Splunk Search

Splunk Search
Community Activity
AceOfSpades
I am currently working on a log and filtering data.Splunk has identified uri_query as a field.I have come across an e...
by AceOfSpades Engager in Splunk Search 06-08-2021
0 4
0
4
Rokas_Strazdas
Following is the data I have:Time (DD/MM/YYYY 00:00:00)Delay_class (String value, example "B. > 15 MIN" or "A. < 15MI...
by Rokas_Strazdas Engager in Splunk Search 06-08-2021
0 3
0
3
cave_splunker
I'm trying to create a dashboard that shows the count of new vulnerabilities between this month and last month, using...
by cave_splunker Explorer in Splunk Search 06-08-2021
1 8
1
8
dm1
I am developing a use case to detect outliers on logons for a specific app using Smart Outlier Detection Assistant in...
by dm1 Contributor in Splunk Search 06-07-2021
2 0
2
0
splunkkid
Hello,I have several different type of searches and made all of those as base search. And now I want to make input to...
by splunkkid Path Finder in Splunk Search 06-07-2021
0 6
0
6
logtastic
Hello,I am comparing a host.csv file with two columns "IP" and "DNS" I want to compare the IP column to my base searc...
by logtastic Explorer in Splunk Search 06-07-2021
0 1
0
1
mlevsh
Hi,We are using Splunk DB Connect on search heads to run "|dbxquery" command with SQL queries to Snowflake DB.Sometim...
by mlevsh Builder in Splunk Search 06-07-2021
0 1
0
1
ebarnhill
I am looking to create a confusion matrix out of a tabled query of the form[query] | table unchanged true predWhere, ...
by ebarnhill Engager in Splunk Search 06-07-2021
0 1
0
1
guido93
From a search I composed a table, let's call it T1, formed by two columns table name, sourcetypeNow I need to create ...
by guido93 New Member in Splunk Search 06-07-2021
0 3
0
3
thenormalone
I have a boolean field which I get from the search, now when I do a stats count by boolean_field, the pie chart will ...
by thenormalone Path Finder in Splunk Search 06-07-2021
0 3
0
3
newBie001
Hello All,Could you please suggest to me whether this option is good or is there any optimized search query? query --...
by newBie001 Loves-to-Learn in Splunk Search 06-07-2021
0 1
0
1
splunkerer
I am providing data from one input in the dashboard, and want to search provided input strings in different fields wh...
by splunkerer Path Finder in Splunk Search 06-07-2021
0 4
0
4
3amer92
Hello!So I'm new to Splunk, and I have a very long event but I'm only interested in the below two lines (there are a ...
by 3amer92 Explorer in Splunk Search 06-07-2021
0 0
0
0
Laxman24
Hi All,I need some help in searching,I have the following data : Field1Field22021-05-14X03:02:57YXa2021-05-13X05:12:1...
by Laxman24 Explorer in Splunk Search 06-07-2021
0 2
0
2
mani9059
Hi Team, I am trying to extract complete URL from the below splunk search i tried many ways can you please help me on...
by mani9059 Engager in Splunk Search 06-07-2021
0 3
0
3
mani9059
0
1
Splunk_Ryan
I would like to extract user name, source IP, source port and access protocol from the following 2 events from /var/l...
by Splunk_Ryan Explorer in Splunk Search 06-06-2021
0 6
0
6
tkdguq0110
How can I use abstract command?My query is| makeresults| eval test = " 123456789123456"| abstract maxlines=1 This que...
by tkdguq0110 Path Finder in Splunk Search 06-06-2021
0 0
0
0
ebs
This is my base search:| datamodel Test summariesonly=true search| search "TEST.date"=2021-05-23 | rename "TEST.date"...
by ebs Communicator in Splunk Search 06-06-2021
0 10
0
10
ebs
Hi,I want to create a search that is able to grab both the start and end times of a specific action, but to create th...
by ebs Communicator in Splunk Search 06-06-2021
0 1
0
1
new2splunk1
Hi Splunk experts, I'm generating stats from 3 indexes (System A, B, C) and the results look like this:Table 1:The to...
by new2splunk1 Engager in Splunk Search 06-05-2021
0 4
0
4
harry_123
Hello, I have alerts that look like belowMay 13 17:15:30 11.2.3.22 0000017768: NOXXXXXX10A: May 13 2021 17:15:30.467 ...
by harry_123 Loves-to-Learn Lots in Splunk Search 06-04-2021
0 13
0
13
vijaykuma
  index=_internal host="ip" source=*license_usage.log* type="Usage"     [| inputlookup all_cs_indexes.csv     | renam...
by vijaykuma New Member in Splunk Search 06-04-2021
0 1
0
1
splunkerer
Hello,I am creating a dashboard, no matter which input can be used, but need is to paste multiple input into dashboar...
by splunkerer Path Finder in Splunk Search 06-04-2021
0 6
0
6
shrogers
Can I please get some assistance on the below?I'm trying to add a filter TRAN_CLASS!=6 to the below query. When I add...
by shrogers Loves-to-Learn Everything in Splunk Search 06-04-2021
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...