Splunk Search

Splunk Search
Community Activity
andrewtrobec
Hello, I have two separate chart calculations that I would like to combine into a single chart. The first is an avg...
by andrewtrobec Motivator in Splunk Search 10-15-2021
0 7
0
7
Brainstorms
Hey all, I got a really helpful response last time and now I'm back with another question. I have a search with the s...
by Brainstorms Explorer in Splunk Search 10-15-2021
0 3
0
3
phoellig
I've been working with the /services/search/jobs/export API recently and I noticed that setting the output mode to 'j...
by phoellig New Member in Splunk Search 10-15-2021
0 0
0
0
neerajs_81
Can someone help me to build a search query for the below use case ?  My use case is to detect if any S3 buckets have...
by neerajs_81 Builder in Splunk Search 10-15-2021
0 10
0
10
humanBeing
Hello all,I'm using a lookup table with a _time field to create a timechart which works great.  However, the lookup t...
by humanBeing Engager in Splunk Search 10-15-2021
0 1
0
1
Johnstone234
Hi, I am hoping to get some help in creating a search, which will be turned into an alert - I am working with system ...
by Johnstone234 Loves-to-Learn in Splunk Search 10-15-2021
0 8
0
8
luckyman80
Hi Experts,                   As part of an new initiative looking at SLO metrics. I have created the below query whi...
by luckyman80 Path Finder in Splunk Search 10-15-2021
0 0
0
0
indeed_2000
Hiwhat is the rex for thisfield1=this is messagehere is the log:00:09:59.990 app module: AB[0000]: Data[{"code":"OK",...
by indeed_2000 Motivator in Splunk Search 10-15-2021
0 1
0
1
indeed_2000
HiI have two field on my logfile <servername> <CLOSESESSION> need to know when CLOSESESSION is 0 each day by serverna...
by indeed_2000 Motivator in Splunk Search 10-15-2021
0 9
0
9
indeed_2000
hi what is rex for these three fields?here is the log:2021-10-14 12:51:20,412 INFO [APP] log in : A12345@#4321@califo...
by indeed_2000 Motivator in Splunk Search 10-15-2021
0 1
0
1
krishna81m
We have multiple TraceIDs that have same payload and this payload is part many logs for a given TraceID. Here foo1 is...
by krishna81m Engager in Splunk Search 10-14-2021
0 2
0
2
cheriemilk
Hi team,I have below kind of data in splunk, it contains 3 fields ISRF, DSRF and DSFF.  they are all multi-value fiel...
by cheriemilk Path Finder in Splunk Search 10-14-2021
0 2
0
2
zoebanning
Hello Splunk Community,Can anyone help me build a query based on the below;I have a batch job that has multiple steps...
by zoebanning Path Finder in Splunk Search 10-14-2021
0 2
0
2
SamHTexas
Is there an SPL to list all my Hosts (Win & Linus), version of their UF, date & time & TZ please? Thanks a million.
by SamHTexas Builder in Splunk Search 10-14-2021
0 3
0
3
dcsteve24
I have a dashboard used for generating data for reports. Since its initial build, I've been going back and revamping ...
by dcsteve24 Explorer in Splunk Search 10-14-2021
0 3
0
3
palisetty
I know that 'Zoom out' will make the search to re-execute but I am not sure about 'zoom in' or 'zoom to select'. Kind...
by palisetty Communicator in Splunk Search 10-14-2021
0 9
0
9
surly78
I'm trying to display a total count for each value found in attributes.eventtype field and group them by the attribut...
by surly78 Loves-to-Learn Lots in Splunk Search 10-14-2021
0 6
0
6
sahiltcs
Hello, We received data from Alicloud and found there are alot of duplicate fields populate in Interesting fields lik...
by sahiltcs Path Finder in Splunk Search 10-14-2021
0 0
0
0
nSphere
Hello community,I am searching since few days a solution to display the earliest and latest value from a chart into a...
by nSphere New Member in Splunk Search 10-14-2021
0 1
0
1
jbanAtSplunk
Hi,We have status in one log type, where we would like to track if account is in state: bypassedExample:2021-13-10 us...
by jbanAtSplunk Communicator in Splunk Search 10-14-2021
0 2
0
2
indeed_2000
HiHow can I find events that not occurred daily? Here is the scenario I have two field on my logfile <servername> <CL...
by indeed_2000 Motivator in Splunk Search 10-14-2021
0 3
0
3
indeed_2000
hiwhat is the rex for extract all brackets contain this pattern[AB_123] [ZXY_987]1-check all brackets if start with A...
by indeed_2000 Motivator in Splunk Search 10-14-2021
0 1
0
1
nmohammed
We know the amount of data ingested daily from the Splunk internal logs and the License dashboard, but we're trying t...
by nmohammed Builder in Splunk Search 10-14-2021
0 3
0
3
swright_rl
Hi All,I'm trying to create a search, to potentially be made into a monitoring rule later on.What I am trying to achi...
by swright_rl Explorer in Splunk Search 10-14-2021
0 0
0
0
dailv1808
Hi,I am using splunk DB connect 2.1.4 to get data from A table in Oracle database, (table with around 1000 transactio...
by dailv1808 Path Finder in Splunk Search 10-14-2021
0 2
0
2
Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...
Top Solution Authors