Splunk Search

Splunk Search
Community Activity
vrmandadi
I have events with GMT time .I want to convert to EST. Wed, 25 Mar 2020 21:43:31 GMT title="Webex Meetings: Users co...
by vrmandadi Builder in Splunk Search 04-04-2020
0 1
0
1
lsantacana
Hi, As part of my search, I'm building some strings with eval and assigning variable to it. I want to use these buil...
by lsantacana Engager in Splunk Search 04-04-2020
0 1
0
1
lbrhyne
We are attempting to write a report querying multiple indexes, which creates a table using data from each. Our challe...
by lbrhyne Path Finder in Splunk Search 04-04-2020
0 2
0
2
jdlocklin526
Hi Everyone, I have a query that produces table 1 below. | from inputlookup:"incident.csv" | where caused_by >= " "...
by jdlocklin526 Observer in Splunk Search 04-04-2020
0 2
0
2
alexman616
Hello! I am trying to search for multiple malware domains in our logs. I cant figure out how to add multiple domains ...
by alexman616 Engager in Splunk Search 04-03-2020
0 4
0
4
leandromatperei
Hello everyone, I have the attached file that is generated every night via my client's internal system and I need to...
by leandromatperei Path Finder in Splunk Search 04-03-2020
0 15
0
15
joshbeckett
I have some data that is being forwarded to another entity via our heavy forwarders and I am trying to monitor that s...
by joshbeckett Explorer in Splunk Search 04-03-2020
0 5
0
5
hollybross1219
hello! This is probably a simple answer that I'm not understanding. Running the query below will add a column at th...
by hollybross1219 Path Finder in Splunk Search 04-03-2020
0 1
0
1
dwibedi03
My index is getting refreshed every 15 mins and new data gets populated every 15 mins. I need to count the events fo...
by dwibedi03 Explorer in Splunk Search 04-03-2020
0 3
0
3
balash1979
Here is the message in splunk and I am trying to extract customer and channel {"line":"2020-04-03T12:24:54.589Z LCS...
by balash1979 Path Finder in Splunk Search 04-03-2020
0 4
0
4
mike000
I tried: index=_nix_xxxx sourcetype=df host=abdhw003 MountedOn="/doc" |eval source="/doc*" and that seems to show the...
by mike000 New Member in Splunk Search 04-03-2020
0 3
0
3
koocies
or do I have to run a whole new query?
by koocies Path Finder in Splunk Search 04-03-2020
0 3
0
3
zacksoft
I have a field serv_time = 44432 in miliseconds. and the default field _time. I want to be able to subtract _tim...
by zacksoft Contributor in Splunk Search 04-03-2020
0 3
0
3
briansarmiento
Hi everyone, I have found this search for GlobalProtect on PaloAlto Networks App, The information showed its really ...
by briansarmiento Explorer in Splunk Search 04-03-2020
0 0
0
0
andrewwjc
I'm using rangemap (mapped with field colors respectively) in chloropeth maps to sort the legend accordingly. However...
by andrewwjc Engager in Splunk Search 04-03-2020
0 0
0
0
canyin
Hi, I have a CSV file as lookup table which contains IP address and timestamp as fields. I need to perform a search ...
by canyin New Member in Splunk Search 04-03-2020
0 4
0
4
packland
I have a kvstore collection with two columns: "_key", and "last_online". The idea is that a search to update the valu...
by packland Path Finder in Splunk Search 04-03-2020
0 1
0
1
garciatdg
I am doing an experiment at home to capture Internet traffic for all of my devices in my house connected to my home w...
by garciatdg New Member in Splunk Search 04-03-2020
0 1
0
1
saurabh0912
Hi, We need to provide report, where we need to capture how long Splunk instance was down in past. Is it possible to ...
by saurabh0912 Path Finder in Splunk Search 04-03-2020
0 5
0
5
RobertRi
Hello Community! I have created a Dashboard with a dbxlookup command in the search. As an admin, i don't have proble...
by RobertRi Communicator in Splunk Search 04-03-2020
0 1
0
1
RobertRi
Hi! Could you please help me with that special case of search? This is my data:User App1. user1 appA2. user1 appB3. u...
by RobertRi Communicator in Splunk Search 04-03-2020
0 2
0
2
surekhasplunk
Hi, I want to know if there is some mechanism by which i can stop indexing a particular kind of data like if segment...
by surekhasplunk Communicator in Splunk Search 04-03-2020
0 8
0
8
dmenon
I have field username - they show up as username=mike and in some cases username=mike. with a dot in the end. How d...
by dmenon Explorer in Splunk Search 04-02-2020
0 5
0
5
leandromatperei
Hello everyone. I need to index the logs below and the example that is on my Dropbox link in a new sourcetype. The ...
by leandromatperei Path Finder in Splunk Search 04-02-2020
0 0
0
0
khojas02
I have the event as below: Mar 31 13:21:29 vg1 : %ASA-4-113019: Group = EMPLOYEE, Username = VAZQUD68, IP = ...*, Se...
by khojas02 Engager in Splunk Search 04-02-2020
0 4
0
4
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...