Splunk Search

Splunk Search
Community Activity
sk
I am searching for queries that are running over a certain amount of time and displaying start/end time and query in ...
by sk Explorer in Splunk Search 01-11-2021
0 7
0
7
jds2726
Hey everyone, I'm trying to write a search that will show the login events that occurred after the last successful lo...
by jds2726 Loves-to-Learn in Splunk Search 01-11-2021
0 3
0
3
snabi
So i have two saved search queries 1. sourcetype="x" "attempted" source="y" | stats count 2. sourcetype="x" "Failed...
by snabi Explorer in Splunk Search 01-11-2021
0 3
0
3
harry1
Hi,I am having a situation where a lookup table defines search filters that needs to be used as part of search query....
by harry1 Engager in Splunk Search 01-11-2021
0 2
0
2
ivana27
Dears,please help. I have log like this [Information] PosService AddInfo:[5006] - Stop customerAnd i want to show in ...
by ivana27 Path Finder in Splunk Search 01-11-2021
0 2
0
2
srujana96
I have a lookup table X which contains list of Servers, my indexer(myserveridx) contains list of server which are up ...
by srujana96 Explorer in Splunk Search 01-11-2021
0 3
0
3
neha19oct97
Hi All,I have a requirement to group keys  (key - value pair) having wildcard char like - usermetadata_*  by other un...
by neha19oct97 Engager in Splunk Search 01-10-2021
0 1
0
1
ivana27
Hello,please help. I have log (example) :[Information] Downtime start:08/01/2021 04:39:56.997 aaxService:NotAvailable...
by ivana27 Path Finder in Splunk Search 01-09-2021
0 3
0
3
variableName
I am attempting to take traffic logs over an arbitrary period of time and use the number of accesses and the time of ...
by variableName Explorer in Splunk Search 01-08-2021
0 10
0
10
splunker9999
Hello Community,  I am looking to Plot a line chart to compare against 2 time ranges by a specific field.This is for ...
by splunker9999 Path Finder in Splunk Search 01-08-2021
0 2
0
2
cros
Hi all, I'm trying to create a visualisation to show the percentage of ticket status (New, Comleted, Cancelled, etc.)...
by cros Engager in Splunk Search 01-08-2021
0 1
0
1
orca
I understand as per docs single value timechart command is required to put sparkline and trendline. However If I am d...
by orca Explorer in Splunk Search 01-07-2021
0 0
0
0
vn_g
index="win*" host="abc" -- doesnt give resultsindex="win*" host="ABC" -- gives resultsBut , it is not suppose to func...
by vn_g Path Finder in Splunk Search 01-07-2021
0 5
0
5
mxanareckless
As you can see, top reports most values in megabytes, but a few are in kilobytes.I am working on a timechart that wil...
by mxanareckless Path Finder in Splunk Search 01-07-2021
0 1
0
1
dl70
Hi!,So my search query looks up an Excel Spreadsheet with a column called Time, that is populated with a time e.g. 10...
by dl70 Loves-to-Learn in Splunk Search 01-07-2021
0 3
0
3
willryals
Hi there!I am kinda new to Splunk so I apologize if my wording is off, but I am trying to collect metrics from a weir...
by willryals Engager in Splunk Search 01-07-2021
0 4
0
4
raghul725
Hello, I have the following log 19:02:32.576 [hz.cache-server-2.HealthMonitor] INFO com.hazelcast.int.dia.HM - [X.X.X...
by raghul725 Explorer in Splunk Search 01-07-2021
0 0
0
0
uagraw01
I want to exclude this event "values='{CARD}hfgjllanabbflvh=='} from the server. Please suggest me regex for this and...
by uagraw01 Motivator in Splunk Search 01-07-2021
0 1
0
1
luckyman80
Hi I am really struggling to find the difference between the 51= time and the 59= time below and add to a separate co...
by luckyman80 Path Finder in Splunk Search 01-07-2021
0 4
0
4
jachockey012
So basically I have some network logs and by base search filters down to source IP, destination IP, destination port,...
by jachockey012 Explorer in Splunk Search 01-07-2021
0 2
0
2
hashsplunk
Hi ,I need to replace the string in a field value role_seu_458137407337_prd-sso-data-science-752-2205-compute-role"  ...
by hashsplunk Loves-to-Learn Lots in Splunk Search 01-07-2021
0 1
0
1
jkjeong
I do exercise example about "Custom search command" step by step , but the following error occurred. What's the pro...
by jkjeong New Member in Splunk Search 01-06-2021
0 2
0
2
sumitkumarsk90
How can I retrieve data from Splunk dashboard or saved searches using SSIS.I am able to create the connection string ...
by sumitkumarsk90 New Member in Splunk Search 01-06-2021
0 0
0
0
moayadalghamdi
Hello splunkers  i want to create a visualization for my command to create a bar chart that contains the (src_ip/user...
by moayadalghamdi Path Finder in Splunk Search 01-06-2021
0 4
0
4
alexspunkshell
Hi All,I want to eliminate TruestedLocation = Zscaler in my splunk search result.Below is my query and screenshot. Pl...
by alexspunkshell Contributor in Splunk Search 01-06-2021
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...