Splunk Search

Splunk Search
Community Activity
DATT
I have a working dashboard that displays a number of metrics and KPIs for the previous week.  Today, I was asked to e...
by DATT Path Finder in Splunk Search 10-22-2024
0 3
0
3
ramuzzini
Need help passing a token value from a Single Value Panel using the ( | stats count) in conjuction to the ( | rex fie...
by ramuzzini Path Finder in Splunk Search 10-21-2024
0 1
0
1
myusufe71
Hi,I need help to fetch field based on other field condition.I have lookup table  as below,NAME STATEabc-a-0 host1 ma...
by myusufe71 Explorer in Splunk Search 10-21-2024
0 1
0
1
SplunkUser001
Hi,I am trying to tie multiple events describing single transaction together.This is my test example: Event Oct 21 08...
by SplunkUser001 Explorer in Splunk Search 10-21-2024
0 1
0
1
LizAndy123
I have a log with a sample of the followingPOST Uploaded File Size for project id : 123 and metadata id : xxxxxxxxxxx...
by LizAndy123 Path Finder in Splunk Search 10-21-2024
0 3
0
3
dataisbeautiful
Hi SplukersI'm looking for cross compare some events with other system data, using an initial search for the event an...
by dataisbeautiful Communicator in Splunk Search 10-21-2024
0 10
0
10
dhineshv1
Hi,I have an log which show currency field and it will have all the valid currency codes like JPY, CNY, USD etc..I ne...
by dhineshv1 Engager in Splunk Search 10-20-2024
0 3
0
3
whipstash
I am having some issues getting this to work correctly. It does not return all the results. I have different records ...
by whipstash Engager in Splunk Search 10-19-2024
0 3
0
3
jibiuthaman
source aaa| eval Description=case(rt_sec>10, "G10", rt_sec>20, "G20", rt_sec>30, "G30", rt_sec>40, "G40") | stats cou...
by jibiuthaman Explorer in Splunk Search 10-18-2024
0 3
0
3
ramuzzini
Have working query to give me list of all printers, total job count, total page count and show location of printers u...
by ramuzzini Path Finder in Splunk Search 10-18-2024
0 2
0
2
bmer
Iam using splunk to generate as below.It is run for 2 days date range where am trying to compare the countClassName16...
by bmer Explorer in Splunk Search 10-18-2024
0 2
0
2
hariengg
Hi TeamSplunk is unable to read a file which has particular content as below. If the file contains other content, the...
by hariengg Engager in Splunk Search 10-18-2024
0 3
0
3
myusufe71
I have subquery result ashost1host2host2And I want to put this all host result as host=*  in the main query.1. subque...
by myusufe71 Explorer in Splunk Search 10-18-2024
0 3
0
3
tread_splunk
I have the following fabricated search which is a pretty close representation of what I actually want to do and gives...
by tread_splunk Splunk Employee Splunk Employee in Splunk Search 10-17-2024
0 1
0
1
PotatoDataUser
I am working on a dashboard that has a bunch of field and will be used by multiple teams and people who will be needi...
by PotatoDataUser Explorer in Splunk Search 10-17-2024
0 1
0
1
dwong-rtr
I currently do a search monthly for searches/jobs that take a long time. I then look up the job and if there is an al...
by dwong-rtr Explorer in Splunk Search 10-17-2024
0 4
0
4
tbayer82
Dear all, I'm trying to search for denied actions in a subnet, regardless if it is the source or destination. I tried...
by tbayer82 New Member in Splunk Search 10-17-2024
0 1
0
1
Siddharthnegi
I have a saved search which is scheduled but it is not showing and not running at the scheduled time.
by Siddharthnegi Contributor in Splunk Search 10-17-2024
0 4
0
4
Neekheal
Hi,I am having some problem to understand How to fetch multiline pattern in a single event.I have logfile in which I ...
by Neekheal Observer in Splunk Search 10-16-2024
0 8
0
8
Deprasad
I've the below event, where I need to display only event which has action=test and category=testdata. test { line1: 1...
by Deprasad Path Finder in Splunk Search 10-16-2024
0 3
0
3
mrminks
Hi All, newbie here - Sorry if my subject is poorly worded, I'm a little confused!I'm trying to add a field to the ta...
by mrminks Engager in Splunk Search 10-16-2024
0 2
0
2
gg_easy
Hello, My team has a search that uses a field called regex, containing a load of different regex expressions to match...
by gg_easy Engager in Splunk Search 10-16-2024
0 1
0
1
H2ck1ngPr13sT
HI,I have a below query, I want to group and count by two different words, one group per word, in a field "text1.valu...
by H2ck1ngPr13sT Loves-to-Learn in Splunk Search 10-16-2024
0 4
0
4
raghul725
Hello,I am looking to calculate how long it takes to refresh the view using the time of the events "End View Refresh"...
by raghul725 Explorer in Splunk Search 10-15-2024
0 10
0
10
msarkaus
Greetings, Please help!! I need to extract the ID value from the two events below, and I’m kinda banging my head here...
by msarkaus Path Finder in Splunk Search 10-15-2024
0 10
0
10
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...