Splunk Search

Splunk Search
Community Activity
SplnkUse
HelloI am a Splunk user, not admin, and I seem to be able to do a search like:| rest splunk_server=local servicesNS/-...
by SplnkUse Path Finder in Splunk Search 12-14-2021
0 0
0
0
shreyasamin64
need help on using command strptime/strftime EX: input: December 7, 2021 1:00:01 PM         output: 12/1/2021   13:00...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 2
0
2
shreyasamin64
need help on removing only endpoint from the data set input :                                                        ...
by shreyasamin64 Explorer in Splunk Search 12-14-2021
0 1
0
1
09128028400
Hello every bodyI have been struggling with a serious problem recently my splunk version is 7.2 when I use  span Comm...
by 09128028400 Engager in Splunk Search 12-14-2021
0 6
0
6
amagson
Hello all,I need a hand with a basic Splunk search. I appreciate this is Splunk 101 basics, but with other commitment...
by amagson Loves-to-Learn in Splunk Search 12-14-2021
0 2
0
2
rxalex
Hi Folks, I have been trying to pull some data associated with latest Run ID (associated with execution), I am having...
by rxalex Engager in Splunk Search 12-14-2021
0 2
0
2
poiromaniax
Hey all,Firstly - the title doesnt actually encapsulate what Im trying to do, Ill try break it down simply:I have AWS...
by poiromaniax Explorer in Splunk Search 12-13-2021
0 2
0
2
Sarvoday
0
1
phamxuantung
I try to use the query eval ID = if(ORG="MC",ID=substr(ID,-6),0) Basically, I want in my result, if ORG="MC", I want ...
by phamxuantung Communicator in Splunk Search 12-13-2021
0 1
0
1
kapoorsumit2020
Team,I'm newbie in writing Splunk queries. Could you please provide me guidance how to design a SPL for below use cas...
by kapoorsumit2020 Loves-to-Learn Everything in Splunk Search 12-13-2021
0 7
0
7
AndreiIssakov
Hello!Could somebody please suggest if it is possible to do a map search search more effectively?What I am trying to ...
by AndreiIssakov Explorer in Splunk Search 12-13-2021
0 6
0
6
tkw03
Hello, As an admin, I tried to delete a lookup table file. I had copied all the apps back to the search head cluster...
by tkw03 Communicator in Splunk Search 12-13-2021
2 3
2
3
pk87
We save hash values from our ids and I want to search for them. I would expected I can do it this way:index=blub id=s...
by pk87 Engager in Splunk Search 12-13-2021
0 9
0
9
Narendra045
Hi,I have two tables and in first table it contains 13 columns and from second table only one column i need to add to...
by Narendra045 Explorer in Splunk Search 12-13-2021
0 3
0
3
nateNpgh
When running the following search for a 24hr period it is always being auto-finalized due to disk usage limit of 100M...
by nateNpgh Loves-to-Learn Lots in Splunk Search 12-13-2021
0 13
0
13
lostcauz3
 TYPEMonthKPI_1KPI_2GLOBALOct'217624LOCALOct'214667 I'm searching the table like | search TYPE="GLOBAL" | search Mont...
by lostcauz3 Path Finder in Splunk Search 12-12-2021
0 2
0
2
GRC
Hi there,I have 2 separate queries that I built using Rex.1. This query captures the logg on and logg off status of t...
by GRC Path Finder in Splunk Search 12-11-2021
0 2
0
2
GindiKhangura
I am encountering an issue when using a subsearch in a tstats query. Specifically, I am seeing the count of events in...
by GindiKhangura Explorer in Splunk Search 12-10-2021
0 3
0
3
splunk3341
Hi, hoping to get some more insight on my current problem. My problem is the following I am using a where clause to c...
by splunk3341 Loves-to-Learn Lots in Splunk Search 12-10-2021
0 2
0
2
jackjack
I am attempting to use a search from IT Essentials Learn named "Alert when host stops reporting data - Linux - IT Ess...
by jackjack Path Finder in Splunk Search 12-10-2021
0 3
0
3
psmp
RAWDATA:user_namemachine_nameevent_namelogon_timeuser1machine1logon12/9/2021 7:20user1machine1logout12/9/2021 7:22use...
by psmp Explorer in Splunk Search 12-10-2021
0 10
0
10
giorgioanastasi
Hi, I would have this need, that is to carry out a search that extracts all users who use iphone with SO = 9. * and t...
by giorgioanastasi Explorer in Splunk Search 12-10-2021
0 7
0
7
radi09
Hi everyone, I'm new here and having a problem filtering of numbers from a message. message: Generated non direct de...
by radi09 Engager in Splunk Search 12-10-2021
0 7
0
7
marceloalejandr
Aloha, We’ve a reporting requirement to create a Pie chart using 2 input files.  So far we’ve successfully created Ba...
by marceloalejandr Path Finder in Splunk Search 12-10-2021
0 9
0
9
indeed_2000
Need to declare in spl Include only those file that has ended with date not .bz2 (I don’t want to use  NOT) Here is s...
by indeed_2000 Motivator in Splunk Search 12-10-2021
0 3
0
3
Get Updates on the Splunk Community!

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...
Top Solution Authors