Splunk Search

Splunk Search
Community Activity
michaelsplunk1
Hi All!When we choose to send an email as an alert action in Splunk, is there a way for Splunk to take the oldest Ser...
by michaelsplunk1 Path Finder in Splunk Search 10-27-2020
0 3
0
3
michaelsplunk1
Hi Everyone!Does the "snowincident" command always create an incident upon being called? I want to use this in an ale...
by michaelsplunk1 Path Finder in Splunk Search 10-27-2020
0 0
0
0
praveenvvn
Hello, am trying to run a query like below: basequery | where match(stringFieldConsistingOfNumsDelimitedBy#, numField...
by praveenvvn Explorer in Splunk Search 10-27-2020
1 10
1
10
vplunk
Hi , I am trying to run a splunk query and i am able to generate the required filed . however i am facing difficultie...
by vplunk Explorer in Splunk Search 10-27-2020
0 0
0
0
doppiolover
I have set of hosts that are installed with different versions of software but logging to the same index, and I need ...
by doppiolover Loves-to-Learn Lots in Splunk Search 10-27-2020
0 2
0
2
jason_hotchkiss
Hello SplunkersI have the following field: MessageThe Message fields have the following values:  1,2,3,4,5,6,7,8,9,10...
by jason_hotchkiss Communicator in Splunk Search 10-27-2020
0 1
0
1
hurryupfool123
I have a field "users" that spits out the result "*****" I want to replace the ***** with an IP address its actually ...
by hurryupfool123 Explorer in Splunk Search 10-27-2020
0 2
0
2
trojan_81
How can I view the default index of a user?In other words, if user runs a search within splunk search app and does no...
by trojan_81 Path Finder in Splunk Search 10-27-2020
0 2
0
2
tsm0099
I have an event which is in json and it has a repeating field say "message"Example:{<!-- -->"Message":[{<!-- -->"message":"xyz987"},{<!-- -->...
by tsm0099 Explorer in Splunk Search 10-27-2020
0 2
0
2
TylerJVitale
I'm trying to find all the saved alerts that have a certain action. I've found this search:|rest/servicesNS/-/-/saved...
by TylerJVitale Explorer in Splunk Search 10-27-2020
0 0
0
0
klaudiac
Hi guys, This little (?) thing's has been wrecking my head all weekend. I'm trying to merge 2 stats commands, or some...
by klaudiac Path Finder in Splunk Search 10-27-2020
0 1
0
1
tsm0099
I have an event in json which has key pairs like:{<!-- -->"timestamp": 157281937,"message":"abc\xyz\pqr\efg",} I have to crea...
by tsm0099 Explorer in Splunk Search 10-27-2020
0 6
0
6
JykkeDaMan
I'm wondering if the following table structure is possible (without custom JS).Raw events are from Jenkins plugin. Be...
by JykkeDaMan Path Finder in Splunk Search 10-27-2020
0 10
0
10
cheriemilk
Hi team,I have below query index&#61;*bizx_application AND sourcetype&#61;perf_log_bizx AND AutoSaveForm OR SaveFormV2 OR Sav...
by cheriemilk Path Finder in Splunk Search 10-26-2020
0 7
0
7
renjujacob88
Hi Splunkers, Whats the best way to rename the existing correlation search.?
by renjujacob88 Path Finder in Splunk Search 10-26-2020
1 4
1
4
mike_nau
Hoping someone can help me to join data in the same index across multiple events. Here is the event dataindexevent_ty...
by mike_nau Engager in Splunk Search 10-26-2020
1 3
1
3
ramesh
When I extract the list of values of a field in stats command, the values appear in separate lines making the output ...
by ramesh Engager in Splunk Search 10-26-2020
3 7
3
7
cantrellr
I have a user field where the name may or may not be prefixed with DOMAIN\ as shown below:DOMAIN\CWIX-USER-SC-4a.rose...
by cantrellr New Member in Splunk Search 10-26-2020
0 2
0
2
vinoths_82
Hi  I have 3 queries as below and all 3 of them have a common field "loaderId". I used join to combine their results ...
by vinoths_82 Explorer in Splunk Search 10-26-2020
1 3
1
3
jjriver2
I am trying to add and search data directly from my local file directory in splunk. I went to setting &gt; data inputs &gt;...
by jjriver2 New Member in Splunk Search 10-26-2020
0 2
0
2
Emily12
Hi everyoneI need to extract value from a string before a specific character "_X" Where X is any integerPlease note o...
by Emily12 Explorer in Splunk Search 10-26-2020
0 2
0
2
barakb
Hi everyone,I'm new to Splunk. I've got this search query:host&#61;"..." earliest&#61;-30d latest&#61;now | stats distinct_count(...
by barakb Engager in Splunk Search 10-26-2020
0 3
0
3
geoffmoraes
I have an alert to discover logins from accounts on servers and workstations. Some of these logins are normal and so ...
by geoffmoraes Path Finder in Splunk Search 10-26-2020
0 3
0
3
hvdtol
Hi,I am a newbie to SPL and would like some help.I want to find the latest date field in my lookup file file.My test....
by hvdtol Path Finder in Splunk Search 10-26-2020
0 4
0
4
LiorG
hi there,i created a dashbord with drilldown values with backslash.how can i escape those backslash to ged values in ...
by LiorG Engager in Splunk Search 10-26-2020
1 3
1
3
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors