Splunk Search

Splunk Search
Community Activity
smahuja
Hi,I have a dropdown with dynamic query<input type="dropdown" token="clientId" searchWhenChanged="true"><label>Integr...
by smahuja Explorer in Splunk Search 01-14-2021
0 4
0
4
UMDTERPS
The following previous splunk thread works fine:https://community.splunk.com/t5/Archive/Insert-sign-for-each-result-i...
by UMDTERPS Communicator in Splunk Search 01-14-2021
0 2
0
2
abilis
Hi everyone,I've been trying several day to create a query that can give me the list of name/value  inside the JSON f...
by abilis Explorer in Splunk Search 01-14-2021
0 4
0
4
eb1929
Hello i am using the following search host=XXX sourcetype=ZZZ http_status=500 OR http_status=502 "HighCostAPI"| stats...
by eb1929 Explorer in Splunk Search 01-14-2021
0 4
0
4
schilds427
Hello,I'm working on a splunk alert that monitors processes. If a process has been running for a long time I want to ...
by schilds427 Explorer in Splunk Search 01-14-2021
0 2
0
2
dhirendra761
Hi Splunkers,Below is my issue:Having multiple xml files, I need to monitor all the files and extracted the values fr...
by dhirendra761 Contributor in Splunk Search 01-14-2021
0 9
0
9
Ewong
Hi all,A past consultant of ours wrote the following correlation search to detect excessive user account lockouts:ind...
by Ewong Explorer in Splunk Search 01-14-2021
0 3
0
3
okretzer
Need some help with and advance joining of 3 queriesI have three queries that produce tables,  I need to combine the ...
by okretzer Engager in Splunk Search 01-14-2021
0 2
0
2
aalvino
I am trying to make it so if a user clicks on any cell in a Dashboard showing a Statistics table, that will result in...
by aalvino Engager in Splunk Search 01-14-2021
0 3
0
3
lish123
<Jan 10, 2021 6:58:06 PM CST> <Info> <WorkManager> <BEA-002942> <CMM memory level becomes 0. Setting standby thread p...
by lish123 Loves-to-Learn Lots in Splunk Search 01-14-2021
0 10
0
10
rrovers
I'm trying to understand the functionality of keepevicted. I've read several documentation about it but it's still no...
by rrovers Contributor in Splunk Search 01-13-2021
0 4
0
4
sysamit
I have an index cloud_stats on which I need to create a daily error count by source report, so that we can work on th...
by sysamit Engager in Splunk Search 01-13-2021
0 2
0
2
ahcarpenter
Hoping to filter a search based on a list of values from a subquery where in both cases it's matching against a rex'd...
by ahcarpenter Engager in Splunk Search 01-13-2021
0 3
0
3
SS1
Hi, I have two searches Search 1 = index="appv" sourcetype="AppV-User" *PUT /package*Search 2 = index="appv_latest" s...
by SS1 Path Finder in Splunk Search 01-13-2021
0 6
0
6
ahcarpenter
Hi,What's the best way to filter a search against a set of unique id's in a subsearch?Currently, approaching it as su...
by ahcarpenter Engager in Splunk Search 01-13-2021
0 1
0
1
suspicious_link
Hi longtime splunker, first time posterso my goal here is to find the most common and uncommon characters in a field ...
by suspicious_link New Member in Splunk Search 01-13-2021
0 1
0
1
wtaylor149
I'm running a search (below) that has results that sometimes in certain fields will display in the gui as empty (null...
by wtaylor149 Explorer in Splunk Search 01-13-2021
0 1
0
1
sk
We are monitoring users who are deleting tables in our system. We have a field "user_query" which I want to parse by ...
by sk Explorer in Splunk Search 01-13-2021
0 4
0
4
alexanderschlau
Hi ,There is a way to extract a value from field even there is no = between Key and Value? After extracting I want to...
by alexanderschlau Explorer in Splunk Search 01-13-2021
0 4
0
4
subtrakt
I'm trying to avoid "no results found. inspect" message when my query returns 0 value. I just want an empty chart to...
by subtrakt Contributor in Splunk Search 01-13-2021
0 12
0
12
larry_merchant
Hello Folks,I am having some Autosys Job that runs multiple times in a day,  having status lifecycle of Starting, Run...
by larry_merchant Explorer in Splunk Search 01-13-2021
0 1
0
1
sarit_s
Helloim trying to count the number of events of each alert the alerts are saved in a lookup file which looks like thi...
by sarit_s Communicator in Splunk Search 01-13-2021
0 8
0
8
rendie
Hi,I wanna merge two fields into sourcetype as below:props.conf[source::/path/to/folder/*]sourcetype = coalesce(field...
by rendie Path Finder in Splunk Search 01-13-2021
0 2
0
2
rsimmons
I'm running a report on Splunk 6.x and would like to remove the chart on the top of my PDF that is rendered?
by rsimmons Splunk Employee Splunk Employee in Splunk Search 01-13-2021
3 3
3
3
aaa2324
Hi Team,I would like to get response time and transaction per second in one graph timechart. Kindly help with the rig...
by aaa2324 Explorer in Splunk Search 01-12-2021
0 2
0
2
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...