Splunk Search

Splunk Search
Community Activity
Arvids
I have got table, which contains field SSS with search patterns and another field FFF, to which I want apply search p...
by Arvids Loves-to-Learn in Splunk Search 09-21-2021
0 1
0
1
orionex
I'm trying to extract 1 fields from a log line. Just trying to extract the email.I cant extract a single field  and i...
by orionex Observer in Splunk Search 09-21-2021
0 1
0
1
mm12
I have a log file below format and props.conf wriiten below. I am getting first four lines as one event and the remai...
by mm12 Explorer in Splunk Search 09-21-2021
0 3
0
3
splunker991
I defined two eventypes: "loginAttempt" and "loginSuccess".  Now I am trying to create a chart where counts of both o...
by splunker991 New Member in Splunk Search 09-21-2021
0 2
0
2
fabiofox
We used the rest receivers simple api to send a body with some fields to index as a urlencoded form.Among these there...
by fabiofox Explorer in Splunk Search 09-21-2021
0 2
0
2
rjgreg
I am testing network latency from various subnets to 3 different VCenters.  The output gives me 3 results per subnet ...
by rjgreg Explorer in Splunk Search 09-21-2021
0 6
0
6
zacksoft_wf
Is there any way to know what splunk apps/add-ons I have access to ?Like using  rest command or any other SPL ?
by zacksoft_wf Contributor in Splunk Search 09-21-2021
0 1
0
1
shaquibk
Hi Team,I have a query related to drilldown searches of notables. I want to export/show results of drilldown searches...
by shaquibk Explorer in Splunk Search 09-21-2021
0 0
0
0
mahbs
Hi, I'm a bit confused with the lookup command, I.e the syntax. lookup <lookup-table-name> <lookup-field1> AS <loca...
by mahbs Path Finder in Splunk Search 09-21-2021
3 7
3
7
DougiieDee
I have a csv file which has field Account and it has over 1000+. In my logs it is named as yourAccount. how do i find...
by DougiieDee Explorer in Splunk Search 09-20-2021
0 2
0
2
SS1
Hi,Can someone help with the regex for below log entry, i need regex to extract the below fields in red. Thanks for y...
by SS1 Path Finder in Splunk Search 09-20-2021
0 2
0
2
VR1225
Hi All,I'm new to Splunk.  I'm not much familiar with the query search and lookup files. I have a custom IOC file wit...
by VR1225 New Member in Splunk Search 09-20-2021
0 0
0
0
corehan
Hello dears,How can i change search result limit ? At this moment, max 10K line shown.. 
by corehan Explorer in Splunk Search 09-20-2021
0 2
0
2
korhanacar
Hello All,I have a quick question about comparison fields from a lookup table.  Just imagine that I have a query like...
by korhanacar Engager in Splunk Search 09-20-2021
0 2
0
2
kishan2356
I have a inputlookup search where I am looking to do a current count vs four week average count. My search is set up ...
by kishan2356 Explorer in Splunk Search 09-20-2021
0 6
0
6
indeed_2000
hihow can i show max duration per servername?  index="my-index"       | rex "duration\[(?<duration>\d+.\d+)"| rex "id...
by indeed_2000 Motivator in Splunk Search 09-20-2021
0 2
0
2
Madhusri
Hi,When using iplocation to get the Country list ,maximum i am getting null values for Country.How to get the exact c...
by Madhusri Engager in Splunk Search 09-20-2021
0 1
0
1
hiteshkh
Im working on extracting Source Network Address's from Splunk I've spent the past few hours defining my query and aft...
by hiteshkh Explorer in Splunk Search 09-20-2021
0 3
0
3
JuanAntunes
Hello team! How are u?I have a question about how to search with a comma separated values: Example:I have an index wi...
by JuanAntunes Explorer in Splunk Search 09-20-2021
0 4
0
4
francesco1g
Hi, i have more ip address in a field like this:host |     IP              h1         10.0.2.2; 10.0.2.1h2         10...
by francesco1g Engager in Splunk Search 09-20-2021
0 1
0
1
splunknewbie81
Hi,Due to come compliance issue, there is a need to search for logs from 10pm to the following day 10am. This has to ...
by splunknewbie81 Engager in Splunk Search 09-20-2021
0 8
0
8
LiquidTension
A user within my organization was attempting to search for various windows events that indicated that somebody modifi...
by LiquidTension Path Finder in Splunk Search 09-20-2021
2 2
2
2
shanaz
Please suggest a splunk query to find whether email abc@def.com successfully sent emails or any emails failed between...
by shanaz Engager in Splunk Search 09-20-2021
0 2
0
2
AnnexQ
Hi,I have two table.The first have few ip what i switched dotdecimal   splunk_server="xyserver" index=main source="/v...
by AnnexQ Explorer in Splunk Search 09-20-2021
0 6
0
6
francesco1g
Hi, from two columns, in order to create a report, i need to remove the elements that are present twice, not only rem...
by francesco1g Engager in Splunk Search 09-20-2021
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...