Splunk Search

Splunk Search
Community Activity
adoumbia
I am trying to write an spl query to detect an event of a single source IP address  or a user fails multiple time to ...
by adoumbia Engager in Splunk Search 11-27-2024
0 4
0
4
darkins
fieldA:1:10 fieldB:1:3 fieldC:1:2fieldA:1:10 fieldC:1:2fieldA:1:10 fieldC:1:2fieldC:1:1 I want to end up with a field...
by darkins Engager in Splunk Search 11-27-2024
0 5
0
5
santhipriya
I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of sear...
by santhipriya Engager in Splunk Search 11-27-2024
0 4
0
4
Crotyo
I have a csv file like this that contain more than 100 numbers 111111112222222233333333 I want to search for events t...
by Crotyo Observer in Splunk Search 11-26-2024
0 9
0
9
hulahoop
Let's say I have events A and B: A -- Feb 1 2010 10:10:00 field1=foo field2=bar B -- Feb 1 2010 10:10:01 field1=foo ...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 11-26-2024
3 15
3
15
thrtnastrx
When I search I want to show the top results by a specific field "field1" and also show "field2" and "field3". Proble...
by thrtnastrx Observer in Splunk Search 11-25-2024
0 3
0
3
Aithnave
Hey Splunk team, I’m facing an issue where Splunk fails to search for certain key-value pairs in some events unless I...
by Aithnave Engager in Splunk Search 11-25-2024
0 3
0
3
SplunkUser001
Hello, I have the following query to search Proofpoint logs.  index=ppoint_prod host=*host1* | eval time=strftime(_ti...
by SplunkUser001 Explorer in Splunk Search 11-25-2024
0 11
0
11
mariojost
We search thru the logs of switches and there are some logs that are unconcerning if you just have a couple of them l...
by mariojost Engager in Splunk Search 11-25-2024
0 6
0
6
darkins
probably an easy one, i have two events as follows thisisfield1 thisisfield2 mynextfield3thisisfield1 mynextfield3mea...
by darkins Engager in Splunk Search 11-25-2024
0 7
0
7
campbellwarren
I understand that tstats will only work with indexed fields, not extracted fields. How can I determine which fields ...
by campbellwarren Engager in Splunk Search 11-24-2024
0 5
0
5
scout29
Need help to extract a field that comes after a certain word in a event. I am looking to extract a field called "sn_g...
by scout29 Path Finder in Splunk Search 11-22-2024
0 3
0
3
Brad
We are trying to watch the NIC statistics for our OS interfaces.  We are gathering data from a simple ifconfig eth0 |...
by Brad Explorer in Splunk Search 11-22-2024
0 6
0
6
vm_molson
I am trying to figure out how to include a lookup in my search, but only some records. My current search is below. My...
by vm_molson Explorer in Splunk Search 11-21-2024
0 1
0
1
robertlynch2020
Hi I have the below code to produce this table - but does anyone know how to get rid of the part in red (I have added...
by robertlynch2020 Influencer in Splunk Search 11-21-2024
0 5
0
5
uagraw01
Hello Splunkers!!We have events that contains source and destination fields with complete values, and we want to matc...
by uagraw01 Motivator in Splunk Search 11-21-2024
0 3
0
3
ecnausysadm
I have searches for two files that are related but the incoming and outgoing file names differ, basically it's an inc...
by ecnausysadm Explorer in Splunk Search 11-21-2024
0 3
0
3
gajananh999
Hello Everyone, I have events like 02-Jul-2014 09:25:25 AM: ========== Finish Transmit Process ========== 02-Ju...
by gajananh999 Contributor in Splunk Search 11-21-2024
0 3
0
3
tlunruh
When I run this query: index=edi-2 | join type=inner TRACKINGNUMBER [search index=edi | rename TRCK AS TRACKINGNUMBER...
by tlunruh New Member in Splunk Search 11-21-2024
0 3
0
3
dmrhodes101
We're using Splunk to monitor EDI traffic onto our backend system. We want to have a single value panel that shows gr...
by dmrhodes101 Explorer in Splunk Search 11-21-2024
1 3
1
3
mbasharat
Hi, I have a simple search which is using a lookup definition based off of a lookup. This lookup is large. Search has...
by mbasharat Builder in Splunk Search 11-20-2024
0 3
0
3
mrsampson
The structure of JSON in my log events is roughly as follows  { "Info": { "Apps": { "Reportin...
by mrsampson Explorer in Splunk Search 11-19-2024
0 2
0
2
NanSplk01
This is my search.  I brings back Not Known for every field instead of the correct case name:index=websphere webspher...
by NanSplk01 Communicator in Splunk Search 11-19-2024
0 3
0
3
majilan1
Hi Splunkers, any help with Rex has exceeded configured match_limit, consider raising the value in limits.conf.My sea...
by majilan1 Path Finder in Splunk Search 11-18-2024
1 4
1
4
ameyad
I am trying to create a dashboard. It has two input text fields.I want to run a search query based on these two input...
by ameyad Engager in Splunk Search 11-18-2024
1 1
1
1
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...
Top Solution Authors