Splunk Search

Splunk Search
Community Activity
JandrevdM
Good day,I am trying to figure out how I can join two searches to see if there is a service now ticket open for someo...
by JandrevdM Path Finder in Splunk Search 11-07-2024
0 1
0
1
tjsnow
I am trying to simply break down a url to extract the region and chart the use of specific urls over time. but i just...
by tjsnow Explorer in Splunk Search 11-07-2024
0 2
0
2
ddrillic
We suspect that some of our users run real time searches. How can I produce a report which shows real time search act...
by ddrillic Ultra Champion in Splunk Search 11-07-2024
0 7
0
7
kenbaugher
After looking at some examples online, I was able to come up with the below query, which can display one or more colu...
by kenbaugher Path Finder in Splunk Search 11-07-2024
0 2
0
2
ppolendey
Splunk Enterprise Version: 9.2.0.1OpenShift Version: 4.14.30 We used to have Openshift Event logs coming in under sou...
by ppolendey New Member in Splunk Search 11-07-2024
0 1
0
1
cbiraris
Can you please help me to build eval queryCondition-1ABC=MatchXYZ=Matchthen output of ABC compare to XYZ is MatchCond...
by cbiraris Path Finder in Splunk Search 11-07-2024
0 2
0
2
NatSec
I have a working dashboard where a token is used as a variable. But now I am trying to use the same concept when maki...
by NatSec Explorer in Splunk Search 11-07-2024
0 5
0
5
ramuzzini
Hello, I am trying to join two indexes to display data from our local printers.  I have an index getting data from ou...
by ramuzzini Path Finder in Splunk Search 11-06-2024
0 8
0
8
jdmeek
I have an index with events containing a src_ip but not a username for the event.   I have another index of VPN auth ...
by jdmeek Explorer in Splunk Search 11-06-2024
0 2
0
2
Noctisae
First of all, English isn't my native language, so I apologize in advance for any error I could write in this support...
by Noctisae Engager in Splunk Search 11-06-2024
0 8
0
8
mursidehsani
I have this queryis not mapped to ink name| rex "(?<time>\d{4}-\d{2}-\d{2}\s\d{2}:\d{2}:\d{2}).*Ink Type '(?<ink_type...
by mursidehsani Explorer in Splunk Search 11-05-2024
0 3
0
3
ajmach343
I am trying to make a search that will fire only when an admin makes a change to their own account.I want to know if ...
by ajmach343 Explorer in Splunk Search 11-05-2024
0 3
0
3
Dayalss
Hi,I have a huge set of data with different emails in it , I want to setup email alerts for few parameters.But the is...
by Dayalss Engager in Splunk Search 11-05-2024
0 3
0
3
smanojkumar
Hello There,    I would like to pass two diffrent values as a token, the search consists of code as a token, where co...
by smanojkumar Contributor in Splunk Search 11-05-2024
0 5
0
5
krishna1
I'm working with a query where I'm using a lookup to enrich events based on the work_queue field and then filtering t...
by krishna1 Explorer in Splunk Search 11-04-2024
0 1
0
1
Miguel3393
How can I make it show me only what appears as null in the Call.CallForwardInfo.OriginalCalledAddr field? Right now I...
by Miguel3393 Path Finder in Splunk Search 11-04-2024
0 4
0
4
tohalan
Hi Everyone, Need some help on how to display the output value as zero in a chart when a negative result is returned...
by tohalan New Member in Splunk Search 11-04-2024
0 2
0
2
sta_splunk
I have data similar to:Field-A Field-BA1           B1A1           B2A1           B3A2           B4A3           B5A2  ...
by sta_splunk Engager in Splunk Search 11-04-2024
0 3
0
3
JandrevdM
Good day,I am trying to figure out how I can join two searches to see if there is a service now ticket open for someo...
by JandrevdM Path Finder in Splunk Search 11-04-2024
0 4
0
4
Ninja_splunk
I'm looking for a query to display a list of jobs stuck in queue (the past 7 days). Does anyone knows the query? 
by Ninja_splunk Splunk Employee Splunk Employee in Splunk Search 11-03-2024
0 1
0
1
dinesh001kumar
I am having two index( index A and index B). Here I need to measure response time of topup of prepaid or postpaid num...
by dinesh001kumar Explorer in Splunk Search 11-03-2024
0 2
0
2
rukshar
Please help me to extract multiple values from one single value. 
by rukshar Explorer in Splunk Search 11-03-2024
0 7
0
7
Cheng2Ready
I have  2 field that holds 3 valuesField 1values= a,b,cField 2values= 1,2,3 Is there a way to table without using Joi...
by Cheng2Ready Communicator in Splunk Search 11-03-2024
0 1
0
1
unicornia
Hello team,I’ve developed a custom command script that works perfectly when executed through the CLI, but it fails to...
by unicornia New Member in Splunk Search 11-02-2024
0 2
0
2
tbessie
In my company's Splunk server, when I do a search, I usually see a difference in time between the "Time" column and t...
by tbessie New Member in Splunk Search 11-02-2024
0 6
0
6
Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...