Splunk Search

Splunk Search
Community Activity
silverdiver
Hello,I have the following SPL command : |tstats count where index=main host IN (H1,H2) by host, _time span=1h | pred...
by silverdiver New Member in Splunk Search 08-11-2021
0 1
0
1
Felix82
Hey Splunk- community, I need your help again. My data are events which reports disturbments. "action=kommend" marks ...
by Felix82 Explorer in Splunk Search 08-11-2021
0 4
0
4
chohye12
index="performance" sourcetype="physical_cpu"| addtotals fieldname=CPU_SUM CPU_*| rex mode=sed field=_raw "s/ //g"| e...
by chohye12 New Member in Splunk Search 08-11-2021
0 3
0
3
Ashutosh_30
Hi All ,i have configured alerts for the search below:index="ebs_red_0" host="dev-obiee-ux0*" source="/obiee_12c/app/...
by Ashutosh_30 Loves-to-Learn in Splunk Search 08-11-2021
0 2
0
2
nnonm111
What should I do to see the value of two counts?I want to see the number of clientips and destinations at the same ti...
by nnonm111 Path Finder in Splunk Search 08-11-2021
0 1
0
1
pjtbasu
Hi Team, I've a field name uri, which has value like this --/dev/{AccountNumber}/accountDetail/uat/{ContentID}/conten...
by pjtbasu Explorer in Splunk Search 08-10-2021
0 2
0
2
manojsrms
Hi, I am new to Splunk environment. I am trying to extract ModifiedAccountName, ModifiedAccountDomain, ModifiedLogonI...
by manojsrms Engager in Splunk Search 08-10-2021
1 2
1
2
jokovitch
I have a data in Splunk like FnameLnameCountryfname1lname1USAfname2lname2USAfname3lname3USA And I have file in Splunk...
by jokovitch Explorer in Splunk Search 08-10-2021
0 16
0
16
Susha
Hi Team,We have one field as Customer=ABC DEF where one space in between  where if i am giving any as Customer = *DEF...
by Susha Engager in Splunk Search 08-10-2021
0 2
0
2
Wendy
Hi experts, I am new to Splunk and came across this requirement at work.Requirement:I want to create a table showing ...
by Wendy Explorer in Splunk Search 08-10-2021
0 4
0
4
Rukmani_Splunk
Hi  ALL, I  have the below data in  a log  . Type = success or  error . region names( In, CN, EMEA, APAC)      Time  ...
by Rukmani_Splunk Path Finder in Splunk Search 08-10-2021
0 0
0
0
jmalachoSPL64
I am using the following query to retrieve events that I then display.  I would like to add another column that is th...
by jmalachoSPL64 Engager in Splunk Search 08-10-2021
0 2
0
2
vikramyadav
Hi Guys,I have created a simple query with stats command and I'm able to see the required results.If same search is r...
by vikramyadav Contributor in Splunk Search 08-10-2021
0 4
0
4
_Mauro_Costa_
HelloI have a query that gives me the data below:_time                                 | id                 | order_i...
by _Mauro_Costa_ Explorer in Splunk Search 08-10-2021
0 2
0
2
sam1010
Can anyone tell me the steps to deploy and configure multiple apps in a cluster with heavy forwarders. 
by sam1010 Explorer in Splunk Search 08-10-2021
0 5
0
5
phil_tt
This seems to be an odd issue or at least I've been searching for the wrong thing.  My event sourcetype is json and t...
by phil_tt Engager in Splunk Search 08-09-2021
0 2
0
2
codekiln
I'm seeking to make a spunk timechart of values that match a certain filter:source="/var/log/bcore/ws_metric*" event=...
by codekiln Explorer in Splunk Search 08-09-2021
0 1
0
1
ft_kd02
Hi all,I have a lookup and I'd like to filter based on tokenized value. The lookup dropdown also sets a different tok...
by ft_kd02 Path Finder in Splunk Search 08-09-2021
0 1
0
1
arist0telis
I've been having a hard time trying to get a Splunk search that will give me a count of all records in my Lead object...
by arist0telis Explorer in Splunk Search 08-09-2021
0 0
0
0
mpasini
Hello,After upgrading to Splunk 8 from Splunk 6, it seems that the "show_source" view  ( used in "Event actions" -> "...
by mpasini Engager in Splunk Search 08-09-2021
0 2
0
2
SplunkDash
 How would I write the props config file for following events, any help will be highly appreciated, thank you! Thu, 0...
by SplunkDash Motivator in Splunk Search 08-09-2021
0 10
0
10
Rajkumarkbm2
Dear Splunkers, I want to increment the fields value based on Some conditions as like below. Limit | Chang...
by Rajkumarkbm2 Explorer in Splunk Search 08-09-2021
1 4
1
4
vishaltaneja070
How can i extract this:"properties": {"nextLink": null,"columns": [{"name": "Cost", "type": "Number"},{"name": "Date"...
by vishaltaneja070 Motivator in Splunk Search 08-09-2021
0 1
0
1
N-W
I have a dashboard with several different base searches that is transformative searches. However I get the error of m...
by N-W Explorer in Splunk Search 08-09-2021
0 1
0
1
ebs
Hi,I have several datasets that have the exact same format with only the source of the data differing. I've duplicate...
by ebs Communicator in Splunk Search 08-09-2021
0 1
0
1
Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Data Management Digest – June 2026

Welcome to the June 2026 edition of Data Management Digest! This month’s update is short and sweet, with a ...

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...