Splunk Search

Splunk Search
Community Activity
anelson1
I'm trying to search for specific words inside the last entry added to a paragraph, where each entry/addition to the ...
by anelson1 New Member in Splunk Search 04-29-2020
0 29
0
29
pm771
Is it possible to "expand" a single variable with comma-separated values into a "list" and then use it inside IN cond...
by pm771 Communicator in Splunk Search 04-29-2020
0 1
0
1
corehan
Hello dear, I want to compare stats count for same host and counts are not equal than create a new field and put "!"...
by corehan Explorer in Splunk Search 04-29-2020
0 4
0
4
rahulrawlani
I am trying to find out all the searches made by users in Splunk. I am running the below search index=_audit action...
by rahulrawlani Explorer in Splunk Search 04-29-2020
0 3
0
3
Inayath_khan
Hi Guys, I am just trying to write a spluNk query to extract data between 1-32 days , >32 days , > 42 days , > 72 da...
by Inayath_khan Path Finder in Splunk Search 04-29-2020
0 2
0
2
celdridge1988
Hi All, ** Summary ** I have windows logs for remote VPN access. I want to be able to graph concurrent use by user. B...
by celdridge1988 Engager in Splunk Search 04-29-2020
0 2
0
2
ChrisCLewis
Good afternoon, I have text in a lookup.csv that has hard returns in it, for example: This is the reason why the s...
by ChrisCLewis Communicator in Splunk Search 04-29-2020
0 3
0
3
pgoldweic
I have a simple search with a sort command at the end as follows: .... some base search | dedup id | table id, name ...
by pgoldweic Communicator in Splunk Search 04-29-2020
0 4
0
4
lhumbertosplunk
Why does the following string work: url=*string1* OR url=*mystring2* But, this one does not work? url in (*mystrin...
by lhumbertosplunk New Member in Splunk Search 04-29-2020
0 3
0
3
iKate
Hi everyone! We've moved some of heavy lookups to kv store and now they work faster and more stable. But one of them ...
by iKate Builder in Splunk Search 04-29-2020
1 0
1
0
katmagee
I appended a CSV to an index, and right now my results pop up as the 100 lines of CSV, and then 30K of the index. W...
by katmagee Engager in Splunk Search 04-29-2020
0 6
0
6
lumpie
I need to change the default output separator of ouputcsv or outputlookup, is there any way to change it? For exampl...
by lumpie New Member in Splunk Search 04-29-2020
0 1
0
1
fabio_lourenco
Currently I am trying to optimize my application and I would like to know if it is possible to use TERM() with a data...
by fabio_lourenco Explorer in Splunk Search 04-29-2020
0 5
0
5
seva98
Hi, I believe that my Splunk's Python has some issue during initialization. This happens whenever I try to run any o...
by seva98 Path Finder in Splunk Search 04-29-2020
0 6
0
6
poddraj
Hi Can someone help me in getting o/p over 1h interval along with Total requests count, Success count, Failure count ...
by poddraj Explorer in Splunk Search 04-29-2020
0 2
0
2
sarvesh_11
Hi Splunkers, Ideally what happens is we set threshold for log file and set some retention. so files do get create l...
by sarvesh_11 Communicator in Splunk Search 04-28-2020
0 2
0
2
ssharma09
Hi Guys, I'm trying to convert events data into metric for CPU, Disk, Memory monitoring for Azure PAAS, using below ...
by ssharma09 Explorer in Splunk Search 04-28-2020
0 1
0
1
ksharma7
If say I have data from December to march in csv every 5 min , and no data from Marc to April.if say in month of nay ...
by ksharma7 Path Finder in Splunk Search 04-28-2020
0 1
0
1
pir8radio
@to4kawa You have helped me a lot the past few weeks, lol you will probably answer this one too!  So i have thes...
by pir8radio Path Finder in Splunk Search 04-28-2020
0 8
0
8
alwagia87
I'm hoping to get help. I have the below errors that are in the same event at in different lines. i would like to g...
by alwagia87 New Member in Splunk Search 04-28-2020
0 1
0
1
nawazns5038
Hi, I would like to extract field values from UI using the field transformations and field extractions from settin...
by nawazns5038 Builder in Splunk Search 04-28-2020
0 12
0
12
mihirpradhan
Hello, I have this subsearch command: [search source="local/data/user/logs/access*" status =5* | table request_id] ...
by mihirpradhan Explorer in Splunk Search 04-28-2020
0 2
0
2
john_dagostino
I've created two accelerated data models. As admin, I can search each of them with |tstats summariesonly=t FROM data...
by john_dagostino Path Finder in Splunk Search 04-28-2020
0 4
0
4
aelliott
I have a list of Cities in a field that are all lower case. Is there a way to capitalize them in search? Example: los...
by aelliott Motivator in Splunk Search 04-28-2020
1 6
1
6
sarit_s
Hello i want to write IF statement as part of my query and want it to run on time frame of 30 days or more... the qu...
by sarit_s Communicator in Splunk Search 04-28-2020
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...