Splunk Search

Splunk Search
Community Activity
MK3
Hello.I have Splunk Enterprise (https://splunk6.****.net run from a browser) and am running a query collecting result...
by MK3 Explorer in Splunk Search 08-14-2024
0 1
0
1
OgoNARA
Hi,   So, I got an issue where I have a log and the log has a field called ERROR_MESSAGES for each event that ends in...
by OgoNARA Explorer in Splunk Search 08-14-2024
0 2
0
2
MK3
Hello,If I want to use a external file that contains 2 columns C and D and use those mappings to a existing query tha...
by MK3 Explorer in Splunk Search 08-14-2024
0 3
0
3
Sishad
Hi Splunk experts,I want to compare the response code of our API for last 4 hours with last 2 days data over the same...
by Sishad Explorer in Splunk Search 08-14-2024
0 4
0
4
Declan123
Hi All,I am trying to calculate 2 values by multiplication and then compare these 2 values on a column/bar chart. My ...
by Declan123 Explorer in Splunk Search 08-14-2024
0 2
0
2
tly22
Hi, I have a single search that produces the following table where fieldA and fieldB are arbitrary strings that may b...
by tly22 Explorer in Splunk Search 08-14-2024
0 5
0
5
trobknight7
Hi there, Splunk Community! First time poster! Whoo! Let me outline the situation, goal, and problem faced briefly:I ...
by trobknight7 Engager in Splunk Search 08-14-2024
0 1
0
1
zksplunk
Is there any difference between a empty macro with  () or "" I see search with both both return results but do not be...
by zksplunk Engager in Splunk Search 08-13-2024
0 4
0
4
Cheng2Ready
There is no Pattern or punctuation so running Regex might not work in this situation since I cant know what kind of E...
by Cheng2Ready Communicator in Splunk Search 08-13-2024
0 3
0
3
DataMechanic
The original query: host="MEIPC" source="WinEventLog:Application" OR source="WinEventLog:Security" OR source="WinEven...
by DataMechanic Engager in Splunk Search 08-13-2024
0 1
0
1
sg86sourav
Hi, We are looking for a splunk query using which we have to create a dashboard to show average and maximum TPS for ...
by sg86sourav New Member in Splunk Search 08-13-2024
0 8
0
8
elend
Did someone ever faced or implementing this on Splunk ES?. Im facing an issue when try add TAXII feed from OTX API co...
by elend Communicator in Splunk Search 08-13-2024
0 2
0
2
jtm7x2
Hello.  I have a data source that is "mostly" json formatted, except it uses single quotes instead of double, therefo...
by jtm7x2 Explorer in Splunk Search 08-13-2024
0 2
0
2
Mondaya13
Hello everyone, I am trying to get the queue or event counts with status=“spooling” that happened after the very firs...
by Mondaya13 Explorer in Splunk Search 08-13-2024
0 2
0
2
neerajs_81
Hi All,i need to consolidate / correlate data from 2 different indexes as explained below. I have gone thru multiple ...
by neerajs_81 Builder in Splunk Search 08-12-2024
0 6
0
6
Taruchit
Hello All, I have a lookup file which stores data of hosts across multiple indexes.  I have reports which fetch infor...
by Taruchit Contributor in Splunk Search 08-12-2024
0 5
0
5
chimuru84
Hello! I'm trying to implement a mechanism to flag users who have not had a third-party authentication verification i...
by chimuru84 Path Finder in Splunk Search 08-12-2024
0 7
0
7
johnsvakel
I am working on a tax product and we have products per tax year. Now I want to compare the performance of the tax pro...
by johnsvakel Observer in Splunk Search 08-12-2024
0 10
0
10
gcusello
Hi all, I found a very strange behavior related to Search Modes: - I have an index with many millions of events mig...
by SplunkTrust SplunkTrust in Splunk Search 08-12-2024
2 18
2
18
marycordova
Problem: search: 1. Search: index=win* EventCode=4624 |userlookup(Account_Name)| table Account_Name name sam eid m...
by SplunkTrust SplunkTrust in Splunk Search 08-12-2024
1 7
1
7
juancarlos_pola
Hello. This is my third of fourth question in this page (I think) so I would like to beg you mercy if this issue/ques...
by juancarlos_pola Explorer in Splunk Search 08-09-2024
1 9
1
9
srivenna
I am trying to extract fields for this custom data but unable to parse the data| extract kv pairdelim="  " kvdelim=" ...
by srivenna Engager in Splunk Search 08-09-2024
0 1
0
1
vijreddy30
 Hi All,Httpevent collector logs in to splunk, not showing the host,source,sourcetype in splunk, please find the belo...
by vijreddy30 Loves-to-Learn Everything in Splunk Search 08-09-2024
0 1
0
1
Alnardo
[serversindex] Configuration initialization for /opt/splunk/var/run/searchpeers/serverhead-1721913866 took longer tha...
by Alnardo Engager in Splunk Search 08-08-2024
0 4
0
4
lemospt
Hi guys,   i have the following query that produces table below   index=core_ct_report_* | eval brand=case(like(repo...
by lemospt Explorer in Splunk Search 08-08-2024
0 1
0
1
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...