Splunk Search

Splunk Search
Community Activity
MidnightRun
I'm trying to write a search that will return a table where all average values of the field price grouped by Ids are ...
by MidnightRun Explorer in Splunk Search 12-04-2021
0 7
0
7
MidnightRun
I have a search query that looks like this: index="myindex" sourcetype="mysource" earliest=@d latest=now | append [...
by MidnightRun Explorer in Splunk Search 12-04-2021
0 1
0
1
martinhelgegren
Hi! Been struggling a lot with a pretty simple problem but my SPLUNK REX skills are insufficient for the task. I want...
by martinhelgegren Explorer in Splunk Search 12-04-2021
0 8
0
8
anjihari
I have the first queryFirst Query :     search criteria | rex field=_raw ".* IPAddress=(?<IPAddress>.+?) " | table IP...
by anjihari Observer in Splunk Search 12-03-2021
0 1
0
1
israbenbr
Hello everyone,I am trying to create queries to show the max and average values of inbound and outbound network traff...
by israbenbr Explorer in Splunk Search 12-03-2021
0 1
0
1
youngsuh
could someone who is SPL expert help me reduce this:  |eval dest=replace(dest, "dstdomain|src|any-of|dst|# ", ""), de...
by youngsuh Contributor in Splunk Search 12-03-2021
0 3
0
3
mikefisher
I have somewhat of an unwieldy log file I'm trying to wrangle. Each log entry is contained between two lines like so:...
by mikefisher New Member in Splunk Search 12-03-2021
0 1
0
1
chrisdev
Hey all,I have 2 source types with the following propertiessource_1idvaluesource_2namedescriptionSo my events might l...
by chrisdev Explorer in Splunk Search 12-03-2021
0 2
0
2
SplunkDash
Hello,How would I implement inline or Uses Transform Field extraction (please see screenshot below) for following eve...
by SplunkDash Motivator in Splunk Search 12-03-2021
0 7
0
7
SplunkNoviceUse
Hi, I am facing issues with the use of extracted fields. I intend to create a timechart with the extracted values. I...
by SplunkNoviceUse Explorer in Splunk Search 12-03-2021
0 5
0
5
plajcsi
I have a query where I get "STARTED" and "FINISHED" status events for the same methods.e.g.index IN (private public) ...
by plajcsi Engager in Splunk Search 12-03-2021
0 2
0
2
pofudukhamsi
I'm new to splunk, how can I import syslog from my local computer to splunk? - when i search it says it can be done v...
by pofudukhamsi Loves-to-Learn in Splunk Search 12-03-2021
0 1
0
1
zacksoft_wf
I have sourcetype A that has info about service_accounts such as name, AU, email , full_name, manager_name.But some o...
by zacksoft_wf Contributor in Splunk Search 12-03-2021
0 22
0
22
cadrija
Basically the chart is showing blue & green lines, but user needs more distinguishing color. Like Red & Blue. 
by cadrija Path Finder in Splunk Search 12-03-2021
0 2
0
2
Splunkster21
Hello, I have a need to run a search for MAC OUI matches against a .csv file containing 1000+ MAC OUIs? Can anyone pr...
by Splunkster21 New Member in Splunk Search 12-03-2021
0 2
0
2
srikarmohan
Hello,We are including the Pod Namespace and Pod Name in the Log Source (for K8s deployments) and would like these fi...
by srikarmohan Observer in Splunk Search 12-03-2021
0 2
0
2
SplunkDash
Hello,I have some issues extracting fields from the following raw event. I should be getting following fileds from th...
by SplunkDash Motivator in Splunk Search 12-02-2021
0 5
0
5
ssamant007
I have event data from the search result in format as shown in the image, now I want to extract the following fields ...
by ssamant007 Explorer in Splunk Search 12-02-2021
0 5
0
5
psmp
I have a dhasboard which should show buckets with number of machines by span of time. Machine A to F is used for 2 mi...
by psmp Explorer in Splunk Search 12-02-2021
0 3
0
3
daryllj
hi there!We have a daly push from Google over to our Splunk instance that provides directory information around total...
by daryllj Path Finder in Splunk Search 12-02-2021
0 2
0
2
jaydiare
I have this output from a field, with a lot of blank spaces,  what would it be the best way to convert this data into...
by jaydiare Explorer in Splunk Search 12-02-2021
0 7
0
7
israbenbr
Hello,I am posting here to know if anyone of you have an idea about the queries i have to search in order to save the...
by israbenbr Explorer in Splunk Search 12-02-2021
0 9
0
9
koreamit3483
I have data coming in where I have a field called Result which holds data as below1) "FAIL"2) " FAIL "3) "PASS"4) " P...
by koreamit3483 Explorer in Splunk Search 12-02-2021
0 3
0
3
srinivas_gowda
Hello all, I am trying to extract a field from the below event and the extraction is missing the last part of the fie...
by srinivas_gowda Path Finder in Splunk Search 12-02-2021
0 1
0
1
pkakodkar
 I have 2 independent queries run on 2 different index that give me a list of requestIds. I want to filter/not includ...
by pkakodkar Loves-to-Learn in Splunk Search 12-02-2021
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...