Splunk Search

Splunk Search
Community Activity
RonWonkers
Lets say we have the following data set:   Fruit_ID Fruit_1 Fruit_2 1 Apple NULL 2 Apple NULL 3 Apple NULL 4 Oran...
by RonWonkers Path Finder in Splunk Search 06-19-2024
0 4
0
4
KulvinderSingh
Hi All,Need some help with SPL query to compare the data from same host on 2 different dates and give me a status as ...
by KulvinderSingh Path Finder in Splunk Search 06-19-2024
0 1
0
1
cjoelly
Coming from SQL, I want to do stuff like GROUP BY and HAVING ...The data is available with a transaction identifier.G...
by cjoelly Loves-to-Learn in Splunk Search 06-18-2024
0 3
0
3
jsven7
| dedup _raw | where NOT MsgId=="AUT22673" OR MsgId=="AUT23574" OR MsgId=="AUT20915" OR MsgId=="AUT22886" What am I...
by jsven7 Communicator in Splunk Search 06-18-2024
1 9
1
9
jose_sepulveda
I need to filter a part of a log using regex, I have the following loglog: {dx.trace_id=xxxxx, dx.span_id=yyyyy, dx.t...
by jose_sepulveda Loves-to-Learn in Splunk Search 06-18-2024
0 6
0
6
sgtwolf1
Thank you everyone for taking the time to ready this. I am new in Splunk and interested in learning more. I have a pr...
by sgtwolf1 Explorer in Splunk Search 06-18-2024
0 1
0
1
Cmiddleton-oppd
Hello, my current search is  index=winsec source=WinEventLog:Security EventCode=6272 | eval date_hour = strftime(_ti...
by Cmiddleton-oppd Explorer in Splunk Search 06-18-2024
0 4
0
4
Silah
I asked in a previous thread for help to get response time based on time differential between two events connected by...
by Silah Path Finder in Splunk Search 06-18-2024
0 2
0
2
Woodpecker
Hi,I have a search as below. I want to find count of recipients by action where how many users received the email vs ...
by Woodpecker Path Finder in Splunk Search 06-18-2024
0 1
0
1
abhinav_go
Hello team ,I am trying to create macro and than use in my splunk dashboard . The purpose is to get time of entered i...
by abhinav_go Explorer in Splunk Search 06-18-2024
0 3
0
3
quadrant8
I've seen the documentation which says "by default subsearches return a maximum of 10,000 results and have a maximum ...
by quadrant8 New Member in Splunk Search 06-18-2024
0 1
0
1
Anushuba
Hi Team I have this requirement .Could you please help me on it .Here is my question I wanted to get result for Pa...
by Anushuba New Member in Splunk Search 06-18-2024
0 1
0
1
shashankk
Hello Team,I need assistance with joining 2 SPL queries to get the desired output. Refer the below log snippet:As per...
by shashankk Communicator in Splunk Search 06-17-2024
0 4
0
4
RahulMisra1
How i update the test_MID_IP.csv  with the output IP, so that next time it runs with updated listindex=abc IP!="10.*"...
by RahulMisra1 Explorer in Splunk Search 06-17-2024
0 3
0
3
heskez
Hi there,I am trying to get some data from MS Defender into a Splunk query. My original KQL query in azure contains |...
by heskez Engager in Splunk Search 06-17-2024
0 1
0
1
leykmekoo
Hello,  I have a lookup table where a list of MAC addresses are listed with the associated Vendors; basically an iden...
by leykmekoo Explorer in Splunk Search 06-17-2024
0 6
0
6
Sphere991
My logs output two consecutive lines in the case of a connection timeout: ... CONNECTION-x.x.x.x:y: connect() timeou...
by Sphere991 New Member in Splunk Search 06-17-2024
0 1
0
1
Ron1999
Hello,How can I get all the pod names with a query where the value will be in between 1.5 - 2.5. I can share a sample...
by Ron1999 New Member in Splunk Search 06-17-2024
0 1
0
1
Marmar
In the indexer, the search for data returns a timeline and details.The timeline is always green: This is fine for que...
by Marmar Observer in Splunk Search 06-16-2024
0 5
0
5
LearningGuy
Hello,I need help improve efficiency of my search using eventstats.The search worked just fine, but when I applied to...
by LearningGuy Motivator in Splunk Search 06-16-2024
0 5
0
5
LearningGuy
Hello,Is it possible to use eventstats with conditions?For example:I only want to apply eventstats only if field name...
by LearningGuy Motivator in Splunk Search 06-16-2024
0 5
0
5
stagare
First Splunk query gives me a value in a table. The value is a jobId. I want to use this jobId in another search quer...
by stagare Explorer in Splunk Search 06-16-2024
0 4
0
4
sivaranjani
index=abc cf_space_name=prod-ad0000123 cf_app_name IN (RED,Blue,Green) "Initiating " OR "Protobuf message received" O...
by sivaranjani Explorer in Splunk Search 06-16-2024
0 4
0
4
Josh1890
Hello, I have a case where I need to do regex  and I built my regex using regex101, everything works great and catchs...
by Josh1890 Explorer in Splunk Search 06-15-2024
0 5
0
5
saurabhatsplunk
Hi All,I want to add entry on first row of my lookup. I know how to append the entry using outputlookup but is there ...
by saurabhatsplunk New Member in Splunk Search 06-15-2024
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...