Splunk Search

Splunk Search
Community Activity
PickleRick
I was wondering... how are foreach-generated searches treated regarding the searches limits?I mean - normally you hav...
by SplunkTrust SplunkTrust in Splunk Search 09-30-2021
0 2
0
2
rodrigomarfei
Hello,I need a help with a search that seems very easy, but I'm unable to achieve the results I want.The events are r...
by rodrigomarfei Explorer in Splunk Search 09-30-2021
0 3
0
3
dababi1234
I am new to Splunk and would appreciate if anyone helps me on this. I would like to set up a Splunk alert for SocketT...
by dababi1234 New Member in Splunk Search 09-30-2021
0 5
0
5
gabrieleguidoni
Hello I would like to pass a value from a joined search (e.g. in this case the "Side") to the final table.I tried dif...
by gabrieleguidoni Loves-to-Learn in Splunk Search 09-30-2021
0 1
0
1
korhanacar
Hi Guys,I have a question about the data model.   Eventually, I want to create complex correlation rules by finding m...
by korhanacar Engager in Splunk Search 09-30-2021
0 0
0
0
priyangshupal
I have a json like this: { "A": [ { "B": [ { "status": "2", "value": "1" ...
by priyangshupal Engager in Splunk Search 09-30-2021
0 1
0
1
splunkcol
Hello there,I have spent a good time researching lateral movement in Splunk, unfortunately I have not found much.I ha...
by splunkcol Builder in Splunk Search 09-29-2021
0 2
0
2
jaibalaraman
Hi Team When i tried running the below eval command, i am getting some error message often.I wrote this below command...
by jaibalaraman Path Finder in Splunk Search 09-29-2021
0 8
0
8
tmarlette
So I have a search that triggers based upon how much memory is being used on any of my linux machines.   index=nix so...
by tmarlette Motivator in Splunk Search 09-29-2021
0 0
0
0
tinylund
| rex field=_raw "(?<dscvIP>[^\.]\d+\.\d+\.\d+\.\d+[\s|\:])"Using the above rex command to try to capture IP addresse...
by tinylund Explorer in Splunk Search 09-29-2021
0 5
0
5
willprince
I constantly see the below error on my search head. What causes this and how do I go about fixing it. I have removed...
by willprince Engager in Splunk Search 09-29-2021
10 9
10
9
GenRockeR
Hi guys. Why Splunk have many errors in log file and what can I do in this situation? 05-17-2019 18:58:08.036 +0300...
by GenRockeR Explorer in Splunk Search 09-29-2021
0 8
0
8
TheBravoSierra
I run a search head cluster with Splunk Enterprise. Typically I update apps via the back end CLI, but am wondering if...
by TheBravoSierra Path Finder in Splunk Search 09-29-2021
0 4
0
4
Shaurdonnay
I am trying to figure out how to pull fields to show the exact count of numbers and letters in a result. Like, if I h...
by Shaurdonnay Engager in Splunk Search 09-29-2021
0 2
0
2
mfudali
Hi, I have a Table created by: eval Actor=actor |eval "Total Time (max/avg/p50/p99)"=maxT + ", " + avgT + ", " + p50T...
by mfudali Explorer in Splunk Search 09-29-2021
0 1
0
1
SplunkDash
Hello,I have some issues in writing PROPS configuration file for the sample data/events given below. I have given 4 e...
by SplunkDash Motivator in Splunk Search 09-29-2021
0 2
0
2
Ida_2017
Dear communityI am struggling with how to allow different format in a search input, but still finding the correspondi...
by Ida_2017 Explorer in Splunk Search 09-29-2021
0 5
0
5
neerajs_81
Hello All,I have a search query that performs lookups against a CSV file and outputs only those hosts that are in the...
by neerajs_81 Builder in Splunk Search 09-29-2021
0 2
0
2
indut
Hi all,I am using splunk after a while and lost touch with the SPL. Please help me on below.I have about 40 fields to...
by indut Path Finder in Splunk Search 09-29-2021
0 2
0
2
metersk
The search below gives me the following data: (ns=stats msg=email_unsub_clicks) OR (ns=email msg=fbl OR msg=send OR ...
by metersk Path Finder in Splunk Search 09-29-2021
0 3
0
3
fedejko
Hi,I've got a lookup with a number of records, and not all of them have all columns populated. Is there a way to appe...
by fedejko Explorer in Splunk Search 09-29-2021
0 0
0
0
kirrusk
Hi,I want to check for a string in the field, but if the string is not found in the field then need to print the rema...
by kirrusk Communicator in Splunk Search 09-29-2021
0 4
0
4
Meliodas1111111
'Hi,We are want to create a playbook for Splunk with Ansible, We are having an issue config the AWS add on proxy conf...
by Meliodas1111111 New Member in Splunk Search 09-28-2021
0 0
0
0
ebs
Hi, if possible I would like to combine the two eval statements below so I can optimise it for my datamodel| eval uri...
by ebs Communicator in Splunk Search 09-28-2021
0 2
0
2
ebs
Hi,I have a uri_path that I want to combine into a single value, and put the combined value back into the original fi...
by ebs Communicator in Splunk Search 09-28-2021
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...