Splunk Search

Splunk Search
Community Activity
LMN007
I have a json list like this:package: [{duration: 100, name: a}, {duration: 90, name: b} ...]and I want to show the t...
by LMN007 Engager in Splunk Search 06-22-2021
0 2
0
2
utk123
I have a table with more than 50000 hostnames. I want to run a wild card for 5th & 6th character in a hostname list.M...
by utk123 Path Finder in Splunk Search 06-22-2021
0 2
0
2
eid1550
Hi. I have an event that has the line "Total time taken for process: 535 ms" in it. it's not in a field it's just a r...
by eid1550 New Member in Splunk Search 06-22-2021
0 1
0
1
Traer001
Hello,I have log entries that look like this:2021-06-21 16:36:14 Error Fix Success for issue submitted by user:142021...
by Traer001 Path Finder in Splunk Search 06-22-2021
0 3
0
3
dcase999
Hi,I have a MV field that I need to split apart into other mv fieldsHere is the result of the querydcase999_0-1624379...
by dcase999 Engager in Splunk Search 06-22-2021
0 4
0
4
3666142
I have a panel that is a single value that only shows the Health Status as "UP" or "DOWN".  If it is "UP" I want it t...
by 3666142 Path Finder in Splunk Search 06-22-2021
0 3
0
3
MarekKrzak
Hi I'm trying to join data from same index but with different marker field and multiple values in second index. Examp...
by MarekKrzak Observer in Splunk Search 06-22-2021
0 1
0
1
kmaron
We keep getting this "empty" log back whenever we do a search within this host/sourcetype. It doesn't seem to matter ...
by kmaron Motivator in Splunk Search 06-22-2021
0 0
0
0
aintechco
HiTry to build a table for the below requirementFirst Column: url2nd Column: jun20213rd Column: May2021.....URL      ...
by aintechco New Member in Splunk Search 06-22-2021
0 3
0
3
WindWalker
So I am writing a query and It all gets piped into stats at the end. There is a value that I want to use to remove li...
by WindWalker Engager in Splunk Search 06-22-2021
0 1
0
1
aohls
I have a field with error messages that I need a case statement to cleanup for reporting. In this case some of the me...
by aohls Contributor in Splunk Search 06-22-2021
0 3
0
3
moinyuso96
I have a field "Date" as below. However, there are some inconsistency in the date format.  How can I get the "30/1/20...
by moinyuso96 Path Finder in Splunk Search 06-22-2021
0 1
0
1
jacques
I am trying to run a simple query, but with a catch.  I want to run something like this:index=weblogs somedomain.com ...
by jacques Loves-to-Learn in Splunk Search 06-22-2021
0 7
0
7
coreyCLI
We have a SHC at version 8.1.3.  When we try to use "earliest" and "latest" in search we get results based on the ear...
by coreyCLI Communicator in Splunk Search 06-22-2021
0 1
0
1
abdul
Hi,want to achieve daily,weekly ,monthly,  yearly reportempDirectory.csv contains Employee ID,Employee  Name, Manager...
by abdul Explorer in Splunk Search 06-22-2021
0 1
0
1
moinyuso96
For example, I would like certain rows "ABC" to have less indextime than "DEF". In normal search, "DEF" would have th...
by moinyuso96 Path Finder in Splunk Search 06-21-2021
0 0
0
0
balcv
How do I take the results of a search pass a field into a dbxquery and then display results from both the search and ...
by balcv Contributor in Splunk Search 06-21-2021
0 0
0
0
rrovers
I use timechart to count the events per month by department| timechart span=1mon count AS Aantal by departmentafter t...
by rrovers Contributor in Splunk Search 06-21-2021
0 4
0
4
sphiwee
How can I get STP as a bar chart ? im getting error when i try to do it like this sphiwee_0-1624211848747.png i want ...
by sphiwee Contributor in Splunk Search 06-21-2021
0 4
0
4
wilcomply13
I've been troubleshooting an issue with a search time field extractions of a JSON field being truncated at 4096 chara...
by wilcomply13 Explorer in Splunk Search 06-21-2021
0 0
0
0
rberman
Is it possible to use the value derived from one search and pass it to another search? For example, I have a search a...
by rberman Path Finder in Splunk Search 06-21-2021
0 4
0
4
abby_xr
Based on my dataset, I have 10 items in total and I wanna generate a new field randomly for each different item. E.g....
by abby_xr Splunk Employee Splunk Employee in Splunk Search 06-21-2021
0 0
0
0
trojan_81
Can someone help me break down this portion of a search? Is it saying, look for anything older than 30 minutes? eval ...
by trojan_81 Path Finder in Splunk Search 06-21-2021
0 1
0
1
dilenthakuri
Hi Guys,I am just wondering if anyone can put me in the right direction - I have a question about search queries in S...
by dilenthakuri Explorer in Splunk Search 06-21-2021
0 5
0
5
sasankganta
I'm searching for list of indexes using|tstats count where index=* sourcetype=log4j  by index sourcetypeI got results...
by sasankganta Path Finder in Splunk Search 06-21-2021
0 1
0
1
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors