Splunk Search

Splunk Search
Community Activity
zubairaizatron
Hi GuysWanted to know if anyone knows if you can populate a summary index from a data model. the summary index query ...
by zubairaizatron Explorer in Splunk Search 11-10-2021
0 2
0
2
jip31
hiI use a lookup in order to do a correspondance between the field web_error_code which is my sourcetype and which is...
by jip31 Motivator in Splunk Search 11-10-2021
0 2
0
2
rohanmiskin
I have extracted two fields in my non prod splunk account. I want to use the same for the prod splunk account as well...
by rohanmiskin Explorer in Splunk Search 11-10-2021
0 2
0
2
Wilfred
Hi,I just started working with Splunk and would ask for some help.I have 3 sources, A, B and C.Source A contains fiel...
by Wilfred Engager in Splunk Search 11-10-2021
0 2
0
2
rel82wi
Hi thereIm trying to filter my search results based on numerical top values of a field.For example. I have 5k events ...
by rel82wi Engager in Splunk Search 11-10-2021
0 4
0
4
spfingst87
HiI want to exclude the path from search results, i.e.:www.testsite.comwww.testsite.com/path1www.testsite.com/path2ww...
by spfingst87 Loves-to-Learn in Splunk Search 11-10-2021
0 4
0
4
febbi
I want to extract the substring: "xenmobile" from string:  "update task to xenmobile-2021-11-08-19-created completed!...
by febbi Explorer in Splunk Search 11-10-2021
0 2
0
2
typicallywrecke
So I'm trying to do something that may or may not be possible. I want to first create a lookup table that maps IP a...
by typicallywrecke Engager in Splunk Search 11-10-2021
0 4
0
4
rnikam1412
I am trying to look for accounts which are not active anywhere in network.(index=network user=*) OR (index=okta SamAc...
by rnikam1412 Loves-to-Learn Everything in Splunk Search 11-09-2021
0 2
0
2
shashank111v
How to extract values from below log file using rex?Log:{Attribute(name=xyz, values={'1'}), Attribute(name=attempts, ...
by shashank111v Explorer in Splunk Search 11-09-2021
0 3
0
3
pm771
We have a relatively small set of devices that emit daily in the vicinity of a million events each.  Each device has ...
by pm771 Communicator in Splunk Search 11-09-2021
0 6
0
6
dlawler1
Hello! I have a lookup table that looks like the following: hosttimestamphost110:33host24:24 What I would like to do ...
by dlawler1 New Member in Splunk Search 11-09-2021
0 4
0
4
kalibaba2021
Does the Lookup cmd allow for Where clause to filter the output of Lookup? Or do I need to have an extra sub search w...
by kalibaba2021 Path Finder in Splunk Search 11-09-2021
0 2
0
2
indeed_2000
Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist...
by indeed_2000 Motivator in Splunk Search 11-09-2021
0 4
0
4
christoffertoft
I'm trying to exclude a value from a multivalue list, but it only works when I input the string as a value, not as a ...
by christoffertoft Communicator in Splunk Search 11-09-2021
0 7
0
7
neerajs_81
Hi All,Can someone help to build a search to check for Total_login_Failures  > 10 (per 24H) OR  Number of Failures pe...
by neerajs_81 Builder in Splunk Search 11-09-2021
0 4
0
4
sylim_splunk
On all SearchHead cluster members with ver 8.0.2,  every day we are observing that CPU utilization grows. After rough...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 11-09-2021
1 2
1
2
jbuddy24
I'm having issue with a search of mine. I've been trying to organize the matrix so that it will be ready for my pivot...
by jbuddy24 Explorer in Splunk Search 11-08-2021
0 1
0
1
rahul1502133
Hey everyone, I just had a small search, is there any way to monitor servers using Splunk and get data on their avai...
by rahul1502133 Explorer in Splunk Search 11-08-2021
0 8
0
8
jip31
hiI use a basic base search like this  <search id="test"> <query>index=toto sourcetype=tutu | fields sam web_hits</qu...
by jip31 Motivator in Splunk Search 11-08-2021
0 11
0
11
Mary666
Hello All, Anyone know how I can get the latest date from a lookup file? I am using the script below:| inputlookup a...
by Mary666 Communicator in Splunk Search 11-08-2021
0 2
0
2
rajs115
Hi,  I have a splunk query which results the two outputs (using table) such as "JOB_NAME" and "JOB_ID".   For example...
by rajs115 Path Finder in Splunk Search 11-08-2021
0 10
0
10
siouxsiesioux
My event returns the following:1@test.com/test/2_0" xmlns:d4p1="http://www.w3.org/1999/xlink"> <eb:Description xml:la...
by siouxsiesioux Engager in Splunk Search 11-08-2021
0 2
0
2
Mary666
Hello Splunk Community I have managed to use REST to add some columns from my CSV files. However, not all the columns...
by Mary666 Communicator in Splunk Search 11-08-2021
0 1
0
1
joe06031990
Hi, I have the bellow search which works out the successes, failures, success_rate, failure_rate and total however I ...
by joe06031990 Communicator in Splunk Search 11-08-2021
0 0
0
0
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...