Splunk Search

Splunk Search
Community Activity
gauravkumar85
 I have dataset which have field INSERT_DATE now i want to perform search based the date which is match with Global T...
by gauravkumar85 Path Finder in Splunk Search 11-28-2024
0 5
0
5
sfmandmdev
What is the difference between lastTime and recentTime in a metadata search?
by sfmandmdev Path Finder in Splunk Search 11-28-2024
2 4
2
4
adoumbia
I am trying to write an spl query to detect an event of a single source IP address  or a user fails multiple time to ...
by adoumbia Engager in Splunk Search 11-27-2024
0 4
0
4
darkins
fieldA:1:10 fieldB:1:3 fieldC:1:2fieldA:1:10 fieldC:1:2fieldA:1:10 fieldC:1:2fieldC:1:1 I want to end up with a field...
by darkins Engager in Splunk Search 11-27-2024
0 5
0
5
santhipriya
I have a 3 node search head cluster and distributed indexers we are getting below error when running any type of sear...
by santhipriya Engager in Splunk Search 11-27-2024
0 4
0
4
Crotyo
I have a csv file like this that contain more than 100 numbers 111111112222222233333333 I want to search for events t...
by Crotyo Observer in Splunk Search 11-26-2024
0 9
0
9
hulahoop
Let's say I have events A and B: A -- Feb 1 2010 10:10:00 field1=foo field2=bar B -- Feb 1 2010 10:10:01 field1=foo ...
by hulahoop Splunk Employee Splunk Employee in Splunk Search 11-26-2024
3 15
3
15
thrtnastrx
When I search I want to show the top results by a specific field "field1" and also show "field2" and "field3". Proble...
by thrtnastrx Observer in Splunk Search 11-25-2024
0 3
0
3
Aithnave
Hey Splunk team, I’m facing an issue where Splunk fails to search for certain key-value pairs in some events unless I...
by Aithnave Engager in Splunk Search 11-25-2024
0 3
0
3
SplunkUser001
Hello, I have the following query to search Proofpoint logs.  index=ppoint_prod host=*host1* | eval time=strftime(_ti...
by SplunkUser001 Explorer in Splunk Search 11-25-2024
0 11
0
11
mariojost
We search thru the logs of switches and there are some logs that are unconcerning if you just have a couple of them l...
by mariojost Engager in Splunk Search 11-25-2024
0 6
0
6
darkins
probably an easy one, i have two events as follows thisisfield1 thisisfield2 mynextfield3thisisfield1 mynextfield3mea...
by darkins Engager in Splunk Search 11-25-2024
0 7
0
7
campbellwarren
I understand that tstats will only work with indexed fields, not extracted fields. How can I determine which fields ...
by campbellwarren Engager in Splunk Search 11-24-2024
0 5
0
5
scout29
Need help to extract a field that comes after a certain word in a event. I am looking to extract a field called "sn_g...
by scout29 Path Finder in Splunk Search 11-22-2024
0 3
0
3
Brad
We are trying to watch the NIC statistics for our OS interfaces.  We are gathering data from a simple ifconfig eth0 |...
by Brad Explorer in Splunk Search 11-22-2024
0 6
0
6
vm_molson
I am trying to figure out how to include a lookup in my search, but only some records. My current search is below. My...
by vm_molson Explorer in Splunk Search 11-21-2024
0 1
0
1
robertlynch2020
Hi I have the below code to produce this table - but does anyone know how to get rid of the part in red (I have added...
by robertlynch2020 Influencer in Splunk Search 11-21-2024
0 5
0
5
LogUx
Hello Splunkers!!We have events that contains source and destination fields with complete values, and we want to matc...
by LogUx Motivator in Splunk Search 11-21-2024
0 3
0
3
ecnausysadm
I have searches for two files that are related but the incoming and outgoing file names differ, basically it's an inc...
by ecnausysadm Explorer in Splunk Search 11-21-2024
0 3
0
3
gajananh999
Hello Everyone, I have events like 02-Jul-2014 09:25:25 AM: ========== Finish Transmit Process ========== 02-Ju...
by gajananh999 Contributor in Splunk Search 11-21-2024
0 3
0
3
tlunruh
When I run this query: index=edi-2 | join type=inner TRACKINGNUMBER [search index=edi | rename TRCK AS TRACKINGNUMBER...
by tlunruh New Member in Splunk Search 11-21-2024
0 3
0
3
dmrhodes101
We're using Splunk to monitor EDI traffic onto our backend system. We want to have a single value panel that shows gr...
by dmrhodes101 Explorer in Splunk Search 11-21-2024
1 3
1
3
mbasharat
Hi, I have a simple search which is using a lookup definition based off of a lookup. This lookup is large. Search has...
by mbasharat Builder in Splunk Search 11-20-2024
0 3
0
3
mrsampson
The structure of JSON in my log events is roughly as follows  { "Info": { "Apps": { "Reportin...
by mrsampson Explorer in Splunk Search 11-19-2024
0 2
0
2
NanSplk01
This is my search.  I brings back Not Known for every field instead of the correct case name:index=websphere webspher...
by NanSplk01 Communicator in Splunk Search 11-19-2024
0 3
0
3
Get Updates on the Splunk Community!

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...

Optimize AI at Scale: Must-Attend Observability Sessions at .conf26

conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help ...

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...