Splunk Search

Splunk Search
Community Activity
mattiasrs
Hello awesome community!I got help from here once before so I will try again.I have two indexes, Index A and Index B....
by mattiasrs Explorer in Splunk Search 02-26-2021
0 3
0
3
Sivakesava574
my search query returns list of _time values for multiple dates and below is start and end times for a each date2021-...
by Sivakesava574 Explorer in Splunk Search 02-26-2021
0 2
0
2
bhartiya008
I have the final result which looks like below:Host Date Total_1 Total_2 To_be_removed Prod 02-26-2...
by bhartiya008 Explorer in Splunk Search 02-26-2021
0 4
0
4
JosIJntema
Hi there, I am new to Splunk and have sent some dummy JSON-data to Splunk. I notice that for example there are 20 e...
by JosIJntema Explorer in Splunk Search 02-26-2021
1 8
1
8
hishamjan
Hi everyone, On my Linux machine, which has Splunk Forwarder and Splunk Add-on for Unix and Linux installed, I'm usin...
by hishamjan Explorer in Splunk Search 02-26-2021
0 3
0
3
bhartiya008
Hi All,I have a log which has below lines in it:"Results":{"Elapsed":"0","Message":"No of Application to Obsolete in ...
by bhartiya008 Explorer in Splunk Search 02-25-2021
0 6
0
6
jip31
HiI use the search below but I lose some events because I have the following message :[subsearch]: Subsearch produced...
by jip31 Motivator in Splunk Search 02-25-2021
0 16
0
16
sriramv2006
Hi,I have a table like this:Tag    |   Valueaa     |   15.5bb     |    20cc     |    23I want to chart the value "dd ...
by sriramv2006 Explorer in Splunk Search 02-25-2021
0 4
0
4
kelie
Goal is to return a table that displays the Top 10  (md5) hashes in  recorded alerts received over a 60 days period. ...
by kelie Path Finder in Splunk Search 02-25-2021
0 9
0
9
chrismok
Hi all, I would like to make the values of a column the column names for a table. Currently, I am using the command...
by chrismok Path Finder in Splunk Search 02-25-2021
1 2
1
2
griffinpair
Search: source=D:\XSP\importhelper source=IH_Daily\DebugImportHelper End | eval dayBuffer=strftime(now(), "%d") | ev...
by griffinpair Path Finder in Splunk Search 02-25-2021
0 3
0
3
Annna
<Shipment Action><ShipmentLines><ShipmentLine PrimeLine="2" /> <ShipmentLine PrimeLine="3"/><ShipmentLine PrimeLine="...
by Annna Explorer in Splunk Search 02-25-2021
0 2
0
2
bojjas
Hello, We are new to Splunk , learning and working customer requirments. You are requested to help on merging these t...
by bojjas Observer in Splunk Search 02-25-2021
0 0
0
0
ynag
Hi, I have a field with multiple values, some of them share the same characters at the beginning of the values. I nee...
by ynag Explorer in Splunk Search 02-25-2021
0 1
0
1
kgaurav
I'm having trouble writing a query which displays the action and host count where log count is below average on any h...
by kgaurav Observer in Splunk Search 02-25-2021
0 1
0
1
rj1408
Hi All,I want to always hide my drop down   <input type="dropdown" token="TransactionID_filter" searchWhenChanged="tr...
by rj1408 Path Finder in Splunk Search 02-25-2021
0 1
0
1
schufi01
Hi,My events contain a field  named "fruit" that distinguishes, what kind of fruit the event is about. I would like t...
by schufi01 Path Finder in Splunk Search 02-25-2021
0 1
0
1
pracsys
I have a search where 2 of the fields returned are based on the following JSON structure:"tags": [        {<!-- -->          ...
by pracsys Engager in Splunk Search 02-25-2021
0 3
0
3
schufi01
Hi,can somebody explain, why I dont get any results?index&#61;... | eval Timestamp&#61;strftime(_time,"%d-%m-%Y %H:%M:%S") |...
by schufi01 Path Finder in Splunk Search 02-25-2021
0 1
0
1
phamxuantung
Hi, I want make a report(or Alert) each month to count the Total transaction success in 1 month and compare it to 3 m...
by phamxuantung Communicator in Splunk Search 02-24-2021
0 4
0
4
hishamjan
Hi,Is there a way to enlist the size of files that are indexed using the local host and universal forwarders? From th...
by hishamjan Explorer in Splunk Search 02-24-2021
0 3
0
3
jmartens
SituationI am trying to parse events with an unrestricted number of key value pairs  that might also include empty va...
by jmartens Path Finder in Splunk Search 02-24-2021
0 1
0
1
omun0z
Hello Splunk team, I'm trying to append columns based in a search of a field (Network &#61; Network_CIDR) in Ashland-Netw...
by omun0z Explorer in Splunk Search 02-24-2021
0 2
0
2
jariw
Hi,I'm bouncing my head against the wall for this (probably) simple question.. I've got a inputlookup "indexers". As ...
by jariw Path Finder in Splunk Search 02-24-2021
0 3
0
3
assennikolov
I have the following question regarding using the sendemail command together with the 'map' one.Using the below searc...
by assennikolov Explorer in Splunk Search 02-24-2021
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...