Splunk Search

Splunk Search
Community Activity
asieira
The problem I am trying to solve is the following: if src_hostfield is missing, null or empty, add it to events by pe...
by asieira Path Finder in Splunk Search 04-13-2021
0 2
0
2
PaintItParker
I have two queries. One gets the total number of events using the message field: index=my_index sourcetype=my_sourcet...
by PaintItParker Explorer in Splunk Search 04-13-2021
0 2
0
2
chuck_life09
Hi,In my dashboard i have set of inputs and when i submit the values gets stored in a lookup file. 2 dropdowns , 1 mu...
by chuck_life09 Path Finder in Splunk Search 04-13-2021
0 1
0
1
chuck_life09
Hi,In my dashboard i have set of inputs and when i submit the values gets stored in a lookup file. 2 dropdowns , 1 mu...
by chuck_life09 Path Finder in Splunk Search 04-13-2021
0 3
0
3
gerbert
Hi splunk community,I feel like this is a very basic question but I couldn't get it to work.I want to search my index...
by gerbert Path Finder in Splunk Search 04-13-2021
0 2
0
2
Habanero
Good day Community,I would like to know what is the best approach to filters events based on previous query. My preci...
by Habanero Explorer in Splunk Search 04-12-2021
0 4
0
4
isoutamo
HiOur client have the next (kind of query) runs as a schedule. It can found events or not, based on current situation...
by SplunkTrust SplunkTrust in Splunk Search 04-12-2021
0 3
0
3
yaoyed
Hello everyone,I am now editing the pie chart section of the dashboard, I want to add a list of URLs to let click imp...
by yaoyed Engager in Splunk Search 04-12-2021
0 0
0
0
onur
Hi,I have a problem about wrong written searches. In our system, there are so many users. Every user will be able to ...
by onur Explorer in Splunk Search 04-12-2021
0 1
0
1
MeMilo09
Hello, I have a small dilema around AND OR boolean operators. I dont want null time logs for event=timeOut, but at th...
by MeMilo09 Path Finder in Splunk Search 04-12-2021
0 2
0
2
genesiusj
Hello,I need to remove the values found (string) from another field.Ex. FIELD1 - abcmailingxyzLIST - mailing, ...Usin...
by genesiusj Builder in Splunk Search 04-12-2021
0 7
0
7
Adevill
Hey all. I need help to selective forward (on a HF) from a log file that is being monitored by a UF. I only need to f...
by Adevill Loves-to-Learn Lots in Splunk Search 04-12-2021
0 13
0
13
Avantika07
I'm creating a query using 4 sourcetypes and want to search across different timerange for them. For example:| multis...
by Avantika07 Observer in Splunk Search 04-12-2021
0 4
0
4
splunkuser1948
According to the splunk doc , eval can be used within aggregate functions with stats command like: index=main sourcet...
by splunkuser1948 Engager in Splunk Search 04-12-2021
0 2
0
2
vinitpathri
I have 2 queries1st is | rest /services/data/indexes| fields title| dedup title| table titlethis query is giving me a...
by vinitpathri Path Finder in Splunk Search 04-12-2021
0 4
0
4
dyapasrikanth
We have 2 eventsOTP generated  through SMS with UUID=123123OTP generated through EMAIL with UUID=432432OTP Verified f...
by dyapasrikanth Path Finder in Splunk Search 04-11-2021
0 3
0
3
gl_splunkuser
Hello everyone.I am trying to deploy ESS, but I having some trouble with the notable events.I can not see results at ...
by gl_splunkuser Path Finder in Splunk Search 04-11-2021
0 2
0
2
ibanez450
I'm pretty new at this so I apologize if the question seems stupid.I have a printer that sends syslogs to Splunk, and...
by ibanez450 Explorer in Splunk Search 04-11-2021
0 3
0
3
jenniferhao
Is there a way to get field's background color by compare with 2 fields numbers? for example:If "POST IPTV CALLS"'s v...
by jenniferhao Explorer in Splunk Search 04-11-2021
0 12
0
12
hFHUT2
I have a lookup table that has a list of values in it similar to:idvalue1test_value12test_value2 I can search for all...
by hFHUT2 Engager in Splunk Search 04-11-2021
0 3
0
3
splunkuser1948
Hi,I read from splunk docs that we should avoid using wildcards `*` in the middle of a string.Now, does this apply to...
by splunkuser1948 Engager in Splunk Search 04-10-2021
0 1
0
1
SamHTexas
How do I check if my Splunk environment is set for Search Head pooling? We have SH clustering all set up and am prepa...
by SamHTexas Builder in Splunk Search 04-10-2021
0 1
0
1
lubanamanjinder
Hi There I am new to splunk and trying to figure out a way to make the below search faster : index=pan_logs sourcetyp...
by lubanamanjinder New Member in Splunk Search 04-10-2021
0 1
0
1
srampally
We currently have lookups and want to move to KV store. What and how can we do that
by srampally Path Finder in Splunk Search 04-10-2021
1 4
1
4
omerl
Hey I’m trying to extract fields in index time on my summary index, in order to use ‘tstats’ command. I used ‘coll...
by omerl Path Finder in Splunk Search 04-10-2021
0 5
0
5
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...