Splunk Search

Splunk Search
Community Activity
Atif
Hi,I have some events like :---------------------------------TXID;RECEIVER;STATUSAA11;RCV00001;OKAA11;RCV00001;KOAA11...
by Atif Explorer in Splunk Search 06-08-2021
0 2
0
2
actionabledata
All, Hopefully a straightforward question.Is it possible to increase the following setting in a .../appname/local/lim...
by actionabledata Path Finder in Splunk Search 06-08-2021
0 1
0
1
Gene
Dear Splunkers, can you please help with the following problem:We use single instance and PaloAlto logs are sent thro...
by Gene Path Finder in Splunk Search 06-08-2021
0 3
0
3
vrmandadi
I am trying to  join two searches with a common fieldEvent1:Jun 7 14:55:37 v3**v sudo: pam_sss(sudo:auth): authentica...
by vrmandadi Builder in Splunk Search 06-08-2021
0 4
0
4
3DGjos
Hello, I have to parse this very custom LOG, and i'm having trouble figuring out how to do this: I have two differen...
by 3DGjos Communicator in Splunk Search 06-08-2021
0 10
0
10
Susha
Hi All,i have 221180 ips in csv(deattackerv1.csv)  with only one field "ip" .. where i want to check if we have any h...
by Susha Engager in Splunk Search 06-08-2021
0 7
0
7
AceOfSpades
I am currently working on a log and filtering data.Splunk has identified uri_query as a field.I have come across an e...
by AceOfSpades Engager in Splunk Search 06-08-2021
0 4
0
4
Rokas_Strazdas
Following is the data I have:Time (DD/MM/YYYY 00:00:00)Delay_class (String value, example "B. > 15 MIN" or "A. < 15MI...
by Rokas_Strazdas Engager in Splunk Search 06-08-2021
0 3
0
3
cave_splunker
I'm trying to create a dashboard that shows the count of new vulnerabilities between this month and last month, using...
by cave_splunker Explorer in Splunk Search 06-08-2021
1 8
1
8
dm1
I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in...
by dm1 Contributor in Splunk Search 06-07-2021
2 0
2
0
splunkkid
Hello,I have several different type of searches and made all of those as base search. And now I want to make input to...
by splunkkid Path Finder in Splunk Search 06-07-2021
0 6
0
6
logtastic
Hello,I am comparing a host.csv file with two columns "IP" and "DNS" I want to compare the IP column to my base searc...
by logtastic Explorer in Splunk Search 06-07-2021
0 1
0
1
mlevsh
Hi,We are using Splunk DB Connect on search heads to run "|dbxquery" command with SQL queries to Snowflake DB.Sometim...
by mlevsh Builder in Splunk Search 06-07-2021
0 1
0
1
ebarnhill
I am looking to create a confusion matrix out of a tabled query of the form[query] | table unchanged true predWhere, ...
by ebarnhill Engager in Splunk Search 06-07-2021
0 1
0
1
guido93
From a search I composed a table, let's call it T1, formed by two columns table name, sourcetypeNow I need to create ...
by guido93 New Member in Splunk Search 06-07-2021
0 3
0
3
thenormalone
I have a boolean field which I get from the search, now when I do a stats count by boolean_field, the pie chart will ...
by thenormalone Path Finder in Splunk Search 06-07-2021
0 3
0
3
newBie001
Hello All,Could you please suggest to me whether this option is good or is there any optimized search query? query --...
by newBie001 Loves-to-Learn in Splunk Search 06-07-2021
0 1
0
1
splunkerer
I am providing data from one input in the dashboard, and want to search provided input strings in different fields wh...
by splunkerer Path Finder in Splunk Search 06-07-2021
0 4
0
4
3amer92
Hello!So I'm new to Splunk, and I have a very long event but I'm only interested in the below two lines (there are a ...
by 3amer92 Explorer in Splunk Search 06-07-2021
0 0
0
0
Laxman24
Hi All,I need some help in searching,I have the following data : Field1Field22021-05-14X03:02:57YXa2021-05-13X05:12:1...
by Laxman24 Explorer in Splunk Search 06-07-2021
0 2
0
2
mani9059
Hi Team, I am trying to extract complete URL from the below splunk search i tried many ways can you please help me on...
by mani9059 Engager in Splunk Search 06-07-2021
0 3
0
3
mani9059
0
1
Splunk_Ryan
I would like to extract user name, source IP, source port and access protocol from the following 2 events from /var/l...
by Splunk_Ryan Explorer in Splunk Search 06-06-2021
0 6
0
6
tkdguq0110
How can I use abstract command?My query is| makeresults| eval test = " 123456789123456"| abstract maxlines=1 This que...
by tkdguq0110 Path Finder in Splunk Search 06-06-2021
0 0
0
0
ebs
This is my base search:| datamodel Test summariesonly=true search| search "TEST.date"=2021-05-23 | rename "TEST.date"...
by ebs Communicator in Splunk Search 06-06-2021
0 10
0
10
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...