Splunk Search

Splunk Search
Community Activity
anayi
I'm trying to create an alert. The alert's query ends with " | stats values(*) as * by actor.displayName | stats coun...
by anayi Observer in Splunk Search 10-03-2024
0 2
0
2
JandrevdM
Good day,I have done a join on two indexes before to add more information to one event. example get department for a ...
by JandrevdM Path Finder in Splunk Search 10-03-2024
0 1
0
1
JandrevdM
Good day,I am trying to find the latest event for my virtual machines to determine if they are still active or decomm...
by JandrevdM Path Finder in Splunk Search 10-03-2024
0 4
0
4
th1agarajan
My Splunk Search is as followsindex="someindex" cf_space_name="somespace" msg.severity="*" | rex field=msg.message "....
by th1agarajan Path Finder in Splunk Search 10-02-2024
0 1
0
1
prakashbhanu407
I have a requirement to Trigger Splunk Alerts Bi-Weekly Mondays (Not 1st and 3rd OR 2nd and 4th weeks) and if a mont...
by prakashbhanu407 New Member in Splunk Search 10-02-2024
0 6
0
6
Abass42
I have a dashboard that a specific team uses. Today, they asked about why one of the panels was broken. Looking into ...
by Abass42 Communicator in Splunk Search 10-02-2024
0 0
0
0
darkins
probably a basic questioni have the following data 600 reasonand this rex(?<MetricValue>([^\s))]+))(?<Reason>([^:|^R]...
by darkins Engager in Splunk Search 10-01-2024
0 2
0
2
alferone
Hello everyone, I have a table (generated from stats) that has several columns, and some values of those columns have...
by alferone Explorer in Splunk Search 10-01-2024
0 3
0
3
nelesama
An extension of this:https://community.splunk.com/t5/Splunk-Search/Looking-at-yesterdays-data-but-need-to-filter-the-...
by nelesama Explorer in Splunk Search 10-01-2024
0 4
0
4
msalghamdi
Hello SplunkersHow can i utilize a lookup in a correlation search showing the detected keyword in the search result ?...
by msalghamdi Path Finder in Splunk Search 10-01-2024
0 5
0
5
tread_splunk
Sometimes I set myself SPL conundrum challenges just to see how to solve them.  I realised I couldn't do something I ...
by tread_splunk Splunk Employee Splunk Employee in Splunk Search 10-01-2024
0 8
0
8
varsh_6_8_6
I have to create a base search for a dashboard and I am kinda stuck. Any help would be appreciated. index=service msg...
by varsh_6_8_6 Explorer in Splunk Search 09-30-2024
0 2
0
2
robertlynch2020
Hi I am looking to monitor the dispatch directory over time.I know I can get the current results by using this| rest ...
by robertlynch2020 Influencer in Splunk Search 09-30-2024
0 3
0
3
DLevine_
I am working on obtaining all user logins for a specified domain, then displaying what percent of those logins were f...
by DLevine_ Explorer in Splunk Search 09-30-2024
0 4
0
4
Glasses2
I have noticed that a saved search is chronically skipped, almost 100% but I cannot trace it back to the origin.The s...
by Glasses2 Communicator in Splunk Search 09-30-2024
0 4
0
4
raculim
Hi, I'm having a hard time trying to narrow down my search results. I would like to return only the results that cont...
by raculim Explorer in Splunk Search 09-30-2024
0 6
0
6
ravi_lookout
I have 2 indexes - index_1 and index_2index_1 has the following fieldsindex1IdcurrEventIdprevEventIdindex_2 has the f...
by ravi_lookout Explorer in Splunk Search 09-30-2024
0 10
0
10
BoscoBaracus
Good morning fellow splunkers.I have a challenge and was wondering if anyone could help me. In some logs with multipl...
by BoscoBaracus Engager in Splunk Search 09-30-2024
0 5
0
5
elend
hello, I have an issue when creating some visualization in splunk dashboard. Im using dashboard studio, and my object...
by elend Communicator in Splunk Search 09-28-2024
0 5
0
5
yuanliu
Here is a really simple dashboard: <form version="1.1" theme="light"> <label>Simple input</label> <fieldset submi...
by SplunkTrust SplunkTrust in Splunk Search 09-28-2024
0 1
0
1
risingflight143
Hi All I am using Office365,  i have an office365 unified group and users are getting removed from this office365 gro...
by risingflight143 Explorer in Splunk Search 09-28-2024
0 1
0
1
sivaranjiniG
I have to create a custom command using python script to update a particular property(enableSched) from 1 to 0 or 0 t...
by sivaranjiniG Communicator in Splunk Search 09-28-2024
0 1
0
1
Naveenkumar
Hi Splunk,I have a table like belowComponent Green Amber RedResp_time 0 200 4005xx 0 50 1004xx 0 50 100 I want to com...
by Naveenkumar Engager in Splunk Search 09-28-2024
0 3
0
3
mark_groenveld
I would like to compare specific response status stats vertically and not horizontally so that the values line up and...
by mark_groenveld Path Finder in Splunk Search 09-28-2024
0 2
0
2
qs_chuy
I was working with DataModels and I came across something strange about them when they are accelerated vs when they a...
by qs_chuy Engager in Splunk Search 09-27-2024
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...