Splunk Search

Splunk Search
Community Activity
shrinivaskittur
Hi,I need help in evaluation the csv files under "<Splunk directory>\etc\apps\search\lookups" folder. we have multipl...
by shrinivaskittur Explorer in Splunk Search 01-02-2022
0 4
0
4
splunk_luis12
Hi all, I'm trying to find the specific queries for the SH to create Splunk dashboard of the following info (example)...
by splunk_luis12 Path Finder in Splunk Search 01-02-2022
0 2
0
2
bcanfield83
Hello,I'm attempting to use the regex command to filter out any records on the "user" field that do not match the wri...
by bcanfield83 Engager in Splunk Search 01-02-2022
0 3
0
3
eranhauser
How do I pair events 4778 & 4779 for the same Logon_ID when I have multi 4778 and multi 4779?I would like to pair the...
by eranhauser Path Finder in Splunk Search 12-31-2021
0 1
0
1
sumitp10797
   Provide details about client purchase details          1. Total purchase split by product ID         2. Total Prod...
by sumitp10797 New Member in Splunk Search 12-31-2021
0 2
0
2
incognito
Hello, My Splunk query an API and gets a JSON answer.Here is a sample for 1 Host (the JSON answer is very long ≈ 400 ...
by incognito Explorer in Splunk Search 12-31-2021
0 6
0
6
SplnkUse
HelloI want to feed data directly into Excel but I do not have API access nor I can install custom connectors.Is ther...
by SplnkUse Path Finder in Splunk Search 12-31-2021
0 2
0
2
bazcurtis178
Hi,My search result brings back a GUID in the ID field. The GUID refers to a customer. I would like it to reflect the...
by bazcurtis178 Explorer in Splunk Search 12-31-2021
0 9
0
9
sagar_shubham
Hi Team,  Need your help in creating regex to create a field. "User_Claim":("sub":"qweihaytej"; "login_id":"Abc@domai...
by sagar_shubham Explorer in Splunk Search 12-30-2021
0 4
0
4
SplnkUse
HelloIf now, it is 30/12/2021 22:30, how can I search for timestamps from 29/12/2021 00:00:00 (i.e. beginning of 29/1...
by SplnkUse Path Finder in Splunk Search 12-30-2021
0 2
0
2
MelnikovTimofey
I use this guide to deploy my search head cluster. When I try to bring up the cluster captain (step 5): /opt/splunk...
by MelnikovTimofey New Member in Splunk Search 12-30-2021
0 4
0
4
Brainstorms
I have looked for solutions but I have mostly found results regarding only current and past time comparison which is ...
by Brainstorms Explorer in Splunk Search 12-30-2021
0 2
0
2
MarsBar
Hey all,Just started learning Splunk this week, interesting so far. How can I sort the top header from lowest to high...
by MarsBar Engager in Splunk Search 12-30-2021
1 5
1
5
sonicZ
Hello,Looking for some assistance in reconstructing my query, which is currently using | transaction with a traceId v...
by sonicZ Contributor in Splunk Search 12-30-2021
1 6
1
6
neerajs_81
Hello,  I am using the below query to output which of our Searches/Rules are mapped to which Mitre Technique IDs. | i...
by neerajs_81 Builder in Splunk Search 12-29-2021
0 3
0
3
drew_eckhardt
I want to look for requests in a service mesh ingest log which have no corresponding application log entries.My first...
by drew_eckhardt Engager in Splunk Search 12-29-2021
1 3
1
3
Ashwini_5
Hello Experts,  Kindly help to filter out latest one year date for the particular field. For ex:  index="abc" sourcet...
by Ashwini_5 Explorer in Splunk Search 12-29-2021
0 1
0
1
MarsBar
Hey all,I've got an interview and I need to show some level of competency at using Splunk, I'm doing a short presenta...
by MarsBar Engager in Splunk Search 12-29-2021
0 1
0
1
Mick_OBrien
I have a search string that details the last log entry for all running jobs [shown in ascending order] bar a few jobs...
by Mick_OBrien Path Finder in Splunk Search 12-29-2021
0 1
0
1
shanaz
Hi,want to create a search to find anyone who does changes to the sAMAccountName So sAMAccountName could be sAMAccoun...
by shanaz Engager in Splunk Search 12-29-2021
0 1
0
1
brcox9090
I am probably asking the most basic question ever, but I'm new to Splunk and just trying to figure out my host url. E...
by brcox9090 New Member in Splunk Search 12-28-2021
0 2
0
2
jerinvarghese
Hi All,I have a code, that uses the output to fetch data from another Panel.First Panel <title>Juniper Mnemonics</tit...
by jerinvarghese Communicator in Splunk Search 12-28-2021
0 2
0
2
johnhuang
Is there a way to remove or relocate the floating "Splunk Product Guidance" button that appears on the lower right of...
by johnhuang Motivator in Splunk Search 12-28-2021
0 3
0
3
Trex1
Hi there,I've set up a dashboard with various columns, one of them outputs a  number field which has a comma(,) in it...
by Trex1 Explorer in Splunk Search 12-28-2021
0 2
0
2
gamedazed
Background:I'm working on a form that associates Qualys vulnerability IDs with CVE IDs. I'm leveraging two lookup tab...
by gamedazed New Member in Splunk Search 12-28-2021
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...