Splunk Search

Splunk Search
Community Activity
cadm777
We use Splunk, and I do know that our SystemOut logs are forwarded to the Splunk indexer. Does anyone have some examp...
by cadm777 Explorer in Splunk Search 08-08-2024
0 3
0
3
jcsvaldueza
I need to generate a report where it will output table with different timings in columns.Trick part is logs captured ...
by jcsvaldueza New Member in Splunk Search 08-08-2024
0 1
0
1
lorispiana
HI all,I just installed the security essential app on my splunk but i'm having issues retrieving the MITRE matrix.I g...
by lorispiana New Member in Splunk Search 08-08-2024
0 4
0
4
Nraj87
Is it possible to get each day first login event( EventCode=4634)  as "logon" and Last event of   (EventCode=4634) as...
by Nraj87 Explorer in Splunk Search 08-08-2024
0 1
0
1
super_edition
Hello Everyone,I have written the splunk query to remove last 2 character from the string:processingDuration = 102ms ...
by super_edition Path Finder in Splunk Search 08-08-2024
0 1
0
1
jjohn149
|union [ search index=osp source=xxx EVENT_TYPE=xxx EVENT_SUBTYPE=xxx field1=* field3=xxx field4="" | eval DATE = s...
by jjohn149 Observer in Splunk Search 08-07-2024
0 5
0
5
whitecat001
how can i troubleshoot when using a dashboard to export data, the data exported has numerous NULL values where there ...
by whitecat001 Explorer in Splunk Search 08-07-2024
0 1
0
1
mamagreen
Good morning!I am receiving the Error: Could not load lookup=LOOKUP-reply_code on multiple boxes.  Any similar situat...
by mamagreen Engager in Splunk Search 08-07-2024
0 1
0
1
ssuluguri
Hi Splunkers, My requirement is below . I have lookup where 7 hosts defined . when my search is running for both tsta...
by ssuluguri Path Finder in Splunk Search 08-07-2024
0 10
0
10
kmm2
I have a powershell script running get-brokersession which then exports the results to a txt file.   The file is then...
by kmm2 Path Finder in Splunk Search 08-07-2024
0 8
0
8
chimpui
Hi Splunkers!I wish to get data in a specific time range using earliest and latest command .I have checked with time ...
by chimpui New Member in Splunk Search 08-07-2024
0 4
0
4
RanjiRaje
Hi, Can anyone please help me to frame the SPL script.I have to collect the list of devices reporting in splunk along...
by RanjiRaje Explorer in Splunk Search 08-07-2024
0 7
0
7
PickleRick
Hi there.I'm relatively new to searching in Splunk so I can't sometimes get my head wrapped up around some Splunk con...
by SplunkTrust SplunkTrust in Splunk Search 08-07-2024
0 5
0
5
mekamundia
I find on splunkd.log a lot of warnings as: "Corrupt csv header, contains empty value (col #3)" without any other det...
by mekamundia Explorer in Splunk Search 08-06-2024
1 12
1
12
Bart
HI, I'm running a search for two different timeranges, for missing datapoint pair it's creating discrepancy with my c...
by Bart Explorer in Splunk Search 08-06-2024
0 2
0
2
JuanPerez
Hello friends, I am trying to create a heat map where I can see the indexes on the left side and in each cell of the ...
by JuanPerez New Member in Splunk Search 08-06-2024
0 2
0
2
Chirag812
Can we create a new field which contains the group of multiple servers name and that field I can use directly in all ...
by Chirag812 Explorer in Splunk Search 08-06-2024
0 2
0
2
cbiraris
Hi Teami am trying to make below field regex which is coming in every single event. but its not allowing me to use sa...
by cbiraris Path Finder in Splunk Search 08-06-2024
0 3
0
3
Thulasinathan_M
Hi Splunk Experts,I'm not sure how easy it's using Splunk, I've a field (_time) with list of epoch_time values in it....
by Thulasinathan_M Contributor in Splunk Search 08-06-2024
0 2
0
2
nb662x
below is my json file. I want to notify whenever  there is a change in last property , "displayName": Included Update...
by nb662x Observer in Splunk Search 08-06-2024
0 6
0
6
cxs6345
I have a data set for web traffic.  A sessionID ties all traffic for an individual browsing session together - all ev...
by cxs6345 Engager in Splunk Search 08-05-2024
0 1
0
1
ravir_jbp
I have a CSV raw data which has files names and data inside the files which is seperated by double quotes and comma. ...
by ravir_jbp Explorer in Splunk Search 08-05-2024
0 14
0
14
splunkpoornima
Hi all. I have a field called TaskAction that has some 400 values. But, I only want the distinct values of that field...
by splunkpoornima Communicator in Splunk Search 08-05-2024
17 4
17
4
Gaya3_devi
Hello Splunkers,I have the following query returning the search results, index="demo1" | search "metrics.job.overall_...
by Gaya3_devi Explorer in Splunk Search 08-05-2024
0 3
0
3
tomjb94
Hi -  I am looking to optimise this search by removing dedup, the idea of the search is to remove duplicate paymentId...
by tomjb94 Observer in Splunk Search 08-05-2024
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...