Splunk Search

Splunk Search
Community Activity
srinivasgowda
Hello all,I am trying to extract the data from the field evtComponent from the below event, and this has a multiple t...
by srinivasgowda Explorer in Splunk Search 03-04-2021
0 2
0
2
VijaySrrie
Hi, Output of the below query has been attached, I need only the total value to be displayed in the dashboard. Here t...
by VijaySrrie Builder in Splunk Search 03-04-2021
0 1
0
1
phanirohith97
I have a Query need to compare hourly log count of today with the average value of last 7 days, if the count is great...
by phanirohith97 Observer in Splunk Search 03-04-2021
0 4
0
4
arandy01
I have two searches:search-A gives values like typestatushostnameidportSizebasecachehttpOFFhost-117NANANANAhttpONhost...
by arandy01 Explorer in Splunk Search 03-04-2021
0 4
0
4
VictorCrunch
I have a process where I load data into database tables.   My log file has the following entries for each :TableLoad=...
by VictorCrunch Loves-to-Learn in Splunk Search 03-04-2021
0 0
0
0
UMDTERPS
Currently we are having issues with our scan data comming in to out indexer, so we have to use CSV's for scan data ....
by UMDTERPS Communicator in Splunk Search 03-04-2021
0 7
0
7
nickstone
As a example, I have a search that calculates "Unique Users per Application" and this can be constrained to a particu...
by nickstone Path Finder in Splunk Search 03-04-2021
0 5
0
5
exchanger
Hello,I have a query (e.g. "....... " | stats count, avg(...)) and after that I get as resultOwnColumn Count AVGXYZ  ...
by exchanger Path Finder in Splunk Search 03-04-2021
0 1
0
1
AnonymousPerson
0
1
phamxuantung
Hi, I have a main search that look like this index=main RESPONSE_CODE="0" earliest =-4mon@mon latest=mon@mon |stats c...
by phamxuantung Communicator in Splunk Search 03-04-2021
0 6
0
6
jip31
hiin the search below I need to excluse the results when instance=_total index="perfmon-fr" | fields %_User_Time hos...
by jip31 Motivator in Splunk Search 03-04-2021
0 1
0
1
jonaclough
Our ML team use the API to export large numbers of events for model training.They are hitting limits: [searchresults]...
by jonaclough Path Finder in Splunk Search 03-04-2021
0 0
0
0
VijaySrrie
How to convert tabular data to distinct countHi,I have a splunk query| stats count by operation (under field operatio...
by VijaySrrie Builder in Splunk Search 03-04-2021
0 5
0
5
mkiran18
Hi ,I have a json structure like this :  { "zip": 67452, "location": "NY", "author": { "book1": { "pr...
by mkiran18 Loves-to-Learn in Splunk Search 03-04-2021
0 4
0
4
pragycho
Hi ,I have data where  i  want to read comment line and store value in field.for example  , I have log where first  4...
by pragycho Loves-to-Learn in Splunk Search 03-04-2021
0 2
0
2
markthompson
Hello, I have this: stats count by opentime | stats avg(count) and I want the average to be in 2dp. Anyone have an...
by markthompson Builder in Splunk Search 03-03-2021
5 11
5
11
porbea01
Hi, I'm new in Splunk and I'm trying to collect Syslog log to indexers. I have read in Splunk documentation that Splu...
by porbea01 New Member in Splunk Search 03-03-2021
0 8
0
8
thenormalone
I have a field from the search query called source which has a pattern of "text:text:text:dynamicText:dynamicText:dyn...
by thenormalone Path Finder in Splunk Search 03-03-2021
0 3
0
3
wcastillocruz
Hello,@rnowitzki @renjith_nair could you help me on the following question please:I index every day at 6 p.m. splunk ...
by wcastillocruz Path Finder in Splunk Search 03-03-2021
0 8
0
8
Naga
Can we get a query to fetch the savedsearches/dashboards which are running with timerange more than 24 hours In oour ...
by Naga Engager in Splunk Search 03-03-2021
0 1
0
1
nits
Here is my Splunk Query:index=test "Entry Done for Id=" | rex field=_raw Id=(?<Id>.*?)# | rex field=_raw UserID=(?<Us...
by nits Explorer in Splunk Search 03-03-2021
0 1
0
1
wcastillocruz
Hello,@scelikokCould you help me on the following search please?I have a main search which groups me together all the...
by wcastillocruz Path Finder in Splunk Search 03-03-2021
0 0
0
0
vmvd
I have events that contain a userId field and I would like to make a line chart to visualize the average count per da...
by vmvd Explorer in Splunk Search 03-03-2021
0 3
0
3
ppatkar
 In some of the events, I have '\n' in the events :message: org.springframework.jdbc.UncategorizedSQLException: Calla...
by ppatkar Path Finder in Splunk Search 03-03-2021
0 1
0
1
Soogbad
I have this code that shows me the start and end times of runs of a program:index=index1 source=source1 | transaction...
by Soogbad Engager in Splunk Search 03-03-2021
0 3
0
3
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...