results to an email body template; however, the search results d...
by lucas4394 Path Finder in Splunk Search 01-19-2022
0 0
0
0
eranhauser
I am trying to assign a value to a parameter in a macro that is based on a calculation of a value being sent to the m...
by eranhauser Path Finder in Splunk Search 01-19-2022
0 3
0
3
amask38
I have been trying to figure out why this doesn't work.|inputlookup ioc_domain.csv | table query | search NOT [inputl...
by amask38 Engager in Splunk Search 01-19-2022
0 6
0
6
drezanka
I am using Splunk Enterprise V8.2.3.2. I am trying to alert when a scheduled search becomes disabled. The problem is ...
by drezanka Explorer in Splunk Search 01-19-2022
0 4
0
4
wangkevin1029
Hi,Splunkers,I have a dashboard with 2 Panels, which share one droplist  input.droplist has  name/values  as  ALL/*, ...
by wangkevin1029 Communicator in Splunk Search 01-19-2022
0 16
0
16
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors