| I am reading the documentation to create a simple search script: #!/usr/bin/env python import os import sys import ... by brent_weaver Builder in Splunk Search 10-02-2025 0 1 | 0 | 1 | ||
| index="*azure*" UserId="*#EXT#*" earliest=-300d@d latest=now| eval activity_time = coalesce(strptime(CreationTime, "%... by GattyBiggz Loves-to-Learn in Splunk Search 10-01-2025 0 12 | 0 | 12 | ||
| | rest splunk_server=* /services/data/indexes| fields title currentDBSizeMB lastIngestTime| eval Bytes = round(coales... by NanSplk01 Communicator in Splunk Search 09-29-2025 0 4 | 0 | 4 | ||
| I have a drop-down in my Classic Dashboard that is populating from an inputlookup.Looks like this:<input type="dropdo... by dmoberg Path Finder in Splunk Search 09-29-2025 0 3 | 0 | 3 | ||
| I'm a novice working in fraud prevention; appreciate your help. When running the following, I'm getting a failure er... by JHFRDANALYSIS Engager in Splunk Search 09-27-2025 0 7 | 0 | 7 | ||
| Good afternoon.I have been working on this issue for a couple of days, and I just cannot seem to get this SPL correct... by sarge338 Path Finder in Splunk Search 09-26-2025 0 3 | 0 | 3 | ||
| We have a need to setup Synthetic Browser Tests against many endpoints. The main purpose for the Browser tests is to ... by dmoberg Path Finder in Splunk Search 09-26-2025 0 1 | 0 | 1 | ||
| Hi, Let's say we have 2 multivalue fields Field1={a,b,c,d} Field2={a,b,c,d,e} Is it possible to evaluate the diff... by HeinzWaescher Motivator in Splunk Search 09-25-2025 0 9 | 0 | 9 | ||
| I've got a list of over 100 account names and I'd like to search Splunk to find out the most recent activity (if any)... by hawkeyesc72 Engager in Splunk Search 09-25-2025 0 5 | 0 | 5 | ||
| According to https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-instruct-Splunk-to-not-add-quotes-when-p... by BacPhan-2005 Loves-to-Learn in Splunk Search 09-25-2025 0 1 | 0 | 1 | ||
| I use fieldformat "Date Time"=strftime('Date Time',"%F %T %:z %Z","Asia/Hong Kong"). but it said the syntax is wrong.... by cyberpop Observer in Splunk Search 09-25-2025 0 7 | 0 | 7 | ||
| I have a regex to extract filename from object field. This works completely fine in Search.index="test" | rex field=o... by luffy Engager in Splunk Search 09-24-2025 0 1 | 0 | 1 | ||
| I have a json from Grafana.| makeresults count=1 | eval json = "{ \"datasources\": { \"ds_a\": {}, \"ds_b\"... by weidertc Contributor in Splunk Search 09-24-2025 0 5 | 0 | 5 | ||
| I have a search with a chart that works well but when attempting to save I get the following error message: "Value of... by BlueHelix New Member in Splunk Search 09-23-2025 0 1 | 0 | 1 | ||
| I am trying to fetch top 10 max Requests count of events with their corresponding response time. So using the below q... by akarivaratharaj Communicator in Splunk Search 09-23-2025 0 5 | 0 | 5 | ||
| Hello wonderful SplunkersI know we can have a WILDCARD match in a lookup where we can match a key to a wildcard in th... by nabeel652 Builder in Splunk Search 09-23-2025 0 6 | 0 | 6 | ||
| Hi,I’m building a search on the Network_Traffic datamodel to detect high outbound flows (>1 GB).I need to exclude a l... by imst27 Loves-to-Learn Lots in Splunk Search 09-22-2025 0 1 | 0 | 1 | ||
| Here is what I haveNow I want to add a new column like this eval nullPercent = round((nullCount/total)*100, 2) where ... by Ombessam Path Finder in Splunk Search 09-22-2025 0 4 | 0 | 4 | ||
| Am having issue with a Splunk alert triggering for daily snapshot of aws account ids. The alert is suppose to trigger... by whitecat001 Explorer in Splunk Search 09-19-2025 0 2 | 0 | 2 | ||
| I’m trying to find logs where requestId value is equal to requestId value in another logTrying to find logs like this... by caschmid Observer in Splunk Search 09-18-2025 0 4 | 0 | 4 | ||
| HelloI have a two multivalue fields: poiMv (point of interest) and timeMv as a result of a transaction command. Both ... by Walter_Oesch Observer in Splunk Search 09-15-2025 0 2 | 0 | 2 | ||
| Dear ExpertsMy search: index="pm-azlm_internal_prod_events" sourcetype="azlmj" [| inputlookup pm-azlm-reg-ocp-tea... by Ste Path Finder in Splunk Search 09-15-2025 0 2 | 0 | 2 | ||
| Hello experts, I have a dashboard in simple xml that shows single number charts which reflect, by host and applicatio... by rdhdr Explorer in Splunk Search 09-13-2025 0 1 | 0 | 1 | ||
| Error in my results query: Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-... by JHFRDANALYSIS Engager in Splunk Search 09-12-2025 0 1 | 0 | 1 | ||
| I need to get historical logs from splunk between a time interval more specifically between two dates. When I do not ... by sselias Engager in Splunk Search 09-12-2025 0 4 | 0 | 4 |