Splunk Search

Splunk Search
Community Activity
mursidehsani
I have this queryis not mapped to ink name| rex "(?<time>\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}).*Ink Type '(?<ink_type...
by mursidehsani Explorer in Splunk Search 11-05-2024
0 3
0
3
ajmach343
I am trying to make a search that will fire only when an admin makes a change to their own account.I want to know if ...
by ajmach343 Explorer in Splunk Search 11-05-2024
0 3
0
3
Dayalss
Hi,I have a huge set of data with different emails in it , I want to setup email alerts for few parameters.But the is...
by Dayalss Engager in Splunk Search 11-05-2024
0 3
0
3
smanojkumar
Hello There,    I would like to pass two diffrent values as a token, the search consists of code as a token, where co...
by smanojkumar Contributor in Splunk Search 11-05-2024
0 5
0
5
krishna1
I'm working with a query where I'm using a lookup to enrich events based on the work_queue field and then filtering t...
by krishna1 Explorer in Splunk Search 11-04-2024
0 1
0
1
Miguel3393
How can I make it show me only what appears as null in the Call.CallForwardInfo.OriginalCalledAddr field? Right now I...
by Miguel3393 Path Finder in Splunk Search 11-04-2024
0 4
0
4
tohalan
Hi Everyone, Need some help on how to display the output value as zero in a chart when a negative result is returned...
by tohalan New Member in Splunk Search 11-04-2024
0 2
0
2
sta_splunk
I have data similar to:Field-A Field-BA1           B1A1           B2A1           B3A2           B4A3           B5A2  ...
by sta_splunk Engager in Splunk Search 11-04-2024
0 3
0
3
JandrevdM
Good day,I am trying to figure out how I can join two searches to see if there is a service now ticket open for someo...
by JandrevdM Path Finder in Splunk Search 11-04-2024
0 4
0
4
Ninja_splunk
I'm looking for a query to display a list of jobs stuck in queue (the past 7 days). Does anyone knows the query? 
by Ninja_splunk Splunk Employee Splunk Employee in Splunk Search 11-03-2024
0 1
0
1
dinesh001kumar
I am having two index( index A and index B). Here I need to measure response time of topup of prepaid or postpaid num...
by dinesh001kumar Explorer in Splunk Search 11-03-2024
0 2
0
2
rukshar
Please help me to extract multiple values from one single value. 
by rukshar Explorer in Splunk Search 11-03-2024
0 7
0
7
Cheng2Ready
I have  2 field that holds 3 valuesField 1values= a,b,cField 2values= 1,2,3 Is there a way to table without using Joi...
by Cheng2Ready Communicator in Splunk Search 11-03-2024
0 1
0
1
unicornia
Hello team,I’ve developed a custom command script that works perfectly when executed through the CLI, but it fails to...
by unicornia New Member in Splunk Search 11-02-2024
0 2
0
2
tbessie
In my company's Splunk server, when I do a search, I usually see a difference in time between the "Time" column and t...
by tbessie New Member in Splunk Search 11-02-2024
0 6
0
6
mackey
We deal with hundreds of iocs ( mostly flagged IP's) that come in monthly, and we need to check them for hits in our ...
by mackey Engager in Splunk Search 11-01-2024
0 5
0
5
mwolfe
I am trying to take the results of one search, extract a field from those results (named "id") and take all of those ...
by mwolfe Engager in Splunk Search 11-01-2024
0 2
0
2
eraser
I've imported a csv file and one of the fields called "Tags" looks like this:Tags="avd:vm, dept:support services, cm-...
by eraser Explorer in Splunk Search 11-01-2024
0 6
0
6
mwolfe
I've got data so:"[clientip]  [host] - [time] [method] [uri_path] [status] [useragent]" ..  and do the following sear...
by mwolfe Engager in Splunk Search 11-01-2024
0 4
0
4
varun99
My requirement is to highlight the "Error" string in red colour if it is present in the extracted field "Status". Not...
by varun99 Path Finder in Splunk Search 10-31-2024
0 12
0
12
jason2
Putting together a query that shows, on an individual alert level, the number of times the alert fired in a day and t...
by jason2 Loves-to-Learn in Splunk Search 10-31-2024
0 3
0
3
imrago
We are ingesting large volume of network data and would like to use tstats to make the searches faster. The query ind...
by imrago Contributor in Splunk Search 10-31-2024
0 2
0
2
taruntalreja
I have two query in splunk query 1 and query 2 and an input. Based on the input, i need to execute either query 1 or ...
by taruntalreja New Member in Splunk Search 10-31-2024
0 4
0
4
smanojkumar
Hello Splunkers,   I'm having a inputput dropdown field, when i'm selecting "*" in that input dropdown field, I need ...
by smanojkumar Contributor in Splunk Search 10-31-2024
0 1
0
1
norish
I'm using `Splunk Add-on for Box` to collect box logging data.As a premise, `box:events' contains information for `up...
by norish Explorer in Splunk Search 10-30-2024
0 3
0
3
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Solution Authors