Splunk Search

Splunk Search
Community Activity
andres91302
Hello everyone!I'm trying to create a time chart of a variable that I have to compute as a global percentage between ...
by andres91302 Communicator in Splunk Search 04-19-2021
0 4
0
4
valpravin
Hi Teamcan you please help in extracting the  123456 from following stringhello world  \"employee\":123456 
by valpravin Engager in Splunk Search 04-19-2021
0 1
0
1
MeMilo09
Hi All, I am trying to replace gentimes from my query due to slowness. I have read that if I add the field to an auto...
by MeMilo09 Path Finder in Splunk Search 04-19-2021
0 0
0
0
dwharam
For inventory management purposes, I have been running the below splunk search for years.  It first checks Remedy and...
by dwharam New Member in Splunk Search 04-19-2021
0 0
0
0
Dheeru
Hi,I am new to splunk and I am trying to create a dashboard with optimizing the independent queries and by using all ...
by Dheeru Engager in Splunk Search 04-19-2021
0 1
0
1
alancalvitti
What's a scalable to extract key-value pairs where the value matches via exact or substring match but the field is no...
by alancalvitti Path Finder in Splunk Search 04-19-2021
0 11
0
11
raultav
Hi, guys!I need to get the difference in hours between _time and now(). How can I get this number?
by raultav Engager in Splunk Search 04-19-2021
0 1
0
1
andres91302
Hello Friends, I'm trying to generate a table that summarizes the total count of events A, B and C as follows search ...
by andres91302 Communicator in Splunk Search 04-19-2021
0 2
0
2
teedilo
We have some issues with line breaking such that we have events that often consist of multiple logical events, or the...
by teedilo Path Finder in Splunk Search 04-19-2021
0 2
0
2
raultav
Hi, guys!I have an event table, which has a field called "COD SERIE CEI". I need to get the "COD SERIE CEI" which has...
by raultav Engager in Splunk Search 04-19-2021
0 3
0
3
rseri17
Can you please help with extracting the fields from the below sample log. I am unable to escape the "'// &" '" in the...
by rseri17 Explorer in Splunk Search 04-19-2021
0 6
0
6
Traer001
Hello!I have two searches that return separate data but have a common field. I am trying to filter my first search by...
by Traer001 Path Finder in Splunk Search 04-19-2021
0 1
0
1
ayadav38
Hey there,I  created a field extraction from UI,using regular expression method,where regular expression got created ...
by ayadav38 Engager in Splunk Search 04-19-2021
0 1
0
1
sudo_su
Hello Splunkers,I would like to create a timechart for status. The data only comes when there's an update, so general...
by sudo_su Engager in Splunk Search 04-19-2021
0 2
0
2
nsantiago17
I'm trying to run this query below: (index=A sourcetype=jobs_info JOB_NAME IN (ACQUA)) OR (index=B sourcetype=FIRE) ...
by nsantiago17 Explorer in Splunk Search 04-19-2021
0 2
0
2
jacobmcn67
Hi all, I am trying to create a fourth column which would display all values between a given time range in the single...
by jacobmcn67 New Member in Splunk Search 04-18-2021
0 1
0
1
mariannedave
I have this XML data in one event but there are multiple transactions with same fieldnames . We need to display them ...
by mariannedave Explorer in Splunk Search 04-18-2021
0 2
0
2
shinobu
I have stored data in 2 indexes. One Index has a attribute which can be a substring of the second index _raw event da...
by shinobu Explorer in Splunk Search 04-18-2021
0 2
0
2
surejsajeev
Hi,I have a csv file uploaded in the location /opt/splunk/etc/apps/search/lookups/. My transforms file is in /opt/spl...
by surejsajeev Explorer in Splunk Search 04-18-2021
0 1
0
1
edoardo_vicendo
Hello,Suppose I have raw records like this: user=blabla,org_L1=12345,org_L2=777,department=7890 user=testtt,org_L1=34...
by edoardo_vicendo Builder in Splunk Search 04-17-2021
0 2
0
2
lohit
I am facing problems with restoring splunk. I require the searches, indexed data and users created on one installati...
by lohit Path Finder in Splunk Search 04-17-2021
0 6
0
6
SamHTexas
How are AWS logs get ingested into Splunk Enterprise or ES? Please advise the steps.
by SamHTexas Builder in Splunk Search 04-17-2021
0 2
0
2
jlph
I would like to run a query for any user additions to privileged Active Directory groups. I am storing the AD groups ...
by jlph Loves-to-Learn in Splunk Search 04-17-2021
0 1
0
1
biers04
I am working on statsing firewall data into a sparkline.  However, when I run the search, the sparkline caps out at 1...
by biers04 Explorer in Splunk Search 04-16-2021
0 0
0
0
aquinojason
Hi,Is there a way from a dashboard perspective that I present a chart from 2 big groups and if I click on the legend ...
by aquinojason Path Finder in Splunk Search 04-16-2021
0 5
0
5
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...