Splunk Search

Splunk Search
Community Activity
iamtheclient20
 index=test | table severity location vehicleseverity locationvehiclehighPlutoBike testLookup.csvseveritylocationvehi...
by iamtheclient20 Explorer in Splunk Search 09-12-2024
0 7
0
7
arjunpkishore5
I'm facing a very strange situation. I have simplified it to just where the problem is ocurring Check out the below 2...
by arjunpkishore5 Motivator in Splunk Search 09-12-2024
2 9
2
9
Girish
my free 60 days trial got expired and now I have updated the license to a free trial, but now I'm unable to use searc...
by Girish New Member in Splunk Search 09-12-2024
0 1
0
1
deepakmr8
Hi,I have two fields, both these fields will be in two different events, now  i want to search for events, where aggr...
by deepakmr8 New Member in Splunk Search 09-12-2024
0 2
0
2
mythili
Hi all, I am trying to show the connected duration, which is calculated using transaction command in a timechart. Whe...
by mythili Explorer in Splunk Search 09-11-2024
0 5
0
5
Yossarian622
Howto to explode 1 row to several breaking out a multi-value field.app=ABC client=AA views=View1,View2app=ABC client=...
by Yossarian622 Engager in Splunk Search 09-11-2024
0 2
0
2
JeffV
I have a timechart that traffic volume over time and the top 15% of API performance times. I would like to add URI_St...
by JeffV Explorer in Splunk Search 09-11-2024
0 3
0
3
jpillai
Hi all,We have an index say index1 with a log retention of 7 days where we receive logs for different applications. N...
by jpillai Path Finder in Splunk Search 09-11-2024
0 5
0
5
kukasky
Hi, i have problem with Data model search.This is my SPL:|datamodel Network_Resolution_DNS_v2 search| search DNS.mess...
by kukasky Loves-to-Learn in Splunk Search 09-11-2024
0 3
0
3
kp_pl
Below quite simple query to fill drop down list in my dashboard.    index=gwcc | eval file=lower(mvindex(split(source...
by kp_pl Path Finder in Splunk Search 09-11-2024
0 6
0
6
Samantha
I would like to create a dashboard which would run a search daily to check network traffic against a list of about 18...
by Samantha Engager in Splunk Search 09-10-2024
0 3
0
3
chrislkt
For some reason my |tstats count query is returning a result of 0 when I add an OR condition in my where clause if th...
by chrislkt Explorer in Splunk Search 09-10-2024
0 11
0
11
Dayalss
Hi,How can I combine a field value , if the other 3 field values are the sameEx:- If the field1 , field2 , field3 are...
by Dayalss Engager in Splunk Search 09-10-2024
0 7
0
7
cimino
If I have two queries: 1. index=poc container_name=app horizontalId=orange outputs events with the trace ids 2. index...
by cimino Engager in Splunk Search 09-10-2024
0 5
0
5
cherrypick
As the title suggests, I want to change the CSS style of a table within Splunk dashboard using classes instead of id....
by cherrypick Path Finder in Splunk Search 09-10-2024
0 1
0
1
ganeshkumarmoha
Hi Team,As per business requirement, need to get below details from same autosys batch and corresponding outputs to b...
by ganeshkumarmoha Explorer in Splunk Search 09-09-2024
0 1
0
1
anila_ec21
When we are trying to run a report in deployment server to get the hosts that are reporting to Splunk, it is giving b...
by anila_ec21 Engager in Splunk Search 09-09-2024
1 1
1
1
texascj
My apologies for such a noob question.  I literally got dropped into a Splunk environment and I know little to nothin...
by texascj Path Finder in Splunk Search 09-09-2024
0 4
0
4
JandrevdM
Good day, I have a query to check my Entra logs to see what Conditional access policies gets hit. The returns results...
by JandrevdM Path Finder in Splunk Search 09-09-2024
0 2
0
2
Codie
Hi, I would like to extract a field from a JSON logs which is in a prettier format already.I would like to extract a ...
by Codie Engager in Splunk Search 09-09-2024
0 5
0
5
aab1
Hi I found this 2011 chat "72798" on Splunk to "considering adding the concept of an "search head user account" on th...
by aab1 Explorer in Splunk Search 09-09-2024
0 5
0
5
wm
I'll first insert my whole splunk search query and show whats it showing and whats the expected result     index=sss ...
by wm Loves-to-Learn Everything in Splunk Search 09-08-2024
0 23
0
23
zksvc
Hi Community,I got trouble when want to activate Use Case "User Login to Unauthorized Geo" it said Error because it s...
by zksvc Contributor in Splunk Search 09-08-2024
0 5
0
5
fahimeh
Hello,As an admin, I deleted a user in Splunk Web, but when I try to add a user during an investigation, I still see ...
by fahimeh Explorer in Splunk Search 09-07-2024
0 3
0
3
Siddharthnegi
hello  I am getting a field port in event .ports="['22', '68', '6556']"how can i display them in separate rows.
by Siddharthnegi Contributor in Splunk Search 09-06-2024
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...