Splunk Search

Splunk Search
Community Activity
pavanae
I have a csv file query as follows :- | inputlookup file_1.csvwhich gives the result as follows in a single line as a...
by pavanae Builder in Splunk Search 09-03-2021
1 1
1
1
rkishoreqa
Hi team,  I am creating a query to fetch a unique id from different events which are having different statuses.  If t...
by rkishoreqa Communicator in Splunk Search 09-03-2021
0 4
0
4
D0do
Hello everybody,I'm using an spl query that extracts some values from a lookup and sends them to a web API via POST r...
by D0do Explorer in Splunk Search 09-03-2021
0 2
0
2
nnonm111
There are multiple sourcetypes in index="main".I'm trying to stats at SOURCETYPE number one and I need a field of sou...
by nnonm111 Path Finder in Splunk Search 09-03-2021
0 3
0
3
kfennell
I'm unable to use the Validate & Package function of Add-on builder. When I run it, it says 'preparing validation' th...
by kfennell Engager in Splunk Search 09-02-2021
0 0
0
0
Madhusri
Hi,I need to calculate average of response time in seconds for my application. Query i am usingindex="prod*_ping*"  s...
by Madhusri Engager in Splunk Search 09-02-2021
0 3
0
3
ebs
Hi,I'm having an odd issue. I made some field extractions and validated them through Regex101. However only some of t...
by ebs Communicator in Splunk Search 09-02-2021
0 6
0
6
rohinisb91
I have two events as below -event 1  "id=1 api=xyz apiResTime=50" event 2 "id=1 api=xyz duration=200" I want to plot...
by rohinisb91 Observer in Splunk Search 09-02-2021
0 1
0
1
nsingh49
This is my splunk query index=xxxxx "searchTerm")|rex "someterm(?<errortype>)" | timechart count byerrortype span ="1...
by nsingh49 Explorer in Splunk Search 09-02-2021
0 2
0
2
SplunkLunk
Greetings,I want to exclude search results if a field contains a value compared against another field with additional...
by SplunkLunk Path Finder in Splunk Search 09-02-2021
0 1
0
1
sarit_s
Helloi have a table that looks like this : and i want it to look like this: so the type values will be the header wha...
by sarit_s Communicator in Splunk Search 09-02-2021
0 16
0
16
vantoryc
Hi,We are sending a reduced size logs to out splunk to do some smarts. We realized for the past year or so one of our...
by vantoryc Explorer in Splunk Search 09-02-2021
0 9
0
9
opamlan
Hi,I want to search    "xyzetc\";0,                   ---this is my string .Unable to search this exact pattern, Unba...
by opamlan Loves-to-Learn in Splunk Search 09-02-2021
0 1
0
1
homer07
I'm trying to calculate percentages based on the number of events per vary group. There are actually a lot of events,...
by homer07 Explorer in Splunk Search 09-02-2021
0 4
0
4
TheEggi98
I want to use the subsearch to get start and endtime of the newest transaction (here a botsession).The subsearch alon...
by TheEggi98 Path Finder in Splunk Search 09-02-2021
0 3
0
3
sarit_s
HelloI have a table with 3 columns1 is stringsand 2 columns with numbersis there a way to sort the table from the hig...
by sarit_s Communicator in Splunk Search 09-02-2021
0 6
0
6
Madhusri
Hi,Current piechartIn the above piechart highlighted cities details are not displaying.have to use mouse over to chec...
by Madhusri Engager in Splunk Search 09-02-2021
0 1
0
1
splunknewbie81
Hi Guys, I would like to check if it's possible to prevent some data from showing up in the search. Below is what I w...
by splunknewbie81 Engager in Splunk Search 09-02-2021
0 5
0
5
Harshi1993
My query is :index="stage*" source="*record service*" | eval type=case(like(message, "%successful generated account%"...
by Harshi1993 New Member in Splunk Search 09-02-2021
0 3
0
3
mcaulsc
Hi,I have data as below sample:Date Time val1 val2 val3 ......21/08/31 01:00:00 2 1 2 2 2 2 2 1 1 2 69 1 0 2 0 0 3 32...
by mcaulsc Path Finder in Splunk Search 09-02-2021
0 2
0
2
splunknewbie81
Hi All, I am having some trouble extracing out the following with the following details 1. username 2. Default Msg3. ...
by splunknewbie81 Engager in Splunk Search 09-02-2021
0 12
0
12
btshivanand
Hi all,We have 3 search heads are in cluster. serach head 1 is captain.Recently we upgraded to 7.2.3 to 8.0.3.after t...
by btshivanand Path Finder in Splunk Search 09-01-2021
0 3
0
3
rczone
Hello All, So i have a field like below with JSON file   {"results_appcodes": [{"count": 2, "app_code": "XYZ", "group...
by rczone Path Finder in Splunk Search 09-01-2021
0 7
0
7
SplunkDash
Hello,How I would write my Props Configuration (Tme Prefix, Time Format,  LINE/EVENT Breaker...etc) for following HTM...
by SplunkDash Motivator in Splunk Search 09-01-2021
0 5
0
5
SplunkDash
Hello,I have some issues using following input configuration file for windows machine: [monitor://T:\Toshtest\logs\te...
by SplunkDash Motivator in Splunk Search 09-01-2021
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...