Splunk Search

Splunk Search
Community Activity
luck123813
Hey everyone, I have an issue where I am ingesting data via REST API, though I am getting a lot of duplicate data i...
by luck123813 Explorer in Splunk Search 02-06-2020
0 2
0
2
vpantangi
I am getting these errors in my internal logs: ERROR SearchOperator:kv - Cannot compile RE \"(?:\s*'[^']*'|\s*"[^"]*...
by vpantangi Path Finder in Splunk Search 02-06-2020
0 1
0
1
btawiah
Please any help will be appreciated. We have a lookup test_pci_asset.csv with a field nt_host values of nt_host are ...
by btawiah Explorer in Splunk Search 02-06-2020
0 0
0
0
marycordova
Assume you have a lookup table and you want to load the lookup table and then search the lookup table for a value or ...
by SplunkTrust SplunkTrust in Splunk Search 02-06-2020
0 2
0
2
khandelwaly
I am not getting any results back using dedup search query: index=prdidx sourcetype="OUTPUT" source="http-access.l...
by khandelwaly Explorer in Splunk Search 02-06-2020
0 19
0
19
ricotries
I am currently monitoring a file that generates logs, but assigns the time in epoch format. Is there a way to transfo...
by ricotries Communicator in Splunk Search 02-06-2020
0 5
0
5
ips_mandar
Hi, Dedup command gives recent unique values based on fields mention. I want to know these recent values are identifi...
by ips_mandar Builder in Splunk Search 02-06-2020
0 2
0
2
thomaap
below average function is not giving me the correct value for last 30 days.Kindly advise | eval sTime=strptime(start...
by thomaap New Member in Splunk Search 02-06-2020
0 5
0
5
gtonti
My log file is: TimeStamp=20180521095103123 Service=ABC12 User=ut1234 Id=12345678 Msg=tttttttttttttTimeStamp=2018052...
by gtonti Explorer in Splunk Search 02-06-2020
1 5
1
5
margie68
Hi, I have an index with events such as: CITY , TICKET, CREATION_DATE, OTHER METADATA FIELDS Pa...
by margie68 New Member in Splunk Search 02-06-2020
0 1
0
1
jiaqya
i have a dynamic column which is bascially today's date, but the column name is 05-02-2020 for example. i would like ...
by jiaqya Builder in Splunk Search 02-06-2020
1 6
1
6
rsaude
Hey everyone, Im trying to come up with a way to get a table stating that, a user was created in splunk had the "Re...
by rsaude Path Finder in Splunk Search 02-06-2020
0 3
0
3
unitedmarsupial
We have a large number of hosts reporting to Splunk, and sometimes (rarely), some of them stop sending events. Is the...
by unitedmarsupial Path Finder in Splunk Search 02-05-2020
0 10
0
10
albasii
Many questions deal with indexed volume per source and per day for licence concern. My need is logs volume per source...
by albasii New Member in Splunk Search 02-05-2020
0 2
0
2
rczone
I have the log snippet below want to extract id and hostname into 2 different fields for example in the expected ou...
by rczone Path Finder in Splunk Search 02-05-2020
0 3
0
3
shruthiangadi
How to change the color of the value based on the range in statistics table visualization
by shruthiangadi Explorer in Splunk Search 02-05-2020
0 6
0
6
shruthiangadi
Hi , I have a statistics table in which each column contains different value for eg: Application Name Application...
by shruthiangadi Explorer in Splunk Search 02-05-2020
1 4
1
4
lyndac
I am indexing json files. Each file contains an array of around 1,000 json objects (with nested arrays/objects). I...
by lyndac Contributor in Splunk Search 02-05-2020
0 6
0
6
dnavia29
Hello, I am trying to simplify a search in Splunk taking only my principal endpoints and not the detail transactions,...
by dnavia29 New Member in Splunk Search 02-05-2020
0 4
0
4
stroud_bc
I have a dashboard which displays some simple "top 15" visualizations based on outbound network traffic. The base sea...
by stroud_bc Path Finder in Splunk Search 02-05-2020
0 7
0
7
msrama5
Hello, I want to break the TestTransaction inside testVal values, JSON needs to break up and show all field values i...
by msrama5 Explorer in Splunk Search 02-05-2020
0 3
0
3
ekost
Our search head pool nodes were recently upgraded from 6.6.1 to 7.3.0. After the upgrade, the scheduled searches have...
by ekost Splunk Employee Splunk Employee in Splunk Search 02-05-2020
1 1
1
1
okakizaki_splun
I’ve been trying to create a yearly/half-yearly/quarterly/monthly/weekly report by using timechart and span command. ...
by okakizaki_splun Splunk Employee Splunk Employee in Splunk Search 02-05-2020
0 3
0
3
j_star
Problem I have a gui running as javaw.exe and I want to identify when this gui is "Not Responding" Tools I am using ...
by j_star New Member in Splunk Search 02-05-2020
0 0
0
0
lukepatrick
I have an existing search that finds "RunDate" "StartTime" "EndTime" stored as part of test run summaries. The search...
by lukepatrick Explorer in Splunk Search 02-05-2020
0 2
0
2
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...