Splunk Search

Splunk Search
Community Activity
mike_nau
Hoping someone can help me to join data in the same index across multiple events. Here is the event dataindexevent_ty...
by mike_nau Engager in Splunk Search 10-26-2020
1 3
1
3
ramesh
When I extract the list of values of a field in stats command, the values appear in separate lines making the output ...
by ramesh Engager in Splunk Search 10-26-2020
3 7
3
7
cantrellr
I have a user field where the name may or may not be prefixed with DOMAIN\ as shown below:DOMAIN\CWIX-USER-SC-4a.rose...
by cantrellr New Member in Splunk Search 10-26-2020
0 2
0
2
vinoths_82
Hi  I have 3 queries as below and all 3 of them have a common field "loaderId". I used join to combine their results ...
by vinoths_82 Explorer in Splunk Search 10-26-2020
1 3
1
3
jjriver2
I am trying to add and search data directly from my local file directory in splunk. I went to setting > data inputs >...
by jjriver2 New Member in Splunk Search 10-26-2020
0 2
0
2
Emily12
Hi everyoneI need to extract value from a string before a specific character "_X" Where X is any integerPlease note o...
by Emily12 Explorer in Splunk Search 10-26-2020
0 2
0
2
barakb
Hi everyone,I'm new to Splunk. I've got this search query:host="..." earliest=-30d latest=now | stats distinct_count(...
by barakb Engager in Splunk Search 10-26-2020
0 3
0
3
geoffmoraes
I have an alert to discover logins from accounts on servers and workstations. Some of these logins are normal and so ...
by geoffmoraes Path Finder in Splunk Search 10-26-2020
0 3
0
3
hvdtol
Hi,I am a newbie to SPL and would like some help.I want to find the latest date field in my lookup file file.My test....
by hvdtol Path Finder in Splunk Search 10-26-2020
0 4
0
4
LiorG
hi there,i created a dashbord with drilldown values with backslash.how can i escape those backslash to ged values in ...
by LiorG Engager in Splunk Search 10-26-2020
1 3
1
3
Sakshi_Parashar
So, if I have an index=abc with fields a,bAlso, I have index=xyz with fields b,cNow I want to count the results where...
by Sakshi_Parashar Engager in Splunk Search 10-25-2020
0 2
0
2
ilyar
Hello,I have field name: let's call it - "foo" and a value I desire to add to my search - "bar".When I execute a norm...
by ilyar Observer in Splunk Search 10-25-2020
0 6
0
6
aarthirajaraman
I want to know what is the difference between usenull and fillnull command in the splunk? can anyone help me with it ...
by aarthirajaraman Engager in Splunk Search 10-25-2020
1 2
1
2
huaraz
Hi,I am trying to order events of wireshark data i.e. events liketime1  src, dst,src_port,dst_port  SYN   time2 src, ...
by huaraz Explorer in Splunk Search 10-24-2020
0 1
0
1
djroks89
Hi Splunk Team,I have a quick question. I'm writing a join query wherein i want the query A ("Birth Test") to execute...
by djroks89 Explorer in Splunk Search 10-24-2020
0 1
0
1
roderickjones
Hi, This might be a super basic question but I have a log and I need to create a dashboard that represents a value fo...
by roderickjones Engager in Splunk Search 10-23-2020
0 2
0
2
Marco
Hi folks,host=* AlertType="Warning" |bucket _time span=day| stats count min(count) max(count)  avg(count) stdev(count...
by Marco Communicator in Splunk Search 10-23-2020
0 1
0
1
OliverG91
I am looking for a way to list the counts by customer (for example, including 0 activity) for the past hour, among al...
by OliverG91 Explorer in Splunk Search 10-23-2020
1 2
1
2
mackmarvin
I got a search query but I need help displaying the failed scans of the IP or devices. What field I use for that part...
by mackmarvin New Member in Splunk Search 10-23-2020
0 1
0
1
Fei
What command would I use to check if anyone has downloaded a large file(s) before they were terminated?
by Fei New Member in Splunk Search 10-23-2020
0 1
0
1
vamsigurram
I need to find the users that are using sourcetypes in their savedsearches (reports/dashboards).I have list of source...
by vamsigurram Path Finder in Splunk Search 10-23-2020
0 3
0
3
msage
I'm working on a project for work where I want to see employee entry data for specific groups. We have a lookup file ...
by msage Path Finder in Splunk Search 10-23-2020
1 3
1
3
fisuser1
having a problem creating proper TIME_FORMAT for the following data.  Seeing "Could not use strptime to parse timesta...
by fisuser1 Contributor in Splunk Search 10-23-2020
0 1
0
1
Mckechnie
Hi All,I am trying to find:Users using event code 4769The count of computers a user connects to within 1hr which is g...
by Mckechnie Engager in Splunk Search 10-23-2020
0 1
0
1
krishman23
I have a log generated in splunk which will have unique id  in with pipe symbols:ex:    19:46:47.146 - [http-nio-8000...
by krishman23 Explorer in Splunk Search 10-23-2020
0 7
0
7
Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...