Splunk Search

Splunk Search
Community Activity
akapoor47
Here is the raw text - com.companyname.package: stringstart e-38049e11-72b7-4968-b575-ecaa86f54e02 stringend for some...
by akapoor47 New Member in Splunk Search 08-18-2024
0 2
0
2
weird_guy
Hello.I have a lot of events. Each event contains similar string \"errorDetail\":\"possible_value\" Please specify ho...
by weird_guy Explorer in Splunk Search 08-18-2024
0 11
0
11
ankitarath2011
I can see below status for the scheduled savedsearches.status="deferred"status="continued"What is the difference betw...
by ankitarath2011 Path Finder in Splunk Search 08-18-2024
0 4
0
4
Juns
Hi all:          I'm a rookie user ask for help, I want to extract all vault in one _raw data(CLI command log as belo...
by Juns Loves-to-Learn in Splunk Search 08-17-2024
0 1
0
1
neerajs_81
Hello,  How can I get my eval case like to match all values  except a  specific value ? I have below values for a fie...
by neerajs_81 Builder in Splunk Search 08-17-2024
0 2
0
2
satyaallaparthi
I have a dataset to visualize my organization in Splunk. When I search for Org=CDO, I get all the direct reports unde...
by satyaallaparthi Communicator in Splunk Search 08-16-2024
0 1
0
1
uagraw01
Hello Splunkers!!I want to achieve below results in Splunk. Please help me how to achieve this in SPL. Whenever the f...
by uagraw01 Motivator in Splunk Search 08-16-2024
0 5
0
5
FPERVIL
We have both Cisco ASA and FTD firewalls.  The ASA is parsing fine where the appropriate fields are extracted.  As fo...
by FPERVIL Explorer in Splunk Search 08-16-2024
0 3
0
3
RonWonkers
Hi, I have a table with dynamic fields, some of these fields contain no value or NULL, how do I remove these fields w...
by RonWonkers Path Finder in Splunk Search 08-16-2024
0 3
0
3
MK3
Hello,I send a GET request to Postman as follows -curl -u <username> -k https://<url>.net:8089/services/jobs/export -...
by MK3 Explorer in Splunk Search 08-16-2024
0 1
0
1
MoeTaher
Hello All,  I'm having a task to measure the compliancy of Security solution onboarded on the SIEM, that means i have...
by MoeTaher Observer in Splunk Search 08-16-2024
0 5
0
5
wm
Hi all,index=sky sourcetype=sky_trade_wss_timestamp| rex field=_raw "trade_id=\"(?<trade_id>\X+)\", event_id"| rex fi...
by wm Loves-to-Learn Everything in Splunk Search 08-16-2024
0 2
0
2
deepthi5
we have recently upgraded from splunk 8.x to 9.x after which all python scripts are failing with ssl errors we have u...
by deepthi5 Path Finder in Splunk Search 08-15-2024
0 2
0
2
wm
Hi all!I would like to create a no_msg_wait_time column here.This is my existing splunk search query: index=index sou...
by wm Loves-to-Learn Everything in Splunk Search 08-15-2024
0 9
0
9
cherrypick
I have arguments for my macro that contain other values e.g. $env:user$ and $timepicker.earliest$/$timepicker.latest$...
by cherrypick Path Finder in Splunk Search 08-15-2024
0 4
0
4
Cheng2Ready
I have search query, if the Status is field is true for more than 5 min, I need to trigger an alert  no matter the Ev...
by Cheng2Ready Communicator in Splunk Search 08-15-2024
0 3
0
3
kmm2
I am not seeing results for count on each of the fields for the 2 different searches below:   The first one shows the...
by kmm2 Path Finder in Splunk Search 08-15-2024
0 5
0
5
wm
This is my current search queryindex=abc sourcetype = example_sourcetype | transaction startswith="Saved messages to ...
by wm Loves-to-Learn Everything in Splunk Search 08-15-2024
0 3
0
3
timgmanCORP
I have a csv with ip addresses. I would like to conduct a search for addresses that are NOT listed in that csv.  I wa...
by timgmanCORP Observer in Splunk Search 08-14-2024
0 2
0
2
kc_prane
Hello, I have time stamps that are not matching. How do I table the actual "Event log time stamp" ? Splunk Time stamp...
by kc_prane Communicator in Splunk Search 08-14-2024
0 5
0
5
Xe03kfp
How would I search multiple hosts with one search string? I have 6 hosts and want the results for all: Search Strin...
by Xe03kfp Path Finder in Splunk Search 08-14-2024
0 10
0
10
jay_cambra
Is there a way to see who modified system settings in Splunk Cloud?  For example we recently had an issue where an Sp...
by jay_cambra Observer in Splunk Search 08-14-2024
0 1
0
1
MK3
Hello.I have Splunk Enterprise (https://splunk6.****.net run from a browser) and am running a query collecting result...
by MK3 Explorer in Splunk Search 08-14-2024
0 1
0
1
OgoNARA
Hi,   So, I got an issue where I have a log and the log has a field called ERROR_MESSAGES for each event that ends in...
by OgoNARA Explorer in Splunk Search 08-14-2024
0 2
0
2
MK3
Hello,If I want to use a external file that contains 2 columns C and D and use those mappings to a existing query tha...
by MK3 Explorer in Splunk Search 08-14-2024
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...