Splunk Search

Splunk Search
Community Activity
LolabhattuA
My file contains a line at the last where it mentions the return code. The format look like below mentioned. If the j...
by LolabhattuA Loves-to-Learn in Splunk Search 01-23-2022
0 4
0
4
feelcool
Hello,everyone!At first, sorry for my bad English.I have a problem to join two result.The raw data is a reg file, lik...
by feelcool Explorer in Splunk Search 01-22-2022
0 7
0
7
jbrenner
I have a Splunk query that does a lot of computation and eventually returns only two calculated fields:  _time and ST...
by jbrenner Path Finder in Splunk Search 01-22-2022
0 3
0
3
roopeshetty
Hi Guys I have a query like this <query>| stats avg(CurrentConnections) as CC by host  And the output is as below wit...
by roopeshetty Path Finder in Splunk Search 01-22-2022
0 3
0
3
dsmith
I'm trying to get a new sourcetype (NetApp user-level audit logs, exported as XML) to work, and I think my fields.con...
by dsmith Path Finder in Splunk Search 01-22-2022
0 12
0
12
dasaed
I have a JSON with a field containing another object, but this object varies depending on type. For example, you may ...
by dasaed Explorer in Splunk Search 01-22-2022
0 3
0
3
jbrenner
I have a transaction command which correlates two log entries. If I pipe this result into a timechart command, which ...
by jbrenner Path Finder in Splunk Search 01-21-2022
0 2
0
2
Razziq
Hello,I have a script gathering the last updated timestamp of three different files and I'm ingesting that data into ...
by Razziq Explorer in Splunk Search 01-21-2022
0 1
0
1
steen
Hi,In the past (Splunk Enterprise v 7.x.x) I used the below search to run a report every few min. There were so many ...
by steen Explorer in Splunk Search 01-21-2022
0 5
0
5
parkertctr
I am trying to use the case match command with more than one option. I keep getting an error message regarding the pa...
by parkertctr Path Finder in Splunk Search 01-21-2022
0 2
0
2
andres
I have a raw where each event looks like this (simplified for this exampel):{"time": "2022-01-20 16:40:02.325216", "n...
by andres Loves-to-Learn Lots in Splunk Search 01-21-2022
0 2
0
2
Ashwini_5
I would like to count the multifield in the table where it has similar values. For Ex:  I need output like below for ...
by Ashwini_5 Explorer in Splunk Search 01-21-2022
0 2
0
2
nate_washburn
Hi, in my index I have a couple time fields that are returned via a simple search_time = 1/20/2022 1:38:55.000 PM (th...
by nate_washburn Engager in Splunk Search 01-21-2022
0 2
0
2
danielbb
We would like to ingest the Oracle's UNIFIED_AUDIT_TRAIL table and the SQL server's MSSQL\SQLAudit\*.sqlaudit files.H...
by danielbb Motivator in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log entries, I wanted to extract uri in a specific format:log: a_level="INFO", a_time="null", a_t...
by nbhat Explorer in Splunk Search 01-21-2022
0 1
0
1
alexandrebas
I need help regarding comparise a ISO 8601 date field with a specific date.Below is a simple example:index=devices | ...
by alexandrebas Explorer in Splunk Search 01-21-2022
0 1
0
1
zacksoft_wf
I have,sourcetype_A  (fields : ID, age, city, state)sourcetype_B  (fields : ID, job, salary, gender)The fields "ID" i...
by zacksoft_wf Contributor in Splunk Search 01-21-2022
0 2
0
2
nbhat
Hi,In the following log, I wanted to extract Url, Method, ResponseTimeMs, StatusCode as a table:log: a_level="INFO", ...
by nbhat Explorer in Splunk Search 01-21-2022
0 2
0
2
robertlynch2020
Is Type=Left the same as type=outer in Splunk? If so why do they list it as three options?https://docs.splunk.com/Doc...
by robertlynch2020 Influencer in Splunk Search 01-20-2022
0 2
0
2
jasonmhamilton
Hello,I was wondering if it is possible to use Splunk to query IIS logs for a monthly application hit count for multi...
by jasonmhamilton New Member in Splunk Search 01-20-2022
0 3
0
3
zebulajams
Hey all,Newbie here learning Splunk. I'm starting to get into dashboards and want to create either a pie chart or jus...
by zebulajams Explorer in Splunk Search 01-20-2022
0 5
0
5
awmorris
I've been trying to resolve this since October and not getting traction.  Turning to the community for help:I have se...
by awmorris Path Finder in Splunk Search 01-20-2022
0 0
0
0
EvansB
   I would like to get the list of those items in the properties field, like appName, levelId, etc.  
by EvansB Path Finder in Splunk Search 01-20-2022
0 4
0
4
majid87
Hello,Looks like the action field is not returning results for almost all of the indexes. This is only impacting one ...
by majid87 Engager in Splunk Search 01-20-2022
0 4
0
4
Flaxamax
Hello Splunk Community,I'm fairly new to splunk and am using it to search and alert me for testing failures in my man...
by Flaxamax Engager in Splunk Search 01-20-2022
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...