Splunk Search

Splunk Search
Community Activity
VS0909
I want to execute a query in app1, but I want to get the data from app2For eg:Execute query in app1 "index="abc",  Th...
by VS0909 Communicator in Splunk Search 07-19-2021
0 5
0
5
elindemann
Hello there, I'm trying to monitor file access on our file server (Windows 2012 R2) with Splunk Light but I can't q...
by elindemann Engager in Splunk Search 07-19-2021
0 3
0
3
iainsmart
Hi, When I search for Windows Event Logs using : index=oswin sourcetype=XmlWinEventLog I'm not getting any pars...
by iainsmart Engager in Splunk Search 07-19-2021
0 4
0
4
joe06031990
Hi,I am looking on generating a search to find the 1% slowest requests from IIS logs however I am not sure if this is...
by joe06031990 Communicator in Splunk Search 07-19-2021
0 0
0
0
mhagoel
I have 2 query searches, one returns set result A and the other one returns set result B. I would like to get the res...
by mhagoel Engager in Splunk Search 07-19-2021
0 1
0
1
doki971
I receive a bunch of messages that all are assigned to a group by the groupID.I also have a dynamic set of a range as...
by doki971 Loves-to-Learn Everything in Splunk Search 07-19-2021
0 10
0
10
indeed_2000
HiI have file server that everyday backups of servers copy on that server on below path:/backup/files//backup/files/s...
by indeed_2000 Motivator in Splunk Search 07-19-2021
0 3
0
3
ezmo1982
Hi, I am using the Threat Intelligence datamodel in my Splunk ES environment. It is being populated with a Threat Int...
by ezmo1982 Path Finder in Splunk Search 07-19-2021
0 0
0
0
pkohn117
I am looking to run a search and filter out whitelisted exceptions in a lookup file.  2 of the fields could contain m...
by pkohn117 Explorer in Splunk Search 07-19-2021
0 5
0
5
szabolcs
Hi,I don't know if it is possible, but I would like to specify the time range of a join subsearch from a calculated v...
by szabolcs Explorer in Splunk Search 07-19-2021
0 4
0
4
cpm003
Hello,i´m looking to get this result between each start /end time.hope you could help me For example:Start timeEndti...
by cpm003 Path Finder in Splunk Search 07-19-2021
0 5
0
5
indeed_2000
HiI have log file like this:2021-07-15 00:00:01,869 INFO APP.InEE-p1-1234567 [AppListener] Receive Message[A123]: Q[p...
by indeed_2000 Motivator in Splunk Search 07-19-2021
0 10
0
10
VS0909
Need help with a Splunk query  to display % failures % failures = A1/A2 *100A1= Total number of events returned by th...
by VS0909 Communicator in Splunk Search 07-19-2021
0 5
0
5
5296
actionfeatureversionlocationcount?difference?Af1v1WA1200Af1v1OR11010Af1v1CA1155Bf1v1AZ1200Af1v2WA141Af1v2OR105Bf1v2AZ...
by 5296 Loves-to-Learn Lots in Splunk Search 07-19-2021
0 1
0
1
moinyuso96
I created some of the columns using regex. So all of the codes for the regex needs to be included. I would like to fi...
by moinyuso96 Path Finder in Splunk Search 07-18-2021
0 2
0
2
indeed_2000
Hii have log file like this: 2021-07-15 00:00:01,869 INFO client.InEE-server1-1234567 [AppListener] Receive Message[A...
by indeed_2000 Motivator in Splunk Search 07-17-2021
0 6
0
6
Laurengineer
I have a few sourcetypes, looking something like this:sourcetype=weatherdate, location, temperaturesourcetype=actions...
by Laurengineer Engager in Splunk Search 07-17-2021
0 1
0
1
asing13
Dear Community Members ,In splunk cloud instance :I am trying to get VPN login and logout for users in a single table...
by asing13 Path Finder in Splunk Search 07-17-2021
0 2
0
2
krusty
Hi there, we have an issue with hostname extraction from syslog events. Normaly the extraction works fine, but for ...
by krusty Contributor in Splunk Search 07-17-2021
0 7
0
7
splunkerer
Hi Folks,I am trying to enrich my search with subsearch in the same time bucket/bin. The search can be found below.De...
by splunkerer Path Finder in Splunk Search 07-17-2021
0 1
0
1
Lukas85
Hi AllI'm new on splunk and have following problem.We need data from a table depending on the value of a variable. Fo...
by Lukas85 New Member in Splunk Search 07-17-2021
0 1
0
1
jsturgeon
Hello, I am looking to clean up the result data from a Splunk query.How do I remove all the text prior to the user na...
by jsturgeon New Member in Splunk Search 07-16-2021
0 1
0
1
revanthammineni
Hello Splunkers.I'm working on some of the usecases on ES and one of the request that I've got from my upper manageme...
by revanthammineni Path Finder in Splunk Search 07-16-2021
0 2
0
2
shashi584
We have 3 different (Active,Closed,Resolved) records for same Incident and we need to retrieve only Active incident r...
by shashi584 Explorer in Splunk Search 07-16-2021
0 6
0
6
splunkcol
 I have 3 different indexes and they asked me to search by document number.The structure of the logs is different inc...
by splunkcol Builder in Splunk Search 07-16-2021
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...