Splunk Search

Splunk Search
Community Activity
strehb18
Hello,I am having trouble with a panel staying hidden when the search above shows no results. I would like to create ...
by strehb18 Path Finder in Splunk Search 02-01-2021
0 4
0
4
rbolande
I wish to take a stacked bar chart, use 'addtotals' to create a field representing the cumulative value of the stacke...
by rbolande Explorer in Splunk Search 02-01-2021
0 3
0
3
designer46
Hi,See, I have been trying to group my result query based on the latest date in order to remove duplicates and get th...
by designer46 Explorer in Splunk Search 02-01-2021
0 2
0
2
SS1
Hi,My splunk instance is not sending email alerts for a new alert th Can soat i just setup. I am getting other alert ...
by SS1 Path Finder in Splunk Search 01-31-2021
0 4
0
4
teewenjie22
How to Convert _time             ColumnA                  ColumnB timeA             10                               ...
by teewenjie22 Engager in Splunk Search 01-31-2021
0 3
0
3
landen99
Enable alerts and reports on real-time searches seen in the internal audit index.
by landen99 Motivator in Splunk Search 01-30-2021
0 2
0
2
redfan9
I am a newbie to Splunk and am trying to find out what query I can use to find a specific users browsing history for ...
by redfan9 New Member in Splunk Search 01-30-2021
0 1
0
1
AzmathShaik
Hello All,i have a default app which gets installed on the UF during the installation (part of our install script). t...
by AzmathShaik Path Finder in Splunk Search 01-29-2021
0 4
0
4
shazbot79
Hi, can anyone make any suggestions as to how I can make this search more efficient?  index=prod_service_now sourcety...
by shazbot79 Path Finder in Splunk Search 01-29-2021
0 4
0
4
gn694
I have a search created, and want to get a count of the events returned by date. I know the date and time is stored ...
by gn694 Communicator in Splunk Search 01-29-2021
3 5
3
5
AshChakor
I want to display counts latest two weeks (last two weeks), two weeks before and everything else before 4 weeks start...
by AshChakor Path Finder in Splunk Search 01-29-2021
0 1
0
1
viswatejabolla
Hi All,I have field called stepName which will have below three values.TextResource.getFirstLineTextResource.getSecon...
by viswatejabolla New Member in Splunk Search 01-29-2021
0 3
0
3
marceloalejandr
Greetings,I've 2 Lookup (csv) files, one generated from index _internal (approx 15k events) and another generated fro...
by marceloalejandr Path Finder in Splunk Search 01-29-2021
0 6
0
6
dnsGuy314
I have a current alert that is working as expected to capture a log event that states a service is down. We have sta...
by dnsGuy314 New Member in Splunk Search 01-29-2021
0 10
0
10
dpwtheitguy
All, I have this search here and it's pretty slow. Any recommendations to speed it up? Currently 250.249 seconds and ...
by dpwtheitguy Loves-to-Learn Lots in Splunk Search 01-28-2021
0 2
0
2
deepuhassan
Hi,I have the below query which does the search on two different sources in the same index and join the results based...
by deepuhassan Explorer in Splunk Search 01-28-2021
0 6
0
6
EStallcup
I'm having a bit of trouble trying to backfill a couple days in my summary index from a query using the collect comma...
by EStallcup Path Finder in Splunk Search 01-28-2021
2 14
2
14
fdevera
How would I take the results from this search:| rex field=initiatedBy.user.userPrincipalName "ex(?<GUID>\d+)z\@"And p...
by fdevera Path Finder in Splunk Search 01-28-2021
0 3
0
3
TheBravoSierra
I'm trying to look for senders where they don't contain values from the lookup mimics.csv. Examples of values in the ...
by TheBravoSierra Path Finder in Splunk Search 01-28-2021
0 3
0
3
redrobish1
Been testing to get a ISE-Splunk successful authentication report and trying this but the "Calling-Station-ID" is not...
by redrobish1 Engager in Splunk Search 01-28-2021
0 2
0
2
youngsuh
Here is what I've done.  How to break out the results into individual software correctly in Splunk.  Any tips could b...
by youngsuh Contributor in Splunk Search 01-28-2021
0 3
0
3
alexspunkshell
Hi All,Please help me with splunk query to find removed (Off-boarded) hosts & index in splunk
by alexspunkshell Contributor in Splunk Search 01-28-2021
0 3
0
3
shazbot79
Hi,I have used the Service Now add on to pull in the incident table. We have a custom SNow field called "dv_u_configu...
by shazbot79 Path Finder in Splunk Search 01-28-2021
0 2
0
2
gcue
i am trying to figure out what the output values are not showing up in my pie chart.  i would eventually like to grap...
by gcue Loves-to-Learn in Splunk Search 01-28-2021
0 2
0
2
prettysunshinez
I have a search query that outputs the count of the event for all the host (i.e., | stats count by host)Now if the co...
by prettysunshinez Explorer in Splunk Search 01-28-2021
0 4
0
4
Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...