Splunk Search

Splunk Search
Community Activity
JohnR
Given a field containing a "userId", I want a count per day of unique userIds by "new" vs "returning". E.g. Ends up w...
by JohnR Engager in Splunk Search 11-12-2021
0 1
0
1
avoelk
I was wondering what, i.e., the following means : 24 physical cores or 48 vcores . does that mean for a virtual envir...
by avoelk Communicator in Splunk Search 11-12-2021
0 3
0
3
EH
I'm trying to rename the IP's of our servers to splunknodeshost_ip host_nameip-111-11-1-11Searchheadip-111-11-1-12Sea...
by EH Explorer in Splunk Search 11-12-2021
0 1
0
1
neerajs_81
Hello All,  I have a search that uses stats command and displays the results as follows.  Note:  I have stripped out ...
by neerajs_81 Builder in Splunk Search 11-12-2021
0 4
0
4
JohnR
I have a search that displays unique users per day (based on a "user id" field). I also would like another search tha...
by JohnR Engager in Splunk Search 11-12-2021
0 4
0
4
Hung_Nguyen
In order to visual a data table with 4 columns: time, resource1, resource2, duration.  I know who to do this with dat...
by Hung_Nguyen Path Finder in Splunk Search 11-12-2021
0 1
0
1
jordanperks
I am getting millions of events/day that I need to send to the null queue. I need to match all events with the except...
by jordanperks Path Finder in Splunk Search 11-11-2021
0 5
0
5
spyeduru06
I have a two VIP names, and I would like to know the number of hits to it. I am new to splunk, and not sure on how to...
by spyeduru06 New Member in Splunk Search 11-11-2021
0 0
0
0
gherkin
Good afternooni'm wondering if I may be able to get a bit of help with this one as I'm struggling on trying to achiev...
by gherkin Explorer in Splunk Search 11-11-2021
0 9
0
9
MeMilo09
Hey There, Below I have a field in where ABC > 2500 cuz the value is actually 2800. So then If ABC>than 2500 add 1 da...
by MeMilo09 Path Finder in Splunk Search 11-11-2021
0 2
0
2
ashishmgupta
I have below two JSON events where under "appliedConditionalAccessPolicies", in one event policy1 has results =failur...
by ashishmgupta Explorer in Splunk Search 11-11-2021
0 0
0
0
lostcauz3
how to include specific rows from a table in a panel into another panel in the same dashboard?
by lostcauz3 Path Finder in Splunk Search 11-11-2021
0 4
0
4
richtate
I have an index with a mv field (parts) that I want to match a value in that field with a csv file, but only return t...
by richtate Path Finder in Splunk Search 11-11-2021
0 12
0
12
sasankganta
Team Can you please provide me documentation link to learn Splunk UBA platform and related links for monitoring, deve...
by sasankganta Path Finder in Splunk Search 11-11-2021
0 1
0
1
rjashton
I'm having trouble with using the where command to compare times. The search that I'm running is this:   index=jamf s...
by rjashton Engager in Splunk Search 11-11-2021
0 2
0
2
Roy_9
Hello,I am seeing the below warning on our SH after splunk cloud performed a restart at the backend when i uninstalle...
by Roy_9 Motivator in Splunk Search 11-11-2021
0 8
0
8
rajs115
Hi,   I am looking for a solution to check the splunk query results . if it returns '0' events i need to trigger an a...
by rajs115 Path Finder in Splunk Search 11-11-2021
0 6
0
6
srinivas_gowda
Hello all, I am trying to extract the below highlighted fields, but the extractions at time is failing to get the req...
by srinivas_gowda Path Finder in Splunk Search 11-11-2021
0 3
0
3
Azwaliyana
I want to extract the field that are on the left which are status, monitoirng status, monitoring mode and so on. Mult...
by Azwaliyana Path Finder in Splunk Search 11-11-2021
0 3
0
3
rafadvega
Hi,I need to join two searchs. For example:Example 1: | inputlookup join_example1.csv countryproductdaystockSpainappl...
by rafadvega Path Finder in Splunk Search 11-10-2021
0 2
0
2
marceloalejandr
For some reason the "Enabled" field is not return "true or false" when running ldapsearch from Splunk.  All the other...
by marceloalejandr Path Finder in Splunk Search 11-10-2021
0 1
0
1
esalesap
We have Splunk 8.0.3 deployed to a private AWS cloud.We use AWS i3.8xlarge instance types for our indexers, recently ...
by esalesap Path Finder in Splunk Search 11-10-2021
0 1
0
1
andrewenstad
I have a user that has asked how to get access/permissions to the "export" button while doing a search in Splunk.  It...
by andrewenstad Engager in Splunk Search 11-10-2021
0 1
0
1
SMM10
I want to find items in one index based on results from another index's search. I have the following but only get a h...
by SMM10 Explorer in Splunk Search 11-10-2021
0 3
0
3
jeck11
This has been asked a million times. I've been digging through the various postings but haven't figured out what I'm ...
by jeck11 Path Finder in Splunk Search 11-10-2021
0 8
0
8
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Splunk is excited to announce the General Availability (GA) of Federated Search for ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...
Top Solution Authors