Splunk Search

Splunk Search
Community Activity
inmanr
Using the below sample search I'm trying to get every possible combination of results between two different sets of d...
by inmanr Engager in Splunk Search 12-02-2024
0 1
0
1
tdavison76
Hello,I need help on passing a field value from a Dashboard table into a "Link to search" drilldown but can't figure ...
by tdavison76 Path Finder in Splunk Search 12-02-2024
0 9
0
9
Newb_KB
I recently migrated from v8 to v9 for Splunk and I am having issues with ldapsearch not returning data that it had pr...
by Newb_KB Loves-to-Learn in Splunk Search 12-02-2024
0 5
0
5
PotatoDataUser
So I want to build a dashboard with _introspection index , some of the metrics I am looking for are THP (enabled/disa...
by PotatoDataUser Explorer in Splunk Search 12-02-2024
0 2
0
2
tdavison76
Hello everyone,I am terrible at regex,  I am trying to regex a field called "alert.message" to create another field w...
by tdavison76 Path Finder in Splunk Search 12-02-2024
0 4
0
4
Sailesh6891
Hi, I have a log file on the server which I ingested in splunk through input app where I defined the index , sourcety...
by Sailesh6891 Engager in Splunk Search 12-02-2024
0 3
0
3
karthi2809
How to filter events in the dashboard with help of search box.In the search box i have to give multiple strings like ...
by karthi2809 Builder in Splunk Search 12-01-2024
0 7
0
7
Cheng2Ready
index=test pod=poddy1 "severity"="INFO" "message"="IamExample*" | rex field=message "IamExample(?<total>).*" | ...
by Cheng2Ready Communicator in Splunk Search 11-29-2024
0 1
0
1
Jyo_Reel
Hi Team,I can see events related to all hosts in internal index but the only few hosts data is available in newly cre...
by Jyo_Reel Engager in Splunk Search 11-29-2024
0 2
0
2
devsru
Hi All,I am running a dashboard which returns the total count(stats count) of field mentioning Severity=ok or Severit...
by devsru Explorer in Splunk Search 11-28-2024
0 32
0
32
gauravkumar85
 I have dataset which have field INSERT_DATE now i want to perform search based the date which is match with Global T...
by gauravkumar85 Path Finder in Splunk Search 11-28-2024
0 5
0
5
sfmandmdev
What is the difference between lastTime and recentTime in a metadata search?
by sfmandmdev Path Finder in Splunk Search 11-28-2024
2 4
2
4
adoumbia
I am trying to write an spl query to detect an event of a single source IP address  or a user fails multiple time to ...
by adoumbia Engager in Splunk Search 11-27-2024
0 4
0
4
darkins
fieldA:1:10 fieldB:1:3 fieldC:1:2fieldA:1:10 fieldC:1:2fieldA:1:10 fieldC:1:2fieldC:1:1 I want to end up with a field...
by darkins Engager in Splunk Search 11-27-2024
0 5
0
5
santhipriya
I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of sear...
by santhipriya Engager in Splunk Search 11-27-2024
0 4
0
4
Crotyo
I have a csv file like this that contain more than 100 numbers 111111112222222233333333 I want to search for events t...
by Crotyo Observer in Splunk Search 11-26-2024
0 9
0
9
hulahoop
Let's say I have events A and B: A -- Feb 1 2010 10:10:00 field1=foo field2=bar B -- Feb 1 2010 10:10:01 field1=foo ...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 11-26-2024
3 15
3
15
thrtnastrx
When I search I want to show the top results by a specific field "field1" and also show "field2" and "field3". Proble...
by thrtnastrx Observer in Splunk Search 11-25-2024
0 3
0
3
Aithnave
Hey Splunk team, I’m facing an issue where Splunk fails to search for certain key-value pairs in some events unless I...
by Aithnave Engager in Splunk Search 11-25-2024
0 3
0
3
SplunkUser001
Hello, I have the following query to search Proofpoint logs.  index=ppoint_prod host=*host1* | eval time=strftime(_ti...
by SplunkUser001 Explorer in Splunk Search 11-25-2024
0 11
0
11
mariojost
We search thru the logs of switches and there are some logs that are unconcerning if you just have a couple of them l...
by mariojost Engager in Splunk Search 11-25-2024
0 6
0
6
darkins
probably an easy one, i have two events as follows thisisfield1 thisisfield2 mynextfield3thisisfield1 mynextfield3mea...
by darkins Engager in Splunk Search 11-25-2024
0 7
0
7
campbellwarren
I understand that tstats will only work with indexed fields, not extracted fields. How can I determine which fields ...
by campbellwarren Engager in Splunk Search 11-24-2024
0 5
0
5
scout29
Need help to extract a field that comes after a certain word in a event. I am looking to extract a field called "sn_g...
by scout29 Path Finder in Splunk Search 11-22-2024
0 3
0
3
Brad
We are trying to watch the NIC statistics for our OS interfaces.  We are gathering data from a simple ifconfig eth0 |...
by Brad Explorer in Splunk Search 11-22-2024
0 6
0
6
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...