Splunk Search

Splunk Search
Community Activity
oribit
Hi,I’m trying to perform a query in Splunk that not sure if it’s even possible… I have my query over data with a form...
by oribit Observer in Splunk Search 08-04-2020
0 5
0
5
sagaraverma
My Ad-hoc searches getting auto-cancelled randomly.I am running them with admin privileges.There's no problem with RA...
by sagaraverma Loves-to-Learn Everything in Splunk Search 08-04-2020
0 6
0
6
priya0709
My query searches for (Eventcode=509 OR EventCode=118) and generates output (host, Time, EventCode, Task category, Me...
by priya0709 Path Finder in Splunk Search 08-04-2020
0 4
0
4
dacamargov
How do I extract the cities from this text? \"timezone\""America/Sao_Paulo\",\"max_counter\":2,\"timezone\":\"Americ...
by dacamargov Engager in Splunk Search 08-04-2020
0 8
0
8
youngrap
I have 2 tablesI'd like to join the tables.for example : A tablestr1str2str3B tablestr4val1oval1str5val2oval2str6val3...
by youngrap Explorer in Splunk Search 08-04-2020
0 3
0
3
vengat4043
Dear Team,We are used p25() and p75() functions to retrieve Percentile values for a range of values in Splunk. To val...
by vengat4043 Path Finder in Splunk Search 08-04-2020
0 1
0
1
Du
Hi,We have following query -   index=yyy sourcetype=zzz "RAISE_ALERT" logger="aaa" | table uuid message timestamp | e...
by Du Engager in Splunk Search 08-04-2020
0 3
0
3
priya0709
My query searches for eventcode and displays (host, time, task category, message) i want to use some color to highlig...
by priya0709 Path Finder in Splunk Search 08-04-2020
0 4
0
4
askkawalkar
Hi All, I am stuck at a scenario where if user using search in a specific app, then that app folders name should be s...
by askkawalkar Path Finder in Splunk Search 08-04-2020
0 1
0
1
boromir
Hi all,I have a challenge, that i have been struggling for the past few days, and can't find the correct solution.I h...
by boromir Path Finder in Splunk Search 08-04-2020
0 5
0
5
ttovarzoll
I am trying to write a report of 'AccessDenied' messages in our AWS CloudTrail logs. These are in JSON format and the...
by ttovarzoll Path Finder in Splunk Search 08-04-2020
0 3
0
3
vikashperiwal
Hi, I have scenario where index and sourcetype are same and i am tryng below conditions.chart dc(run) OVER app by eve...
by vikashperiwal Path Finder in Splunk Search 08-04-2020
0 3
0
3
kevintelford
I just ran into the problem -- Error in 'IndexScopedSearch': The search failed. More than 125000 events found at time...
by kevintelford Path Finder in Splunk Search 08-04-2020
0 6
0
6
svercelli
So I seem to have an issue similar to the one in this question here and have accidentally indexed over 1,000,000 even...
by svercelli Path Finder in Splunk Search 08-04-2020
0 3
0
3
Sunjux
hello ervery:Scenario:In my case,I use daily search create DnsQueryLog.csv,record the domains inquired every day in t...
by Sunjux Explorer in Splunk Search 08-04-2020
0 5
0
5
Voriaz
Hi,Can we manipulate data with functions in a chart.I have a chart table obtained with :| chart count over user by da...
by Voriaz Engager in Splunk Search 08-04-2020
0 3
0
3
prakashbhanu407
I have 2 queries and need to show the result of both in one table index=someindex queryType="ts" filename=PNASC.HRBD...
by prakashbhanu407 New Member in Splunk Search 08-03-2020
0 5
0
5
jip31
HelloI use the search below  [| inputlookup host.csv | table host] `diskspace` | fields FreeSpaceKB host | ...
by jip31 Motivator in Splunk Search 08-03-2020
0 0
0
0
msage
I want to create a chart showing the attendance between pre covid (February) and current covid (July) for one of our ...
by msage Path Finder in Splunk Search 08-03-2020
0 4
0
4
Username1
If the trend is zero, how do I not have a black background? I just want a grey background 
by Username1 Path Finder in Splunk Search 08-03-2020
0 0
0
0
yvassilyeva
Hi!I have a table created with Splunk search with the name of the site and projects with due dates that looks like th...
by yvassilyeva Path Finder in Splunk Search 08-03-2020
0 0
0
0
bdondlinger
I have scheduled search jobs that run nightly. The first search adds fields A and B for the day to the lookup. The ...
by bdondlinger Explorer in Splunk Search 08-03-2020
1 6
1
6
DHPADIA
Hi,I have multiple records with different data_set value. I want to get each data_set record at a time. So tried usin...
by DHPADIA Engager in Splunk Search 08-03-2020
0 0
0
0
alanzchan
I am trying to mimic the table below. I have the count of the source IP, but how do I get the count of the respective...
by alanzchan Path Finder in Splunk Search 08-03-2020
0 1
0
1
stjack99
I'm using transaction to combine events & generate multi-value fields. What I want to do is keep the values of a mv f...
by stjack99 Explorer in Splunk Search 08-03-2020
0 3
0
3
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...