Splunk Search

Splunk Search
Community Activity
Joe20
Hello All,  I am new to splunk and I have a question regarding the splunk field extraction. Consider the following ex...
by Joe20 Explorer in Splunk Search 02-18-2021
0 2
0
2
auaave
Hi Guys! I have an error duration in seconds, how can I convert it to [h]:mm:ss? I used the below query but the if ...
by auaave Communicator in Splunk Search 02-18-2021
1 6
1
6
aneyraba
I am trying to use the Drilldown on Click >  Link to Search > custom :LOGRC_TYPE=F8 | eval FUNC_TRAN =AFI_LOG03FUN+"-...
by aneyraba New Member in Splunk Search 02-18-2021
0 0
0
0
bsrikanthreddy5
Hi, Is there was to dynamically pass a value like below in Splunk for running a search from cli.I am trying to write ...
by bsrikanthreddy5 Path Finder in Splunk Search 02-18-2021
0 2
0
2
michaelrosello
I need to create a regex to match the fieldname for first match and fieldvalue for the second match. Issue happens w...
by michaelrosello Path Finder in Splunk Search 02-18-2021
0 11
0
11
hishamjan
Hi, In my production environment, I have two Asterisk Servers installed where one of them caters to 95% of the data w...
by hishamjan Explorer in Splunk Search 02-18-2021
0 6
0
6
tkerr1357
Hey All,I am trying to pull the username from the following event which is everything after the Rightnetworks\ in the...
by tkerr1357 Path Finder in Splunk Search 02-18-2021
0 4
0
4
Murali2888
Hi Splunkers, I was wondering if there is an option to disable Export Results option for specific users or roles. Ba...
by Murali2888 Communicator in Splunk Search 02-18-2021
2 7
2
7
phamxuantung
Hi,I have a dataset about transactions, each event is a transaction detail about response code(success or not), their...
by phamxuantung Communicator in Splunk Search 02-18-2021
0 1
0
1
phamxuantung
Hi, I have a raw log with structure like this: TIME|FROM|TO|URL|ERROR|STATUS|ALERT Example:Wed Jan 6 15:10:01 2021|De...
by phamxuantung Communicator in Splunk Search 02-18-2021
0 5
0
5
ivana27
Hi,i have log like this[Information] WebService Call CheckVehicle : country=111111, licensePlate=12DUMMYAnd i would l...
by ivana27 Path Finder in Splunk Search 02-18-2021
0 9
0
9
ajees_basha
by ajees_basha Explorer in Splunk Search 02-17-2021
0 1
0
1
mztopp
How would I take a 24 hour search such as: index=* | iplocation src_ip | stats count by src_ip, Country, dest_ip, des...
by mztopp Explorer in Splunk Search 02-17-2021
0 4
0
4
aniket
I am pretty new to splunk and i have a query which uses TABLE command to filter output on certain fields. The output ...
by aniket New Member in Splunk Search 02-17-2021
0 2
0
2
Kupo
I have two sources that have a common field (user) and am currently using transaction to join the user_a with the sou...
by Kupo Engager in Splunk Search 02-17-2021
0 2
0
2
amsagg
Hi Everyone,I am trying to use  a lookup table and an index to get an output as a comparison of two fields from two d...
by amsagg Observer in Splunk Search 02-17-2021
0 2
0
2
Hudond
Good MorningAs I am new to Splunk,  sometimes I need to try things that are beyond my comprehension at this time. Thi...
by Hudond Path Finder in Splunk Search 02-17-2021
0 2
0
2
bhartiya007
I am fairly new to splunk and still learning. I have a splunk event which is a mix of some texts and json in between....
by bhartiya007 Loves-to-Learn Lots in Splunk Search 02-17-2021
0 11
0
11
sasankganta
I have raw event like : time action severity host , etc., But when I checked interesting filed action filed is not sh...
by sasankganta Path Finder in Splunk Search 02-17-2021
0 11
0
11
Glasses
Lets say I have 3 lookups >>> a-list.csv, b-list.csv, c-list.csv and the lists only have 1 column header = NameAlice ...
by Glasses Builder in Splunk Search 02-17-2021
2 3
2
3
jacob_rod
Hello friends,Please try to assist me.My data structure is -Date , field1 , field2 , field3I need to search events th...
by jacob_rod Explorer in Splunk Search 02-17-2021
0 2
0
2
ruchijain
Hi, I am trying to search for a list of users who have not logged into the Splunk environment in the past 30 days. ...
by ruchijain New Member in Splunk Search 02-17-2021
0 6
0
6
hishamjan
index=_* OR index=* sourcetype=Kamailio BC="Current Billable Calls Count:" | rex field=_raw "Count:(?<Billablecalls>....
by hishamjan Explorer in Splunk Search 02-17-2021
0 5
0
5
Jarohnimo
Hello All, I just upgraded to the latest version of Splunk 7.2.5 and now when I search anything i recieve errors sta...
by Jarohnimo Builder in Splunk Search 02-17-2021
0 6
0
6
jacob_rod
Hello,Help will be very appreciated.My splunk index contains a field with codes, and another field with names.Every e...
by jacob_rod Explorer in Splunk Search 02-16-2021
0 6
0
6
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...