Splunk Search

Splunk Search
Community Activity
indeed_2000
HiI have log file like this, need to extract "id" from lines that A=20 and match these lines to lines where that B=10...
by indeed_2000 Motivator in Splunk Search 10-10-2021
0 15
0
15
kjordans
I need to create a table that includes the filename, the domain name of which file came from, the source IP, the dest...
by kjordans Engager in Splunk Search 10-09-2021
1 1
1
1
danifor10
Hello I am looking a simple SPL to  to detect activity from users without MFA in AWS.I have the search below which su...
by danifor10 New Member in Splunk Search 10-09-2021
0 0
0
0
shashi584
I want to delete this field (VID) from one of my search query, this is not available under  Field extractions.and wha...
by shashi584 Explorer in Splunk Search 10-09-2021
0 3
0
3
Morrel
Hallo.can anyone please help me.i want search sourcetype for this IP10.2.123.123 OR 22.222.222.22 OR 33.333.333.33 | ...
by Morrel New Member in Splunk Search 10-09-2021
0 2
0
2
kumarnis45
Hi,     I have recently integrated and migrated AWS Simple Queue Serivce (SQS) logs to splunk. I am trying to search ...
by kumarnis45 Path Finder in Splunk Search 10-09-2021
0 0
0
0
SplunkDash
Hello,I have Universal Forward and Heavy Forward in Linux machine, how would I stop and restart them.  Any help will ...
by SplunkDash Motivator in Splunk Search 10-09-2021
0 3
0
3
indeed_2000
hi i want to use sendmail spl command but it give me below errorcommand="sendemail", (535, '5.7.3 Authentication unsu...
by indeed_2000 Motivator in Splunk Search 10-08-2021
0 4
0
4
SamHTexas
We have Splunk Ent. + ES. I have a dashboard that I 'd like to install in Security Essentials. What level permission ...
by SamHTexas Builder in Splunk Search 10-08-2021
0 0
0
0
jaydiare
I need help to use the values from a lookup table into multiple fields, where the output from the lookup table is a l...
by jaydiare Explorer in Splunk Search 10-08-2021
0 2
0
2
data_explorer88
I have a list of files name under one field called "attachment"  and I would like to split this string into multiple ...
by data_explorer88 Explorer in Splunk Search 10-08-2021
0 2
0
2
yk010123
I am trying to produce the following output :app_namerequest_idtimeworkload at the time(requests per second)App112310...
by yk010123 Path Finder in Splunk Search 10-08-2021
0 4
0
4
graziaedu
Hello,I have a field with this values/v1/accounts/96ea01b5-7ea7-4dc6-b534-39ae8b114bba/transactions/v1/accounts/ff572...
by graziaedu Explorer in Splunk Search 10-08-2021
0 4
0
4
Gunnar
Hi all,strange thing - when using mean() and avg() in the same stats command, whichever is written first is empty, wh...
by Gunnar Explorer in Splunk Search 10-08-2021
0 6
0
6
mlg
Hi,I am new to Splunk and working with parking records. I am calculating the current wait_time based off upcoming par...
by mlg Observer in Splunk Search 10-08-2021
0 1
0
1
dtccsundar
Hi,my regex was like below ,search| rex field=_raw "Status=(?<Status>\"\w+\s+\w+\".*?)," |stats count by StatusMy out...
by dtccsundar Path Finder in Splunk Search 10-08-2021
0 2
0
2
mlg
Hi, I am new to Splunk and working with parking records. Within my events, I have a permit_expiry field, which is a d...
by mlg Observer in Splunk Search 10-08-2021
0 1
0
1
yvassilyeva
Hi!I have the following data and would like to check, for those records with the same ID, if one record has CREATED_D...
by yvassilyeva Path Finder in Splunk Search 10-08-2021
0 1
0
1
mlg
Hi, I am new to Splunk and working with parking records. I am trying to display parking spaces that are currently not...
by mlg Observer in Splunk Search 10-08-2021
0 1
0
1
srinivas_gowda
Hello all,I am extracting a field which is coming in multiple formats, however I found that once of the format is not...
by srinivas_gowda Path Finder in Splunk Search 10-08-2021
0 1
0
1
Bleepie
Dear Splunk Community,I have the following search: index=websphere 200 OK POST  And I have different platforms that I...
by Bleepie Communicator in Splunk Search 10-08-2021
0 2
0
2
bburns2122
I'm trying to figure out how to get the time difference between two events that use the same UUID. However, the secon...
by bburns2122 Explorer in Splunk Search 10-07-2021
0 1
0
1
Justin49
Hello All,I have a large dataset "audit.cost_records" wherein I am trying to locate a correlation based on a large nu...
by Justin49 Loves-to-Learn in Splunk Search 10-07-2021
0 3
0
3
iiix94
Hello! I have a lookup table with fields 'name' and 'last_login'. I'm trying to find users who haven't logged in the ...
by iiix94 Loves-to-Learn in Splunk Search 10-07-2021
0 4
0
4
sjringo
Trying to figure out how to loop in Splunk.  I have the below query and my end result is to map/chart into a timechar...
by sjringo Contributor in Splunk Search 10-07-2021
0 10
0
10
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors