Splunk Search

Splunk Search
Community Activity
Schroeder
Hi!Maybe this question is so simple to answer that I did not find any example, so please be kind to me We use append...
by Schroeder Explorer in Splunk Search 09-13-2024
0 7
0
7
tomjb94
Hi - I have a quick props question.I need to write a props for a particular sourcetype, and the messages always start...
by tomjb94 Observer in Splunk Search 09-13-2024
0 1
0
1
Thulasinathan_M
Hi,I've a case where I want to update/append the Macro with the results from lookup. I don't want to do this manually...
by Thulasinathan_M Contributor in Splunk Search 09-13-2024
0 9
0
9
JoseQuintero
how can I monitoring an user if he is using the wireless in the company?thank you!
by JoseQuintero Loves-to-Learn in Splunk Search 09-12-2024
0 1
0
1
iamtheclient20
 index=test | table severity location vehicleseverity locationvehiclehighPlutoBike testLookup.csvseveritylocationvehi...
by iamtheclient20 Explorer in Splunk Search 09-12-2024
0 7
0
7
arjunpkishore5
I'm facing a very strange situation. I have simplified it to just where the problem is ocurring Check out the below 2...
by arjunpkishore5 Motivator in Splunk Search 09-12-2024
2 9
2
9
Girish
my free 60 days trial got expired and now I have updated the license to a free trial, but now I'm unable to use searc...
by Girish New Member in Splunk Search 09-12-2024
0 1
0
1
deepakmr8
Hi,I have two fields, both these fields will be in two different events, now  i want to search for events, where aggr...
by deepakmr8 New Member in Splunk Search 09-12-2024
0 2
0
2
mythili
Hi all, I am trying to show the connected duration, which is calculated using transaction command in a timechart. Whe...
by mythili Explorer in Splunk Search 09-11-2024
0 5
0
5
Yossarian622
Howto to explode 1 row to several breaking out a multi-value field.app=ABC client=AA views=View1,View2app=ABC client=...
by Yossarian622 Engager in Splunk Search 09-11-2024
0 2
0
2
JeffV
I have a timechart that traffic volume over time and the top 15% of API performance times. I would like to add URI_St...
by JeffV Explorer in Splunk Search 09-11-2024
0 3
0
3
jpillai
Hi all,We have an index say index1 with a log retention of 7 days where we receive logs for different applications. N...
by jpillai Path Finder in Splunk Search 09-11-2024
0 5
0
5
kukasky
Hi, i have problem with Data model search.This is my SPL:|datamodel Network_Resolution_DNS_v2 search| search DNS.mess...
by kukasky Loves-to-Learn in Splunk Search 09-11-2024
0 3
0
3
kp_pl
Below quite simple query to fill drop down list in my dashboard.    index=gwcc | eval file=lower(mvindex(split(source...
by kp_pl Path Finder in Splunk Search 09-11-2024
0 6
0
6
Samantha
I would like to create a dashboard which would run a search daily to check network traffic against a list of about 18...
by Samantha Engager in Splunk Search 09-10-2024
0 3
0
3
chrislkt
For some reason my |tstats count query is returning a result of 0 when I add an OR condition in my where clause if th...
by chrislkt Explorer in Splunk Search 09-10-2024
0 11
0
11
Dayalss
Hi,How can I combine a field value , if the other 3 field values are the sameEx:- If the field1 , field2 , field3 are...
by Dayalss Engager in Splunk Search 09-10-2024
0 7
0
7
cimino
If I have two queries: 1. index=poc container_name=app horizontalId=orange outputs events with the trace ids 2. index...
by cimino Engager in Splunk Search 09-10-2024
0 5
0
5
cherrypick
As the title suggests, I want to change the CSS style of a table within Splunk dashboard using classes instead of id....
by cherrypick Path Finder in Splunk Search 09-10-2024
0 1
0
1
ganeshkumarmoha
Hi Team,As per business requirement, need to get below details from same autosys batch and corresponding outputs to b...
by ganeshkumarmoha Explorer in Splunk Search 09-09-2024
0 1
0
1
anila_ec21
When we are trying to run a report in deployment server to get the hosts that are reporting to Splunk, it is giving b...
by anila_ec21 Engager in Splunk Search 09-09-2024
1 1
1
1
texascj
My apologies for such a noob question.  I literally got dropped into a Splunk environment and I know little to nothin...
by texascj Path Finder in Splunk Search 09-09-2024
0 4
0
4
JandrevdM
Good day, I have a query to check my Entra logs to see what Conditional access policies gets hit. The returns results...
by JandrevdM Path Finder in Splunk Search 09-09-2024
0 2
0
2
Codie
Hi, I would like to extract a field from a JSON logs which is in a prettier format already.I would like to extract a ...
by Codie Engager in Splunk Search 09-09-2024
0 5
0
5
aab1
Hi I found this 2011 chat "72798" on Splunk to "considering adding the concept of an "search head user account" on th...
by aab1 Explorer in Splunk Search 09-09-2024
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...