Splunk Search

Splunk Search
Community Activity
ddrillic
We suspect that some of our users run real time searches. How can I produce a report which shows real time search act...
by ddrillic Ultra Champion in Splunk Search 11-07-2024
0 7
0
7
kenbaugher
After looking at some examples online, I was able to come up with the below query, which can display one or more colu...
by kenbaugher Path Finder in Splunk Search 11-07-2024
0 2
0
2
ppolendey
Splunk Enterprise Version: 9.2.0.1OpenShift Version: 4.14.30 We used to have Openshift Event logs coming in under sou...
by ppolendey New Member in Splunk Search 11-07-2024
0 1
0
1
cbiraris
Can you please help me to build eval queryCondition-1ABC=MatchXYZ=Matchthen output of ABC compare to XYZ is MatchCond...
by cbiraris Path Finder in Splunk Search 11-07-2024
0 2
0
2
NatSec
I have a working dashboard where a token is used as a variable. But now I am trying to use the same concept when maki...
by NatSec Explorer in Splunk Search 11-07-2024
0 5
0
5
ramuzzini
Hello, I am trying to join two indexes to display data from our local printers.  I have an index getting data from ou...
by ramuzzini Path Finder in Splunk Search 11-06-2024
0 8
0
8
jdmeek
I have an index with events containing a src_ip but not a username for the event.   I have another index of VPN auth ...
by jdmeek Engager in Splunk Search 11-06-2024
0 2
0
2
Noctisae
First of all, English isn't my native language, so I apologize in advance for any error I could write in this support...
by Noctisae Engager in Splunk Search 11-06-2024
0 8
0
8
mursidehsani
I have this queryis not mapped to ink name| rex "(?<time>\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}).*Ink Type '(?<ink_type...
by mursidehsani Explorer in Splunk Search 11-05-2024
0 3
0
3
ajmach343
I am trying to make a search that will fire only when an admin makes a change to their own account.I want to know if ...
by ajmach343 Explorer in Splunk Search 11-05-2024
0 3
0
3
Dayalss
Hi,I have a huge set of data with different emails in it , I want to setup email alerts for few parameters.But the is...
by Dayalss Engager in Splunk Search 11-05-2024
0 3
0
3
smanojkumar
Hello There,    I would like to pass two diffrent values as a token, the search consists of code as a token, where co...
by smanojkumar Contributor in Splunk Search 11-05-2024
0 5
0
5
krishna1
I'm working with a query where I'm using a lookup to enrich events based on the work_queue field and then filtering t...
by krishna1 Explorer in Splunk Search 11-04-2024
0 1
0
1
Miguel3393
How can I make it show me only what appears as null in the Call.CallForwardInfo.OriginalCalledAddr field? Right now I...
by Miguel3393 Path Finder in Splunk Search 11-04-2024
0 4
0
4
tohalan
Hi Everyone, Need some help on how to display the output value as zero in a chart when a negative result is returned...
by tohalan New Member in Splunk Search 11-04-2024
0 2
0
2
sta_splunk
I have data similar to:Field-A Field-BA1           B1A1           B2A1           B3A2           B4A3           B5A2  ...
by sta_splunk Engager in Splunk Search 11-04-2024
0 3
0
3
JandrevdM
Good day,I am trying to figure out how I can join two searches to see if there is a service now ticket open for someo...
by JandrevdM Path Finder in Splunk Search 11-04-2024
0 4
0
4
Ninja_splunk
I'm looking for a query to display a list of jobs stuck in queue (the past 7 days). Does anyone knows the query? 
by Ninja_splunk Splunk Employee Splunk Employee in Splunk Search 11-03-2024
0 1
0
1
dinesh001kumar
I am having two index( index A and index B). Here I need to measure response time of topup of prepaid or postpaid num...
by dinesh001kumar Engager in Splunk Search 11-03-2024
0 2
0
2
rukshar
Please help me to extract multiple values from one single value. 
by rukshar Explorer in Splunk Search 11-03-2024
0 7
0
7
Cheng2Ready
I have  2 field that holds 3 valuesField 1values= a,b,cField 2values= 1,2,3 Is there a way to table without using Joi...
by Cheng2Ready Communicator in Splunk Search 11-03-2024
0 1
0
1
unicornia
Hello team,I’ve developed a custom command script that works perfectly when executed through the CLI, but it fails to...
by unicornia New Member in Splunk Search 11-02-2024
0 2
0
2
tbessie
In my company's Splunk server, when I do a search, I usually see a difference in time between the "Time" column and t...
by tbessie New Member in Splunk Search 11-02-2024
0 6
0
6
mackey
We deal with hundreds of iocs ( mostly flagged IP's) that come in monthly, and we need to check them for hits in our ...
by mackey Engager in Splunk Search 11-01-2024
0 5
0
5
mwolfe
I am trying to take the results of one search, extract a field from those results (named "id") and take all of those ...
by mwolfe Engager in Splunk Search 11-01-2024
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...