Splunk Search

Splunk Search
Community Activity
ezmo1982
Hello,I have a problem where fields are not showing on the Field Sidebar when i run a search against certain indexes/...
by ezmo1982 Path Finder in Splunk Search 12-08-2020
0 4
0
4
ArchieCrozier
I have read through almost every Join label topic on the Splunk Community page and I don't seem to see one that fits ...
by ArchieCrozier Path Finder in Splunk Search 12-08-2020
0 8
0
8
jugalkinariwala
Hi Splunkers, I am writing on SPL in the report which has lookup. And if the lookup has less number of rows then over...
by jugalkinariwala Explorer in Splunk Search 12-08-2020
0 0
0
0
rohitnaz007
I am running 2 different Index and have to compare each value in field 1 from 1st index with the values in field2 fro...
by rohitnaz007 Loves-to-Learn Lots in Splunk Search 12-07-2020
0 2
0
2
heath
I have data that is in json format but I only want to keep the value of the MESSAGE field from it. I created a trans...
by heath Path Finder in Splunk Search 12-07-2020
0 4
0
4
bhavlik
I have created a dashboard that is monitoring the number of events received at corporate to the number of events repo...
by bhavlik Path Finder in Splunk Search 12-07-2020
0 2
0
2
rkishoreqa
I have a requirement to fetch stats count from raw data logs. Sharing you the query and results.Query : index="bw6_st...
by rkishoreqa Communicator in Splunk Search 12-07-2020
0 1
0
1
avoelk
this is how my xml events look like: <AttackCoords>-80.33100097073213,25.10742916222947</AttackCoords> <Outcome>Int...
by avoelk Communicator in Splunk Search 12-07-2020
0 2
0
2
Marco
Hello Splunkers,I am trying to write is a condition that says if command starts with "CHA" or "INS" add one.The Query...
by Marco Communicator in Splunk Search 12-07-2020
0 4
0
4
kirrusk
Hi All, i'm trying to compare row values .my table is like  App           label                   env         spacemi...
by kirrusk Communicator in Splunk Search 12-07-2020
0 2
0
2
Sasquatchatmars
Hi all,I have been trying to create a search which compares results from an index with results from an ldap search. T...
by Sasquatchatmars Communicator in Splunk Search 12-07-2020
0 5
0
5
logginz85
Hi there,I'm pretty new to Splunk, but have got a fortigate set up to send all logs to Splunk.Simply looking to find ...
by logginz85 Explorer in Splunk Search 12-07-2020
0 1
0
1
FC50
Hello,I'm pretty new to SPLUNK and I'm looking for help trying to find ASA open connections between two endpoints.Mos...
by FC50 Path Finder in Splunk Search 12-07-2020
0 4
0
4
rrovers
With this searchindex=useradmin sourcetype=role_capabilities| eval capabilities=replace(capabilities,"\s",",")| makem...
by rrovers Contributor in Splunk Search 12-07-2020
0 3
0
3
pck_npluyaud
Hello.It is not a question, it is a use case that I don't arrive to resolve.The situation :a log file on remote serve...
by pck_npluyaud Explorer in Splunk Search 12-07-2020
0 0
0
0
JMFrank215
I have the following search:index=aa sourcetype="bb" Service="/abc" OR Service="/mno" OR Service="/xyz" | chart count...
by JMFrank215 Explorer in Splunk Search 12-06-2020
0 8
0
8
pstalin_
index=105261-cli sourcetype=show_system_resources| dedup deviceId| eval nexus_percent_used=round(100*memory_used/memo...
by pstalin_ Engager in Splunk Search 12-06-2020
0 4
0
4
aking76
I have a search that runs with no issues-ComputerName=CompName* (event_simpleName=*written* OR event_simpleName=Direc...
by aking76 Path Finder in Splunk Search 12-06-2020
0 3
0
3
insatiableavi
Hi everyone,I have a data set such as:Log1:  EventId + EventType1Log 2: EventId + EventType2Log 3: EventId + EventTyp...
by insatiableavi Observer in Splunk Search 12-06-2020
0 3
0
3
Snehaan
Hello team,My search string is as below: index=qrp STAGE IN ("*_RAW", T_FEED_MESSAGES) | stats sum(TRADES) as "TradeC...
by Snehaan Explorer in Splunk Search 12-04-2020
0 1
0
1
jacortijo
Hi, I am getting crazy with a simply JOIN statement to use Tenable data in Splunk.The goal is to enrich the KV store ...
by jacortijo Explorer in Splunk Search 12-04-2020
0 1
0
1
Saikat001
I have  kv lookup table named bingo_kv_table. There are multiple rows having same hosts along with other hosts. I wan...
by Saikat001 Explorer in Splunk Search 12-04-2020
0 1
0
1
LegalPrime
I am trying to monitor for higher than threshold number of events per user. Alert is run once in an hour and I need t...
by LegalPrime Path Finder in Splunk Search 12-04-2020
0 2
0
2
Rody333
Hello,I want to search AD for all users in my organization. But as the list is huge, there is memory error occurring ...
by Rody333 New Member in Splunk Search 12-04-2020
0 0
0
0
leandromatperei
Hello everyone,I have the following pattern of logs and I'm trying to use rex to filter the values.I started doing it...
by leandromatperei Path Finder in Splunk Search 12-04-2020
0 1
0
1
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...