Splunk Search

Splunk Search
Community Activity
indeed_2000
HiI have 4 huge log file that ingest into the Splunk File1File2File3File4 Now i want to know when i search specific s...
by indeed_2000 Motivator in Splunk Search 12-09-2021
0 1
0
1
michel_wolf
Hello guys, I have a problem with the "Cluster Map" so I have add a log 2 weeks ago and when I do a search about the...
by michel_wolf Path Finder in Splunk Search 12-08-2021
1 3
1
3
Jason
I am using transforms.conf to pull the sourcetype from the source via a complex regex. It doesn't seem to be working,...
by Jason Motivator in Splunk Search 12-08-2021
2 8
2
8
mwhitake78
Is there any easy way to enable/disable indexing of a debug log file so that it can be indexed only when needed? We h...
by mwhitake78 Explorer in Splunk Search 12-08-2021
0 6
0
6
blablabla
Hello,I would like to ask, if it is possible to pass a time restriction to a subsearch of an join ? Unfortunately I d...
by blablabla Path Finder in Splunk Search 12-08-2021
0 10
0
10
VijaySrrie
Hi,What are the 4 important attributes to be considered under distsearch.conf
by VijaySrrie Builder in Splunk Search 12-08-2021
0 2
0
2
cadrija
I have data in source which shows Y/N for fields investor, borrower, guarantor, benefic for each customer. Need to sh...
by cadrija Path Finder in Splunk Search 12-08-2021
0 2
0
2
jbanAtSplunk
The search you ran returned a number of fields that exceeded the current indexed field extraction limit='200'To ensur...
by jbanAtSplunk Communicator in Splunk Search 12-08-2021
0 0
0
0
incoghnito_1
Hi every one I have some difficulty to count my consumedHostUnits I have this commande : index="dynatrace_hp" | searc...
by incoghnito_1 Engager in Splunk Search 12-08-2021
0 2
0
2
pkharbanda1021
Splunk Queryindex="abc" source=def[| inputlookup ABC.csv | table text_strings count | rename text_strings as search]P...
by pkharbanda1021 Engager in Splunk Search 12-07-2021
0 16
0
16
kapoorsumit2020
Hi,I am providing sample data below:[2021-12-07 03:50:14,666] {<!-- -->{taskinstance.py:1532}} INFO - Marking task as FAILED....
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-07-2021
0 2
0
2
dsb6
I have a base search:index&#61;oswin EventCode&#61;19 SourceName&#61;"Microsoft-Windows-WindowsUpdateClient" earliest&#61;-10d Comput...
by dsb6 Loves-to-Learn Lots in Splunk Search 12-07-2021
0 6
0
6
saraque
Hi everyone, Recently, I have tried to install the OCI addon in a test enviroment but it does not work. According to ...
by saraque Observer in Splunk Search 12-07-2021
0 0
0
0
RedHonda03
I have a search which looks at rare events in Windows Event Logs and provides output shown below.source&#61;"winevtlog:se...
by RedHonda03 Explorer in Splunk Search 12-07-2021
0 1
0
1
pkharbanda1021
I am using the following query and trying to display the results using stats but count by field valuessearch query | ...
by pkharbanda1021 Engager in Splunk Search 12-07-2021
0 7
0
7
lostcauz3
i have a query likeindex &#61; xyz| eval assignment&#61; upper(assignment)| eval SO &#61; upper(SO)| eval Ser &#61; upper(Ser)| join ...
by lostcauz3 Path Finder in Splunk Search 12-07-2021
0 7
0
7
SCMsplConfig
When using the Expand your search feature, the Expanded Search String output is stripped of any custom formatting, pa...
by SCMsplConfig Engager in Splunk Search 12-07-2021
1 2
1
2
dylanhess
I am trying to extract the action&#61;* from this field, in this event its add. I've trying extracting through how you wo...
by dylanhess Engager in Splunk Search 12-07-2021
0 2
0
2
shashank_24
Hi, I've been reading number of posts about how to extract the OS and browser details but I don't think there is a be...
by shashank_24 Path Finder in Splunk Search 12-07-2021
0 5
0
5
sarit_s
HelloI have a table with user gcid and user score and i want to show it as a bar chart so the Xis will be the gcid nu...
by sarit_s Communicator in Splunk Search 12-07-2021
0 2
0
2
jshanaiah
using tmechart command , I want to display values of 7 filds.. i don't want to use avg, sum functions.. just i want t...
by jshanaiah Explorer in Splunk Search 12-07-2021
0 3
0
3
cadrija
My current querysource&#61;"VLS_OUTSTANDING_GEO.csv" host&#61;"dev-bnk-loaniq-" sourcetype&#61;"csv" | geostats latfield&#61;AREA_LAT...
by cadrija Path Finder in Splunk Search 12-07-2021
0 0
0
0
neerajs_81
Hello All,  We currently use the following search to list all the Windows hosts in our environment.   | tstats dc(hos...
by neerajs_81 Builder in Splunk Search 12-07-2021
0 4
0
4
meera
Hi,I am using earliest and latest in sub search to get last 24 hrs data and compare it with last 7 days data to know ...
by meera New Member in Splunk Search 12-06-2021
0 1
0
1
indeed_2000
HiHope you are well,I want to use splunk-agent-java and read description of this pagehttps://github.com/splunk/splunk...
by indeed_2000 Motivator in Splunk Search 12-06-2021
0 0
0
0
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...