Splunk Search

Splunk Search
Community Activity
youngsuh
could someone who is SPL expert help me reduce this:  |eval dest=replace(dest, "dstdomain|src|any-of|dst|# ", ""), de...
by youngsuh Contributor in Splunk Search 12-03-2021
0 3
0
3
mikefisher
I have somewhat of an unwieldy log file I'm trying to wrangle. Each log entry is contained between two lines like so:...
by mikefisher New Member in Splunk Search 12-03-2021
0 1
0
1
chrisdev
Hey all,I have 2 source types with the following propertiessource_1idvaluesource_2namedescriptionSo my events might l...
by chrisdev Explorer in Splunk Search 12-03-2021
0 2
0
2
SplunkDash
Hello,How would I implement inline or Uses Transform Field extraction (please see screenshot below) for following eve...
by SplunkDash Motivator in Splunk Search 12-03-2021
0 7
0
7
SplunkNoviceUse
Hi, I am facing issues with the use of extracted fields. I intend to create a timechart with the extracted values. I...
by SplunkNoviceUse Explorer in Splunk Search 12-03-2021
0 5
0
5
plajcsi
I have a query where I get "STARTED" and "FINISHED" status events for the same methods.e.g.index IN (private public) ...
by plajcsi Engager in Splunk Search 12-03-2021
0 2
0
2
pofudukhamsi
I'm new to splunk, how can I import syslog from my local computer to splunk? - when i search it says it can be done v...
by pofudukhamsi Loves-to-Learn in Splunk Search 12-03-2021
0 1
0
1
zacksoft_wf
I have sourcetype A that has info about service_accounts such as name, AU, email , full_name, manager_name.But some o...
by zacksoft_wf Contributor in Splunk Search 12-03-2021
0 22
0
22
cadrija
Basically the chart is showing blue & green lines, but user needs more distinguishing color. Like Red & Blue. 
by cadrija Path Finder in Splunk Search 12-03-2021
0 2
0
2
Splunkster21
Hello, I have a need to run a search for MAC OUI matches against a .csv file containing 1000+ MAC OUIs? Can anyone pr...
by Splunkster21 New Member in Splunk Search 12-03-2021
0 2
0
2
srikarmohan
Hello,We are including the Pod Namespace and Pod Name in the Log Source (for K8s deployments) and would like these fi...
by srikarmohan Observer in Splunk Search 12-03-2021
0 2
0
2
SplunkDash
Hello,I have some issues extracting fields from the following raw event. I should be getting following fileds from th...
by SplunkDash Motivator in Splunk Search 12-02-2021
0 5
0
5
ssamant007
I have event data from the search result in format as shown in the image, now I want to extract the following fields ...
by ssamant007 Explorer in Splunk Search 12-02-2021
0 5
0
5
psmp
I have a dhasboard which should show buckets with number of machines by span of time. Machine A to F is used for 2 mi...
by psmp Explorer in Splunk Search 12-02-2021
0 3
0
3
daryllj
hi there!We have a daly push from Google over to our Splunk instance that provides directory information around total...
by daryllj Path Finder in Splunk Search 12-02-2021
0 2
0
2
jaydiare
I have this output from a field, with a lot of blank spaces,  what would it be the best way to convert this data into...
by jaydiare Explorer in Splunk Search 12-02-2021
0 7
0
7
israbenbr
Hello,I am posting here to know if anyone of you have an idea about the queries i have to search in order to save the...
by israbenbr Explorer in Splunk Search 12-02-2021
0 9
0
9
koreamit3483
I have data coming in where I have a field called Result which holds data as below1) "FAIL"2) " FAIL "3) "PASS"4) " P...
by koreamit3483 Explorer in Splunk Search 12-02-2021
0 3
0
3
srinivas_gowda
Hello all, I am trying to extract a field from the below event and the extraction is missing the last part of the fie...
by srinivas_gowda Path Finder in Splunk Search 12-02-2021
0 1
0
1
pkakodkar
 I have 2 independent queries run on 2 different index that give me a list of requestIds. I want to filter/not includ...
by pkakodkar Loves-to-Learn in Splunk Search 12-02-2021
0 3
0
3
SplnkUse
Hello I am running a * search in an app and it returns several columns in the csv extract where a column is named 'so...
by SplnkUse Path Finder in Splunk Search 12-02-2021
0 2
0
2
MeMilo09
Hi There, I am probably making this more confusing for myself than it needs to be, but its a simple concept.  Here is...
by MeMilo09 Path Finder in Splunk Search 12-01-2021
0 1
0
1
Mike6960
I am trying to use an eval but there is a wildcard so I noticed this does not work. Ho can I get this to work? I trie...
by Mike6960 Path Finder in Splunk Search 12-01-2021
0 6
0
6
CMSchelin
I'm running this search: | rest/servicesNS/-/-/saved/searches | search disabled=0 AND is_scheduled=1 AND eai:acl.sha...
by CMSchelin Path Finder in Splunk Search 12-01-2021
2 1
2
1
viksvig
I have splunk search - index=cloud EventName: "Error Occurred" XChangeToSalesForce | rename message as "Message" _tim...
by viksvig Loves-to-Learn Lots in Splunk Search 12-01-2021
0 8
0
8
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...