Splunk Search

Splunk Search
Community Activity
hughkelley
Background:I've created a small function in a spark/Databricks notebook that uses Splunk's splunk-sdk  package.  The ...
by hughkelley Path Finder in Splunk Search 10-30-2024
0 0
0
0
whitefang1726
Hi Splunkers, How can I create a single value field based on multiple fields? Also, let's assume that the field names...
by whitefang1726 Path Finder in Splunk Search 10-30-2024
0 2
0
2
xaviershebha
index=web_logs sourcetype=access_combined | eval request_duration=round(duration/1000, 2) | stats avg(request_durat...
by xaviershebha New Member in Splunk Search 10-30-2024
0 1
0
1
Mick_OBrien
Hi All I have a search string ... index="ee_apigee" vhost="rbs" uri="/eforms/v1.0/cb/*" | rex "(?i) .*?=\"(?P<httpsta...
by Mick_OBrien Path Finder in Splunk Search 10-30-2024
0 1
0
1
JandrevdM
Good day,Is there a way to join all my rows into one?My simple query  index=collect_identities sourcetype=ldap:query ...
by JandrevdM Path Finder in Splunk Search 10-30-2024
0 9
0
9
Ckashton
I have data like this in splunk search2024-10-29 20:14:49 (715) worker.6 worker.6 txid=XXXX JobPersistence Total reco...
by Ckashton New Member in Splunk Search 10-30-2024
0 1
0
1
smanojkumar
Hello Splunkers,   I would like to pass the two base search when input dropdown is set as all, i need to pass a base ...
by smanojkumar Contributor in Splunk Search 10-29-2024
0 3
0
3
splunksuperman
Hi Guys,I have one master list that inculdes all items, and I want to consolidate two other time-related tables into ...
by splunksuperman Explorer in Splunk Search 10-29-2024
0 2
0
2
apmcharter
Hello,I need help in creating a search query to filter info showing just our logfile with same error line for all row...
by apmcharter New Member in Splunk Search 10-29-2024
0 1
0
1
JandrevdM
Good day,I want to join two indexes to show all the email addresses that the user have that signed in. This queries m...
by JandrevdM Path Finder in Splunk Search 10-29-2024
0 1
0
1
cimino
We have an on-prem Splunk-Enterprise Version: 9.0.4.1 We updated IDP url in the SAML configuration and after uploadin...
by cimino Engager in Splunk Search 10-29-2024
0 0
0
0
LearningGuy
Hello,Hello,How do I send email alert if  one or more subsearch exceed 50000 results?For example below I have 4 subse...
by LearningGuy Motivator in Splunk Search 10-29-2024
0 18
0
18
PotatoDataUser
So I have a lookup file with a complete list of servers and their details like version, owner etc, and an index my_in...
by PotatoDataUser Explorer in Splunk Search 10-29-2024
0 2
0
2
yuuki98696
splunkで以下のSPLをジョブのバックグラウンドに送りました。| metadata type=sourcetypes | search totalCount > 0その後、こちらのサーチのジョブを削除したのですが、splunkのサ...
by yuuki98696 New Member in Splunk Search 10-28-2024
0 0
0
0
SplunkUser001
Hello,I have these two events that are part of a transaction.These have the same s and qid. I need to match s and qid...
by SplunkUser001 Explorer in Splunk Search 10-28-2024
0 6
0
6
varsh_6_8_6
HiI am kinda stuck and need help. I am creating a chart in the splunk dashboard and for the y axis I have nearly 20 v...
by varsh_6_8_6 Explorer in Splunk Search 10-28-2024
1 2
1
2
andy11
I'm using a query which returns entire day data :   index="index_name" source="source_name"    And this search provid...
by andy11 Observer in Splunk Search 10-27-2024
0 5
0
5
Federica_92
I'm working with a dataset that lists companies and individual people, so that some entries have the field "Entity Na...
by Federica_92 Communicator in Splunk Search 10-25-2024
2 6
2
6
Splunked_Kid
Hellohow can I display only 1 value of these 3 "maxCapacitMachine" results (which are the same in all 3 cases) in a B...
by Splunked_Kid Explorer in Splunk Search 10-25-2024
0 5
0
5
sajjadali1122
I’m experiencing slow performance with my Splunk queries, especially when working with large datasets. What are some ...
by sajjadali1122 New Member in Splunk Search 10-25-2024
0 2
0
2
karthi2809
How to extract fields from below source./audit/logs/QTEST/qtestw-core_server4-core_server4.log I need extract QTEST ...
by karthi2809 Builder in Splunk Search 10-25-2024
0 2
0
2
Devinz
I need to replace the variables in the field rule_title field that is generated when using the `notable` macro. I was...
by Devinz Loves-to-Learn Lots in Splunk Search 10-25-2024
0 1
0
1
linaaabad
Hello Smarties... Can someone offer some assistance; We recently started ingesting Salesforce into Splunk, Username a...
by linaaabad Observer in Splunk Search 10-24-2024
0 2
0
2
unitedmarsupial
Some years ago I've created a (beautiful!) dashboard, with multiple panels, which presented related data at different...
by unitedmarsupial Path Finder in Splunk Search 10-24-2024
0 3
0
3
enb_splunk
Hello Everyone,Having a hard time finding the appropriate way to display data. I have duplicate data where one field ...
by enb_splunk Engager in Splunk Search 10-24-2024
0 1
0
1
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...