Splunk Search

Splunk Search
Community Activity
Bassik
Beginner here, I'm trying to run a search on unique logins for a web-based application. The current logs, however, do...
by Bassik Path Finder in Splunk Search 07-16-2020
0 28
0
28
jadengoho
Why are  we seeing logs from year ago even we use sumarriesonly=t| tstats summariesonly=t earliest(_time) as Earliest...
by jadengoho Builder in Splunk Search 07-15-2020
0 0
0
0
Deniserity
Hi! I'm new to splunk, I'm just learning it now because I need to understand the splunk search string given to me by ...
by Deniserity Engager in Splunk Search 07-15-2020
0 2
0
2
summerura
Hi Splunkers,  my search is like that and it makes table with data and error message. But error message includes like...
by summerura Explorer in Splunk Search 07-15-2020
0 3
0
3
rashi83
Hi ,I need to replace value of _time with special extracted log time event. I am using this search but its not workin...
by rashi83 Path Finder in Splunk Search 07-15-2020
0 2
0
2
asahni
Hi Guys,I am trying find changes in office 365 ip address and URL using SPL by comparing results from today to yester...
by asahni Loves-to-Learn in Splunk Search 07-15-2020
0 0
0
0
rsantkumar
Hi. I have a splunk table which tracks  all the plugin version available to install for each plugin. Please note that...
by rsantkumar Observer in Splunk Search 07-15-2020
0 3
0
3
rajatsinghbagga
Hello Everyone, I am trying to count the events for the window 8PM(Day1) to 6AM(Day2) for last 3 days so that I can ...
by rajatsinghbagga Explorer in Splunk Search 07-15-2020
0 1
0
1
jstocker
I am fairly new to Splunk and only have the basics under my belt at best. I'm having trouble proving out the followin...
by jstocker New Member in Splunk Search 07-15-2020
0 2
0
2
paxo
Hi everyone, silly question but I'm not much practical with Splunk queries. How to speed up a search that is currentl...
by paxo Loves-to-Learn Lots in Splunk Search 07-15-2020
0 16
0
16
Filomenka
Hello, fellow splunkers!I am trying to find a search string where I could define a variable & then use it in the same...
by Filomenka Explorer in Splunk Search 07-15-2020
0 7
0
7
RJ_Grayson
After upgrading to Splunk 6.5.1 we began receiving an error message in the GUI stating "File Integrity checks found 1...
by RJ_Grayson Path Finder in Splunk Search 07-15-2020
0 9
0
9
johnfrias
I have the outcome of my search results but I want to filter by only OS.  I was able to get all the results but need ...
by johnfrias New Member in Splunk Search 07-15-2020
0 4
0
4
tkwaller
Hello On my search heads, I am able to find searches that are named "search1", "search2" etc: savedsearch_name sear...
by tkwaller Builder in Splunk Search 07-15-2020
3 4
3
4
nalia_v
Hello.Again, these lookups ). The hardest thing about queries.The request itself is the identification of users who l...
by nalia_v Loves-to-Learn Everything in Splunk Search 07-15-2020
0 0
0
0
dflodstrom
I want to restrict a given role's access to the data in Splunk by using 'Restrict search terms' under access controls...
by dflodstrom Builder in Splunk Search 07-15-2020
2 4
2
4
asahni
Hi Guys,I am trying find changes in office 365 ip address and URL using SPL by comparing results from today to yester...
by asahni Loves-to-Learn in Splunk Search 07-14-2020
0 0
0
0
tonyclifford
I have the following query: host=PRODPLEX NOT "C:\\WINDOWS\\system32" | timechart span=1m sum(deltatasks) The Ev...
by tonyclifford Engager in Splunk Search 07-14-2020
0 3
0
3
pred15
Hi, any help with this would be appreciated! rex field=msg.message "loc=(?<place>\d+)" | search place="16" | stats co...
by pred15 Engager in Splunk Search 07-14-2020
0 3
0
3
bvan
I've tried to follow others posts as well as the documentation here and I've come up empty. I have a bunch of device ...
by bvan Explorer in Splunk Search 07-14-2020
0 5
0
5
murilocepeda
how can I compare information from two different hosts?For exemple, On a host I have the name, number and phone calls...
by murilocepeda Engager in Splunk Search 07-14-2020
0 1
0
1
griffins
Assume I have a simple search that lists in a table the email addresses of those who recently sent an email:index=ema...
by griffins Explorer in Splunk Search 07-14-2020
0 2
0
2
Ephrem32
I have a list of ip address that come from 1 source, I want a query to list the ip address separately and make them t...
by Ephrem32 Explorer in Splunk Search 07-14-2020
0 1
0
1
willadams
I am unable to get additional columns from a CSV I have referenced in an SPL query that I have written.  In the CSV t...
by willadams Contributor in Splunk Search 07-14-2020
0 1
0
1
karadikid
Hi All,So, I know I can get a list of all enabled saved searches by doing:| rest count=0 /servicesNS/-/-/saved/search...
by karadikid Explorer in Splunk Search 07-14-2020
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...