Splunk Search

Splunk Search
Community Activity
khursheed
HiBelow data is dynamic, sample input table is given below, rows are order may vary (for simplicity I have put the da...
by khursheed New Member in Splunk Search 09-28-2021
0 2
0
2
mfudali
Hello,I have the query :hostalias=$hostname$ AND actor AND total | timechart span=1s count by actor | stats This retu...
by mfudali Explorer in Splunk Search 09-28-2021
0 7
0
7
dyarashus
I think this is a pretty basic question, but I'd appreciate some help with it.  I'm trying to produce an exportable, ...
by dyarashus Loves-to-Learn in Splunk Search 09-28-2021
0 3
0
3
guywood13
So this search...index="myindex" source="/data/logs/log.json" "Calculation Complete"... the results return a MessageB...
by guywood13 Path Finder in Splunk Search 09-28-2021
0 4
0
4
gaglimax
Hi,Let's imagine I have those raws :NameValue1Value2foo12foo1216foodazd56fooaoke43foo5623bar12barjodpez74barjo74bar12...
by gaglimax Loves-to-Learn Lots in Splunk Search 09-28-2021
0 0
0
0
samneo
Im looking to get a query that will tell me the difference in an error rate increase i.e 5 minutes ag it was 120 erro...
by samneo Path Finder in Splunk Search 09-28-2021
0 7
0
7
francesco1g
Hi, I have a search that contains millions of events and is extremely slow, is there a way to speed it up? This is th...
by francesco1g Engager in Splunk Search 09-28-2021
0 2
0
2
ky129q
Looking for the most efficient way to find 2 way traffic in flow data for a particular set of IP/port/protocol combin...
by ky129q Engager in Splunk Search 09-28-2021
0 0
0
0
Manasi25
hello, I have alert transaction at "ACK" and at "Resolved", i have created table for each value, but unable to edit t...
by Manasi25 Explorer in Splunk Search 09-28-2021
0 15
0
15
kxmorrr
Hi,I am trying to filter out fields from a table based on its content, example:LP. NAME SURNAME STREET CITY1. Bob Smi...
by kxmorrr Engager in Splunk Search 09-28-2021
0 3
0
3
username13
Hey guys. I have multiple events combined to transactions. I'd like to view the duration of each transaction on a tim...
by username13 Explorer in Splunk Search 09-28-2021
0 6
0
6
phamxuantung
So in detail, I have a dashboard that read log files to monitor the list of host's status which is UP or DOWN. But wh...
by phamxuantung Communicator in Splunk Search 09-28-2021
0 1
0
1
corehan
Hello dears,I want to list my search if  "B" total count higher than >3 than list by "A"A and B fields could have var...
by corehan Explorer in Splunk Search 09-28-2021
0 7
0
7
cauhe
Hi Experts,I'm having some difficulties to extract the correct information from a file that was add to splunk.I tried...
by cauhe Explorer in Splunk Search 09-28-2021
0 4
0
4
rhallinan
I have the following search. index=main_index sourcetype="hec:google" operationName=createMobileAuthenticationOutcome...
by rhallinan Engager in Splunk Search 09-27-2021
0 2
0
2
sahana
I have requirement to split the single cell into two columns, in which i need to add different search result data.I n...
by sahana Engager in Splunk Search 09-27-2021
0 1
0
1
vl951f
Our ITSI is showing some "Detected Anomaly" for the kpi "Index Usage".Where and how can I find the notable events for...
by vl951f Path Finder in Splunk Search 09-27-2021
0 0
0
0
splunkuser2127
There are no data on Mondays so my timecharts always dip to 0. {search string} | eval date_wday=lower(strftime(_time,...
by splunkuser2127 Loves-to-Learn in Splunk Search 09-27-2021
0 12
0
12
N-W
Hello!I have been trying to make a base search on a dashboard with a time and environment input as a drop-down.It onl...
by N-W Explorer in Splunk Search 09-27-2021
0 3
0
3
Jochen_Widmaier
Hi, I want to create a dashboard, where a user has a drop down input to select a named time frame ($value$). The star...
by Jochen_Widmaier Engager in Splunk Search 09-26-2021
0 6
0
6
zakura
Hi , I have 2 queries :index="bar_*" sourcetype =foo crm="ser"| dedup uid| stats count as TotalCountand index="bar_*"...
by zakura Explorer in Splunk Search 09-26-2021
0 3
0
3
P_Viz
Hey, I am working towards Slunk Fundamentals 1 and doing the eLearning assignments. Currently on Module5. I have impo...
by P_Viz Engager in Splunk Search 09-26-2021
1 3
1
3
ashvini_mishra
I have an api which has a number of endpoint, e.g., /health, /version, /specification and so on...I have a query whic...
by ashvini_mishra Explorer in Splunk Search 09-26-2021
0 3
0
3
ephemeric
I have a macro that adds a backslash to an existing backslash: [backslash(1)] args = arg definition = replace("$arg$"...
by ephemeric Contributor in Splunk Search 09-25-2021
0 0
0
0
ronsri
index=test sourcetype=test_access tag=prod server_name!="www.test.com" earliest=-4h latest=now | timechart eval(avg(r...
by ronsri Observer in Splunk Search 09-25-2021
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...