Splunk Search

Splunk Search
Community Activity
SplunkDash
Hello,What would be my TIME_FORMAT for prop configuration file for this events2021-06-08T13:26:53.665000-04:00|PGM|mt...
by SplunkDash Motivator in Splunk Search 08-13-2021
0 5
0
5
Sirius27
I have two results of servers list as per last 30 days and last 12 hrs. I want to compare and find out which servers ...
by Sirius27 New Member in Splunk Search 08-12-2021
0 3
0
3
dbrooks_CIR
I have an index which contains data from many logfiles. I want to search for specific data in log1 and display  with ...
by dbrooks_CIR New Member in Splunk Search 08-12-2021
0 1
0
1
paras
We use cribl for field extraction. `Action` is a field that is being parsed from cribl and it should be a indexed fie...
by paras Explorer in Splunk Search 08-12-2021
0 1
0
1
SplunkDash
Hello, how can I write TIME_PREFIX for props conf file for following sample event. Any help will be highly appreciate...
by SplunkDash Motivator in Splunk Search 08-12-2021
0 2
0
2
munisb
Hi,I am trying to return values that DO NOT MATCH the search between an index and .csv fileEx - this returns the valu...
by munisb Explorer in Splunk Search 08-12-2021
0 1
0
1
SplunkDash
Hello,I am a source file which has  events with 2 different file formats. How would I write  TIME_FOMAT for my PROPS ...
by SplunkDash Motivator in Splunk Search 08-12-2021
0 1
0
1
SplunkDash
Hello, I was trying to write PROPS configuration file following sample events...2021-06-08T13:26:53.665000-04:00|PGM|...
by SplunkDash Motivator in Splunk Search 08-12-2021
0 1
0
1
truongvinh2112
My log is formatted like this:labels: {<!-- -->       app: splunk-kubernetes-metrics       app.kubernetes.io/managed-by: Helm...
by truongvinh2112 New Member in Splunk Search 08-12-2021
0 4
0
4
nnonm111
index&#61;"www1" sourcetype&#61;"access_combined_wcookie" action&#61;* status&lt;&#61;400| timechart span&#61;1d count(action) by clientip u...
by nnonm111 Path Finder in Splunk Search 08-12-2021
0 1
0
1
samkaj
I am using loadjob to load an already scheduled report that contains more than 2 million results. But when i try to f...
by samkaj Explorer in Splunk Search 08-12-2021
0 7
0
7
Mrig342
Hi All,I am using below query to search for certain logs:index&#61;int_gcg_apac_solace_166076 host&#61;"mwgcb-csrla0*U*" sour...
by Mrig342 Contributor in Splunk Search 08-12-2021
0 2
0
2
madhav_dholakia
Hi There, I have got incidents data in below format: dateRaised, IncID, Location, Status, closedDate 05-05-20, 1234...
by madhav_dholakia Contributor in Splunk Search 08-12-2021
0 5
0
5
phamxuantung
I have a query index &#61; "index1" |spath output&#61;error_code input&#61;RAW_DATA path&#61;MsgSts.Cd |dedup SESSIONID |stats count ...
by phamxuantung Communicator in Splunk Search 08-12-2021
0 2
0
2
Bleepie
Dear Community, I have the following search query: index&#61;"myIndex" host&#61;"myHost" source&#61;"mySource.log" 20210811053...
by Bleepie Communicator in Splunk Search 08-12-2021
0 4
0
4
Tomas_K
Hi all,Is it possible pass multiple value to a Token from one search to another? This is what I try to do.First Panel...
by Tomas_K Explorer in Splunk Search 08-11-2021
0 3
0
3
msage
I'm looking to combine data from a lookup file to data from our security server to create a comparison chart between ...
by msage Path Finder in Splunk Search 08-11-2021
0 5
0
5
richtate
I have network logs that show various network device communication that are in an index in Splunk.  I have another in...
by richtate Path Finder in Splunk Search 08-11-2021
0 13
0
13
pjtbasu
Hi, I've a lookup that looks like this - clientid url abc accounts/*/balanceabc accounts/*/namexyz /user/*/details An...
by pjtbasu Explorer in Splunk Search 08-11-2021
0 2
0
2
Raghork
We want to replicate this table (especially the circled row).We have to divide data (from 1 to 3 and from 4 to 6) for...
by Raghork Loves-to-Learn Lots in Splunk Search 08-11-2021
0 0
0
0
brennson90
Hi community,i have the following tstats output"| tstats count WHERE fromzone&#61;"*INTRANET*" index&#61;*_*_* by index sourc...
by brennson90 Path Finder in Splunk Search 08-11-2021
0 2
0
2
silverdiver
Hello,I have the following SPL command : |tstats count where index&#61;main host IN (H1,H2) by host, _time span&#61;1h | pred...
by silverdiver New Member in Splunk Search 08-11-2021
0 1
0
1
Felix82
Hey Splunk- community, I need your help again. My data are events which reports disturbments. "action&#61;kommend" marks ...
by Felix82 Explorer in Splunk Search 08-11-2021
0 4
0
4
chohye12
index&#61;"performance" sourcetype&#61;"physical_cpu"| addtotals fieldname&#61;CPU_SUM CPU_*| rex mode&#61;sed field&#61;_raw "s/ //g"| e...
by chohye12 New Member in Splunk Search 08-11-2021
0 3
0
3
Ashutosh_30
Hi All ,i have configured alerts for the search below:index&#61;"ebs_red_0" host&#61;"dev-obiee-ux0*" source&#61;"/obiee_12c/app/...
by Ashutosh_30 Loves-to-Learn in Splunk Search 08-11-2021
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...