Splunk Search

Splunk Search
Community Activity
Sarvoday
0
1
phamxuantung
I try to use the query eval ID = if(ORG="MC",ID=substr(ID,-6),0) Basically, I want in my result, if ORG="MC", I want ...
by phamxuantung Communicator in Splunk Search 12-13-2021
0 1
0
1
kapoorsumit2020
Team,I'm newbie in writing Splunk queries. Could you please provide me guidance how to design a SPL for below use cas...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-13-2021
0 7
0
7
AndreiIssakov
Hello!Could somebody please suggest if it is possible to do a map search search more effectively?What I am trying to ...
by AndreiIssakov Explorer in Splunk Search 12-13-2021
0 6
0
6
tkw03
Hello, As an admin, I tried to delete a lookup table file. I had copied all the apps back to the search head cluster...
by tkw03 Communicator in Splunk Search 12-13-2021
2 3
2
3
pk87
We save hash values from our ids and I want to search for them. I would expected I can do it this way:index=blub id=s...
by pk87 Engager in Splunk Search 12-13-2021
0 9
0
9
Narendra045
Hi,I have two tables and in first table it contains 13 columns and from second table only one column i need to add to...
by Narendra045 Explorer in Splunk Search 12-13-2021
0 3
0
3
nateNpgh
When running the following search for a 24hr period it is always being auto-finalized due to disk usage limit of 100M...
by nateNpgh Loves-to-Learn Lots in Splunk Search 12-13-2021
0 13
0
13
lostcauz3
 TYPEMonthKPI_1KPI_2GLOBALOct'217624LOCALOct'214667 I'm searching the table like | search TYPE="GLOBAL" | search Mont...
by lostcauz3 Path Finder in Splunk Search 12-12-2021
0 2
0
2
GRC
Hi there,I have 2 separate queries that I built using Rex.1. This query captures the logg on and logg off status of t...
by GRC Path Finder in Splunk Search 12-11-2021
0 2
0
2
GindiKhangura
I am encountering an issue when using a subsearch in a tstats query. Specifically, I am seeing the count of events in...
by GindiKhangura Explorer in Splunk Search 12-10-2021
0 3
0
3
splunk3341
Hi, hoping to get some more insight on my current problem. My problem is the following I am using a where clause to c...
by splunk3341 Loves-to-Learn Lots in Splunk Search 12-10-2021
0 2
0
2
jackjack
I am attempting to use a search from IT Essentials Learn named "Alert when host stops reporting data - Linux - IT Ess...
by jackjack Path Finder in Splunk Search 12-10-2021
0 3
0
3
psmp
RAWDATA:user_namemachine_nameevent_namelogon_timeuser1machine1logon12/9/2021 7:20user1machine1logout12/9/2021 7:22use...
by psmp Explorer in Splunk Search 12-10-2021
0 10
0
10
giorgioanastasi
Hi, I would have this need, that is to carry out a search that extracts all users who use iphone with SO = 9. * and t...
by giorgioanastasi Explorer in Splunk Search 12-10-2021
0 7
0
7
radi09
Hi everyone, I'm new here and having a problem filtering of numbers from a message. message: Generated non direct de...
by radi09 Engager in Splunk Search 12-10-2021
0 7
0
7
marceloalejandr
Aloha, We’ve a reporting requirement to create a Pie chart using 2 input files.  So far we’ve successfully created Ba...
by marceloalejandr Path Finder in Splunk Search 12-10-2021
0 9
0
9
indeed_2000
Need to declare in spl Include only those file that has ended with date not .bz2 (I don’t want to use  NOT) Here is s...
by indeed_2000 Motivator in Splunk Search 12-10-2021
0 3
0
3
geomore
Hi,I'm trying to get wildcard lookups to work using the "lookup" function. I've followed guidance to set up the "Matc...
by geomore Explorer in Splunk Search 12-10-2021
0 7
0
7
usd0872
I hate hardcoding dynamic things. Sooner or later those thing break. I have data with fields ... forecast_2020=400, f...
by usd0872 Path Finder in Splunk Search 12-10-2021
0 4
0
4
PickleRick
Hello there.I was wondering... is there any way to generate _events_ in search?I mean, I know of the makeresults comm...
by SplunkTrust SplunkTrust in Splunk Search 12-10-2021
0 6
0
6
psmp
| makeresults| eval _raw = "user_name machine_name event_name logon_timeuser1 machine1 logon 12/9/2021 7:20user1 mach...
by psmp Explorer in Splunk Search 12-09-2021
0 3
0
3
Alanshiau717
Hey I am having difficulties trying to extract fields from my splint logs. They are in the format of’{“field”: “value...
by Alanshiau717 New Member in Splunk Search 12-09-2021
0 1
0
1
VijaySrrie
Hi,When we use sedcmd command to mask data it is Indexed time extractions and when we use transforms to mask data it ...
by VijaySrrie Builder in Splunk Search 12-09-2021
0 2
0
2
rhilderbrand1
I have a date column that I'm trying to convert to %m/%d/%Y. The date stamp is a little complex but I got it to work ...
by rhilderbrand1 Observer in Splunk Search 12-09-2021
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...