Splunk Search

Splunk Search
Community Activity
LegalPrime
I am running following search query to obtain history of triggered alerts (time, name, severity), manually: index=_au...
by LegalPrime Path Finder in Splunk Search 06-28-2021
0 0
0
0
rilee
I have a search result like below:{ [-]   dt: 2021-06-24T22:46:40.7013297Z   flds: [ [-]     { [-]       fn: username...
by rilee Explorer in Splunk Search 06-28-2021
0 4
0
4
jerrysplunk88
trying to display two timecharts together, to make it easy to spot the time when no response received for the request...
by jerrysplunk88 Explorer in Splunk Search 06-27-2021
0 3
0
3
dyapasrikanth
I am trying to compare count of events with previous days within business hours, here is my query  index=abc | search...
by dyapasrikanth Path Finder in Splunk Search 06-27-2021
0 5
0
5
vinod743374
This is my _raw data consists06/24/2021 17:26:17 +0530, info_search_time=1624535777.471, Dns Rule=Passed, HOSTNAME=Pa...
by vinod743374 Communicator in Splunk Search 06-27-2021
0 8
0
8
sudhakar_mnsr
How to plot http error % as timeseries? (when I add _time or timeseries count Iam getting DAG: Execution exception (s...
by sudhakar_mnsr New Member in Splunk Search 06-27-2021
0 4
0
4
pankajad
There are 100s  of APIs in my application. I'm logging exception for an API. I can get stats to get total no of excep...
by pankajad Explorer in Splunk Search 06-27-2021
0 3
0
3
tchankapi
I am trying to find matches for field b, when there is a partial match in field a. I have field a which is an importe...
by tchankapi Engager in Splunk Search 06-26-2021
0 1
0
1
evelenke
Hi Splunkers, I was stuck with cutting the part of string for drilldown value from a chart using the <eval token>. S...
by evelenke Contributor in Splunk Search 06-26-2021
0 3
0
3
gliptak
Running| makeresults | eval s="foo\nbar" displaysfoo\nbarand it is unclear if the variable has a newline or just cont...
by gliptak Explorer in Splunk Search 06-26-2021
0 4
0
4
IcyPenguin
Hello everyone,I am new to Splunk and learning the ropes. I am stuck on a query I am trying setup. I have SNMP data c...
by IcyPenguin Loves-to-Learn Lots in Splunk Search 06-25-2021
0 0
0
0
Sentira
Hi,I've written a query query below which joins 2 different event types from same source with different filters.sourc...
by Sentira Explorer in Splunk Search 06-25-2021
0 8
0
8
yvassilyeva
Hi,I have a column chart with multiple overlaying fields (see blue orange and yellow lines below). Right now i am dis...
by yvassilyeva Path Finder in Splunk Search 06-25-2021
0 0
0
0
kirrusk
I have a CSV file with the below data, trying to push to Splunk.Example - Thu JUN 24  15:27:52 +08 2021,name1,address...
by kirrusk Communicator in Splunk Search 06-25-2021
0 1
0
1
FyazIkram834
So currently  i have:|Name                     | Branch                    | Age-------------------------------------...
by FyazIkram834 Engager in Splunk Search 06-25-2021
0 6
0
6
pagnihot
Is there a way to monitor the searches for some specific fields?Let's say I wish to monitor if anyone is running any ...
by pagnihot Path Finder in Splunk Search 06-25-2021
0 2
0
2
ookamidono
I am encountering problems joining 2 querries that are getting values from 2 different sourcetypes.I would like to ge...
by ookamidono Explorer in Splunk Search 06-25-2021
0 3
0
3
a_n
Hello,I am ingesting  files containing host and ports for each host.For each Source (FILE) The Nodes(host) and ports ...
by a_n Path Finder in Splunk Search 06-25-2021
0 2
0
2
bhavinsatwani65
I want to get error logs counts from windows event logs from multiple servers.Want to create a separate dashboard whe...
by bhavinsatwani65 New Member in Splunk Search 06-25-2021
0 5
0
5
hvdtol
Hello,I have a directory structure which i want split up in separate events.For example\MAIN\SUB1\SUB2\SUB3\file.xlsx...
by hvdtol Path Finder in Splunk Search 06-25-2021
0 4
0
4
Tejesh
Kindly help me out with Query to find top 10 indexers w.r.t index max allocated storage.
by Tejesh Observer in Splunk Search 06-25-2021
0 0
0
0
nasha430
Hi.I have one problem. It is truncated subsearch result.   index="test-index01" sourcetype="test_sourcetype" user="*"...
by nasha430 Explorer in Splunk Search 06-25-2021
0 1
0
1
ashriram
Hi I have the data that looks like thisuser, ip, (metrics kv pairs)---- sample results for search -- user=user1,ip=10...
by ashriram Engager in Splunk Search 06-25-2021
0 4
0
4
franks59
All my dashboards panels, written in Simple XML, default to Search Mode "Fast" when the "Open In Search" icon is sele...
by franks59 Explorer in Splunk Search 06-24-2021
1 4
1
4
kirrusk
Hi All,I have a CSV file with the below data, trying to push to splunk. Example - Thu JUN 24  15:27:52 +08 2021,name1...
by kirrusk Communicator in Splunk Search 06-24-2021
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...