Splunk Search

Splunk Search
Community Activity
moinyuso96
So what I have now from my search so farProduct     Status    TimeA                   Start        8.00 AMA          ...
by moinyuso96 Path Finder in Splunk Search 05-11-2021
0 2
0
2
SS1
Hi,I need some help with the regex,Currently we have below two paths, note the naming format is different for the log...
by SS1 Path Finder in Splunk Search 05-10-2021
0 4
0
4
ebs
Hi,I'm trying to create an eval expression in my data model which is based on _time. Can you please advise on what I'...
by ebs Communicator in Splunk Search 05-10-2021
0 3
0
3
jhick
Currently my splunk search to get a list of macs of the security cameras with their respective IP is index = dhcp 00:...
by jhick Observer in Splunk Search 05-10-2021
0 1
0
1
phamxuantung
Hello I have some event logs that show batch purchase like this: Event 1: <BankID>Bank A</BankID> <value>5</value> <s...
by phamxuantung Communicator in Splunk Search 05-10-2021
0 1
0
1
abowesman
The following example | makeresults | eval FilePath="\\Temp.exe" | where match(FilePath, "(?i)\\Temp\.exe$") Creates ...
by abowesman Explorer in Splunk Search 05-10-2021
0 0
0
0
ershad_c
The date field sometimes has 2 spaces and sometimes 1 space, depending on whether the date is a single digit or doubl...
by ershad_c Engager in Splunk Search 05-10-2021
0 2
0
2
keshavgupta
SpoilerHow to split/extract substring before the first - from the right side of the field on splunk searchHow to spli...
by keshavgupta Engager in Splunk Search 05-10-2021
0 1
0
1
kirrusk
how to use horseshoe meter for below queryindex = *   | table podname cluster status | dedup podname cluster status |...
by kirrusk Communicator in Splunk Search 05-10-2021
0 1
0
1
yifatcy
Hi,I've been trying for hours and nothing works, so I figure you might help me out.I have the following very long que...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 2
0
2
Flobzh
Dear all,I'm trying to retrieve some log metadata and associate them to all my events.Exemple: When my application st...
by Flobzh Explorer in Splunk Search 05-10-2021
0 1
0
1
or1515
Hi,My query:index=ph_windows_sec sourcetype=XmlWinEventLog (EventCode=630 OR EventCode=4726 OR EventCode=624 OR Event...
by or1515 Loves-to-Learn Everything in Splunk Search 05-10-2021
0 2
0
2
yifatcy
Hi,Can I separate Trellis visualization by two variables as keys? In other words, I would like a timechart for each c...
by yifatcy Path Finder in Splunk Search 05-10-2021
0 0
0
0
keyu921
Resolved
by keyu921 Explorer in Splunk Search 05-10-2021
0 1
0
1
junlozhang
I want to concatenate strings with special characters like "\t" and Unicode char "\u0006"I tried  | makeresults | ev...
by junlozhang Explorer in Splunk Search 05-09-2021
0 2
0
2
robayers
I have a field that consists of data separated from a json  data field using this search.index="test-99" sourcetype="...
by robayers Explorer in Splunk Search 05-09-2021
0 8
0
8
schou87
I am relatively new to this wonderful tool called SPLUNK. Please excuse me if this question has already been answered...
by schou87 Path Finder in Splunk Search 05-09-2021
0 4
0
4
Msugiyama
Dear ALL,I want to insert a value into a subsearch using the search result as a variable.Do the following search to g...
by Msugiyama Path Finder in Splunk Search 05-09-2021
0 2
0
2
prajwal_94
For the below query, searching for the values of 2nd occurence of earliest and latest events so that the timechart wo...
by prajwal_94 Explorer in Splunk Search 05-09-2021
0 2
0
2
hvdtol
I would kindly need some help for a query i am not able to create.I have  inputlookups as source.And i want to filter...
by hvdtol Path Finder in Splunk Search 05-09-2021
0 4
0
4
PaintItParker
Right now I have something like this: index=my_index sourcetype=my_sourcetype | rex field=message "- (?<User>\S+) -:"...
by PaintItParker Explorer in Splunk Search 05-08-2021
0 3
0
3
cboonyan
I am aiming to provide headers to my generated report. I have 3 hosts, host1 host2 and host3. My report is configured...
by cboonyan New Member in Splunk Search 05-08-2021
0 1
0
1
Matthew
Hi Guys, Wondering if you can help me out with the following. Within a single event I have to fields: 1) expiry_date2...
by Matthew Engager in Splunk Search 05-08-2021
0 2
0
2
sh_tavousi
Hi,I have 2 servers with the same names and I have installed universal forwarder on both servers. In forwarder manage...
by sh_tavousi Explorer in Splunk Search 05-08-2021
0 3
0
3
junlozhang
Let's say the data looks like:StudentNameStudentIdGradeExamDateTom1602021-04-01Jerry2702021-04-01Tom1622021-04-07Jerr...
by junlozhang Explorer in Splunk Search 05-08-2021
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...