Splunk Search

Splunk Search
Community Activity
MarekKrzak
Hi I'm trying to join data from same index but with different marker field and multiple values in second index. Examp...
by MarekKrzak Observer in Splunk Search 06-22-2021
0 1
0
1
kmaron
We keep getting this "empty" log back whenever we do a search within this host/sourcetype. It doesn't seem to matter ...
by kmaron Motivator in Splunk Search 06-22-2021
0 0
0
0
aintechco
HiTry to build a table for the below requirementFirst Column: url2nd Column: jun20213rd Column: May2021.....URL      ...
by aintechco New Member in Splunk Search 06-22-2021
0 3
0
3
WindWalker
So I am writing a query and It all gets piped into stats at the end. There is a value that I want to use to remove li...
by WindWalker Engager in Splunk Search 06-22-2021
0 1
0
1
aohls
I have a field with error messages that I need a case statement to cleanup for reporting. In this case some of the me...
by aohls Contributor in Splunk Search 06-22-2021
0 3
0
3
moinyuso96
I have a field "Date" as below. However, there are some inconsistency in the date format.  How can I get the "30/1/20...
by moinyuso96 Path Finder in Splunk Search 06-22-2021
0 1
0
1
jacques
I am trying to run a simple query, but with a catch.  I want to run something like this:index=weblogs somedomain.com ...
by jacques Loves-to-Learn in Splunk Search 06-22-2021
0 7
0
7
coreyCLI
We have a SHC at version 8.1.3.  When we try to use "earliest" and "latest" in search we get results based on the ear...
by coreyCLI Communicator in Splunk Search 06-22-2021
0 1
0
1
abdul
Hi,want to achieve daily,weekly ,monthly,  yearly reportempDirectory.csv contains Employee ID,Employee  Name, Manager...
by abdul Explorer in Splunk Search 06-22-2021
0 1
0
1
moinyuso96
For example, I would like certain rows "ABC" to have less indextime than "DEF". In normal search, "DEF" would have th...
by moinyuso96 Path Finder in Splunk Search 06-21-2021
0 0
0
0
balcv
How do I take the results of a search pass a field into a dbxquery and then display results from both the search and ...
by balcv Contributor in Splunk Search 06-21-2021
0 0
0
0
rrovers
I use timechart to count the events per month by department| timechart span=1mon count AS Aantal by departmentafter t...
by rrovers Contributor in Splunk Search 06-21-2021
0 4
0
4
sphiwee
How can I get STP as a bar chart ? im getting error when i try to do it like this  i want to display STP for each mon...
by sphiwee Contributor in Splunk Search 06-21-2021
0 4
0
4
wilcomply13
I've been troubleshooting an issue with a search time field extractions of a JSON field being truncated at 4096 chara...
by wilcomply13 Explorer in Splunk Search 06-21-2021
0 0
0
0
rberman
Is it possible to use the value derived from one search and pass it to another search? For example, I have a search a...
by rberman Path Finder in Splunk Search 06-21-2021
0 4
0
4
abby_xr
Based on my dataset, I have 10 items in total and I wanna generate a new field randomly for each different item. E.g....
by abby_xr Splunk Employee Splunk Employee in Splunk Search 06-21-2021
0 0
0
0
trojan_81
Can someone help me break down this portion of a search? Is it saying, look for anything older than 30 minutes? eval ...
by trojan_81 Path Finder in Splunk Search 06-21-2021
0 1
0
1
dilenthakuri
Hi Guys,I am just wondering if anyone can put me in the right direction - I have a question about search queries in S...
by dilenthakuri Explorer in Splunk Search 06-21-2021
0 5
0
5
sasankganta
I'm searching for list of indexes using|tstats count where index=* sourcetype=log4j  by index sourcetypeI got results...
by sasankganta Path Finder in Splunk Search 06-21-2021
0 1
0
1
middlemiddle
I need to create a field "search_hours" with values for every hour in (%H:00) format within the search window, whethe...
by middlemiddle Explorer in Splunk Search 06-21-2021
0 0
0
0
sphiwee
 index="acoe_np_spa_metrics" | search Project="*" AND Volume="*" | timechart span=1mon count(eval(D_Status="F")) as ...
by sphiwee Contributor in Splunk Search 06-21-2021
0 1
0
1
athorat
I need to get the list of Sourcetypes by Index in a Dashboard. I got this search from Splunk forums which gives the ...
by athorat Communicator in Splunk Search 06-21-2021
0 6
0
6
jason_hotchkiss
Hello - we are trying to calculate the possible_duration between the first event and last event in the following base...
by jason_hotchkiss Communicator in Splunk Search 06-21-2021
0 4
0
4
Learnersplunk21
Hi AllBelow is my query to tabulate a few fields together and count them on basis of its value .I need help with a si...
by Learnersplunk21 Engager in Splunk Search 06-21-2021
0 0
0
0
sasankganta
Index=A sourcetype=B and I can see under fields category filed "C" with count of 10k+ values ..But if I search with  ...
by sasankganta Path Finder in Splunk Search 06-21-2021
0 6
0
6
Get Updates on the Splunk Community!

Index This | What has many keys but can’t unlock a door?

July 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...
Top Solution Authors