Splunk Search

Splunk Search
Community Activity
manuelostertag
Hello,I've create a search which contains (...(CallerCountry="CN")).When I take a look in the search log in the job i...
by manuelostertag Path Finder in Splunk Search 08-29-2024
1 1
1
1
DDowns
Wondering if there are any industry best practices and/or recommendation for  setting fileSizeGB AND fileCount thresh...
by DDowns New Member in Splunk Search 08-29-2024
0 1
0
1
VRP136
Below is my raw log   [08/28/2024 08:14:50] Current Device Info ... *************************************************...
by VRP136 Engager in Splunk Search 08-29-2024
0 5
0
5
jwhughes58
I'm working on a dashboard in which the user enters a list of hosts.  The issue I'm running into is they must add an ...
by jwhughes58 Contributor in Splunk Search 08-29-2024
0 3
0
3
mninansplunk
Hello,Thank you for your help on this in advance,  I just need to create a field in Splunk Search that contains the v...
by mninansplunk Path Finder in Splunk Search 08-29-2024
0 1
0
1
MatthewWolf
The task guide for the Forage job sim states this: For example, to add “Count by category” to your dashboard, type ou...
by MatthewWolf New Member in Splunk Search 08-29-2024
0 1
0
1
jagan_vannala
HI Team,When i am trying to exclude one field by inserting condition sessionId!=X its not working . even though I use...
by jagan_vannala Observer in Splunk Search 08-29-2024
0 6
0
6
btheneghan
I have never been one to understand regex, however I need to extract everything after the first entry (#172...) into ...
by btheneghan New Member in Splunk Search 08-28-2024
0 2
0
2
jwhughes58
I've got this searchindex=my_index data_type=my_sourcetype earliest=-15m latest=now | eval domain_id=if(isnull(domain...
by jwhughes58 Contributor in Splunk Search 08-28-2024
0 6
0
6
OzzMann80
Howdy, Im fairly new to splunk and couldnt google the answer I wanted to Here we go. I am trying to simplify my queri...
by OzzMann80 Engager in Splunk Search 08-28-2024
0 2
0
2
andreaswpv
Running queries on really large sets of data, and sending the output to an outputlookup works well for weekly refresh...
by andreaswpv Explorer in Splunk Search 08-28-2024
0 2
0
2
sumarri
When I search I want something like this:if(ID =99): then lookup 1,else: lookup 2.What I have right now is something ...
by sumarri Path Finder in Splunk Search 08-28-2024
0 2
0
2
JandrevdM
Good day, I have a query that I would like to add more information onto. The query pulls all users that accessed a AI...
by JandrevdM Path Finder in Splunk Search 08-28-2024
0 3
0
3
st1
I'm not very good with SPL. I currently have Linux application logs that show the IP address, user name, and if the u...
by st1 Path Finder in Splunk Search 08-28-2024
0 2
0
2
irkey
Is there a way to reference or combine multiple fields into a single name so that it can be referenced by that new na...
by irkey Explorer in Splunk Search 08-27-2024
1 5
1
5
ksukumaran
Im getting a "not found" error. On trying to start splunk in the 'bin' folder I am getting am error. Any help appreci...
by ksukumaran New Member in Splunk Search 08-27-2024
0 10
0
10
elsaddiq
I'm a student running the free Community Edition in my homelab. My host currently receives a dynamic IP. Is a static ...
by elsaddiq Engager in Splunk Search 08-27-2024
0 4
0
4
apiprek2
Hi, I have a log that tracks user changes to a specific field in a form. The process is as follows:1. The user access...
by apiprek2 Explorer in Splunk Search 08-27-2024
0 2
0
2
Substance82
Here is my current query. I either get the Totals label in the last column or not at all. I need it to show in the fi...
by Substance82 Path Finder in Splunk Search 08-27-2024
0 3
0
3
bharat
Hi Splunkers,I'm trying to get diskusage for searches running by user. | rest /services/search/jobs | rex field=event...
by bharat Engager in Splunk Search 08-27-2024
0 3
0
3
nkavouris
I have a search which yields a time and correlated serial number for event A.I want to use this time and serial numbe...
by nkavouris Path Finder in Splunk Search 08-27-2024
0 1
0
1
JandrevdM
Good day,I have a query to summarize data per week. Is there a way to display my tables in a better way as my dates f...
by JandrevdM Path Finder in Splunk Search 08-27-2024
0 4
0
4
fahimeh
Hello,I want to write a suppression in Splunk ES that suppresses an event if a specific process occurs at 11 AM every...
by fahimeh Explorer in Splunk Search 08-27-2024
0 5
0
5
zksvc
According to Windows Export Certificate - Splunk Security Content it using macros in the first query `certificateserv...
by zksvc Contributor in Splunk Search 08-27-2024
0 2
0
2
zksvc
Hi everyone i want to ask where can i get latest update for legit_domains.csv ?Ask here because when i check it in lo...
by zksvc Contributor in Splunk Search 08-26-2024
0 6
0
6
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Solution Authors