Splunk Search

Splunk Search
Community Activity
rel82wi
Hi thereIm trying to filter my search results based on numerical top values of a field.For example. I have 5k events ...
by rel82wi Engager in Splunk Search 11-10-2021
0 4
0
4
spfingst87
HiI want to exclude the path from search results, i.e.:www.testsite.comwww.testsite.com/path1www.testsite.com/path2ww...
by spfingst87 Loves-to-Learn in Splunk Search 11-10-2021
0 4
0
4
febbi
I want to extract the substring: "xenmobile" from string:  "update task to xenmobile-2021-11-08-19-created completed!...
by febbi Explorer in Splunk Search 11-10-2021
0 2
0
2
typicallywrecke
So I'm trying to do something that may or may not be possible. I want to first create a lookup table that maps IP a...
by typicallywrecke Engager in Splunk Search 11-10-2021
0 4
0
4
rnikam1412
I am trying to look for accounts which are not active anywhere in network.(index=network user=*) OR (index=okta SamAc...
by rnikam1412 Loves-to-Learn Everything in Splunk Search 11-09-2021
0 2
0
2
shashank111v
How to extract values from below log file using rex?Log:{Attribute(name=xyz, values={'1'}), Attribute(name=attempts, ...
by shashank111v Explorer in Splunk Search 11-09-2021
0 3
0
3
pm771
We have a relatively small set of devices that emit daily in the vicinity of a million events each.  Each device has ...
by pm771 Communicator in Splunk Search 11-09-2021
0 6
0
6
dlawler1
Hello! I have a lookup table that looks like the following: hosttimestamphost110:33host24:24 What I would like to do ...
by dlawler1 New Member in Splunk Search 11-09-2021
0 4
0
4
kalibaba2021
Does the Lookup cmd allow for Where clause to filter the output of Lookup? Or do I need to have an extra sub search w...
by kalibaba2021 Path Finder in Splunk Search 11-09-2021
0 2
0
2
indeed_2000
Hi i have log like this, need to find where unusuall time gap between "Packet Processed" and "Send Packet" that exist...
by indeed_2000 Motivator in Splunk Search 11-09-2021
0 4
0
4
christoffertoft
I'm trying to exclude a value from a multivalue list, but it only works when I input the string as a value, not as a ...
by christoffertoft Communicator in Splunk Search 11-09-2021
0 7
0
7
neerajs_81
Hi All,Can someone help to build a search to check for Total_login_Failures  > 10 (per 24H) OR  Number of Failures pe...
by neerajs_81 Builder in Splunk Search 11-09-2021
0 4
0
4
sylim_splunk
On all SearchHead cluster members with ver 8.0.2,  every day we are observing that CPU utilization grows. After rough...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 11-09-2021
1 2
1
2
jbuddy24
I'm having issue with a search of mine. I've been trying to organize the matrix so that it will be ready for my pivot...
by jbuddy24 Explorer in Splunk Search 11-08-2021
0 1
0
1
rahul1502133
Hey everyone, I just had a small search, is there any way to monitor servers using Splunk and get data on their avai...
by rahul1502133 Explorer in Splunk Search 11-08-2021
0 8
0
8
jip31
hiI use a basic base search like this  <search id="test"> <query>index=toto sourcetype=tutu | fields sam web_hits</qu...
by jip31 Motivator in Splunk Search 11-08-2021
0 11
0
11
Mary666
Hello All, Anyone know how I can get the latest date from a lookup file? I am using the script below:| inputlookup a...
by Mary666 Communicator in Splunk Search 11-08-2021
0 2
0
2
rajs115
Hi,  I have a splunk query which results the two outputs (using table) such as "JOB_NAME" and "JOB_ID".   For example...
by rajs115 Path Finder in Splunk Search 11-08-2021
0 10
0
10
siouxsiesioux
My event returns the following:1@test.com/test/2_0" xmlns:d4p1="http://www.w3.org/1999/xlink"> <eb:Description xml:la...
by siouxsiesioux Engager in Splunk Search 11-08-2021
0 2
0
2
Mary666
Hello Splunk Community I have managed to use REST to add some columns from my CSV files. However, not all the columns...
by Mary666 Communicator in Splunk Search 11-08-2021
0 1
0
1
joe06031990
Hi, I have the bellow search which works out the successes, failures, success_rate, failure_rate and total however I ...
by joe06031990 Communicator in Splunk Search 11-08-2021
0 0
0
0
ltrand
I'm working with some json data that contains 1 field with a list of keys and 1 field with a list of values. These p...
by ltrand Contributor in Splunk Search 11-08-2021
0 4
0
4
Mary666
Hello All, This may seem easy, but its been quite tedious. How can I create one field that has common values from two...
by Mary666 Communicator in Splunk Search 11-08-2021
0 4
0
4
joe06031990
Hi, I have the bellow search which works out the successes, failures, success_rate, failure_rate and total however I ...
by joe06031990 Communicator in Splunk Search 11-08-2021
0 0
0
0
himanshuqb
I wan to set color  for output of column if it's date matches current or two days before current date. 
by himanshuqb Loves-to-Learn in Splunk Search 11-08-2021
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...