Splunk Search

Splunk Search
Community Activity
Substance82
Stuck again and not sure what I'm missing... I have the first two steps, but cannot figure out the syntax to use Time...
by Substance82 Path Finder in Splunk Search 06-21-2024
0 2
0
2
kp_pl
below is my scenario described by Oracle DBA I have two indexesINDEXAfieldAfieldBfieldCINDEXBfieldAfieldXfieldYfield...
by kp_pl Path Finder in Splunk Search 06-21-2024
0 3
0
3
Siddharthnegi
Hello , How can I know the start time and the latest time  coming of data of all index .meaning that when was the fir...
by Siddharthnegi Contributor in Splunk Search 06-21-2024
0 3
0
3
Splunk_sid
Hi Team,We have onboarded csv data into Splunk and each row in csv is ingested into _raw field . I need to bring this...
by Splunk_sid Explorer in Splunk Search 06-21-2024
0 5
0
5
Kadae
Hi, I have the results of an append operation as follows:IDCol3col4col5a  abcaabcNo axyzYes b  abcb  xyzbxyzNo bfghYe...
by Kadae Splunk Employee Splunk Employee in Splunk Search 06-20-2024
0 3
0
3
runiyal
I have a logfile like this - 2024-06-14 09:34:45,504 INFO [com.mysite.core.repo.BaseWebScript] [http-nio-8080-exec-4...
by runiyal Path Finder in Splunk Search 06-20-2024
0 3
0
3
Sophie6
I have two query tablestable 1index="k8s_main" namespace="app02013" "EConcessionItemProcessingStartedHandler.createRm...
by Sophie6 New Member in Splunk Search 06-20-2024
0 1
0
1
paulcurry
I have a search that returns all of my correlation searches for a given app.   | rest splunk_server=local count=0 /se...
by paulcurry Path Finder in Splunk Search 06-20-2024
0 3
0
3
Substance82
How do I add a  new field and set the value to seven days ago from the current date, snapped to thebeginning of the c...
by Substance82 Path Finder in Splunk Search 06-20-2024
0 2
0
2
Memphis
Hi all - I am trying to create what I would think is a relatively simple conditional statement in Splunk. Use Case: I...
by Memphis Explorer in Splunk Search 06-20-2024
0 4
0
4
jrowland1230
I want to exact a string 'GUID" from the log right after "customers". This regex expression works in https://regex101...
by jrowland1230 Explorer in Splunk Search 06-20-2024
0 4
0
4
avikc100
this is the log dataavikc100_0-1718892426100.png i want a report like this:avikc100_1-1718892579363.png  my current q...
by avikc100 Path Finder in Splunk Search 06-20-2024
0 2
0
2
EricMonkeyKing
Hi community, can anyone help me figure out the log which Get incorrect data after Update(both get and update will lo...
by EricMonkeyKing Explorer in Splunk Search 06-20-2024
0 2
0
2
illuminatedaxis
My application is a backend web service. All events in a request contain the same value for a "req_id" field.I have a...
by illuminatedaxis Engager in Splunk Search 06-19-2024
0 2
0
2
akgmail
How to find difference of the time in days and hours respectively between Event time of the data and current time?For...
by akgmail Explorer in Splunk Search 06-19-2024
0 5
0
5
RonWonkers
Lets say we have the following data set:   Fruit_ID Fruit_1 Fruit_2 1 Apple NULL 2 Apple NULL 3 Apple NULL 4 Oran...
by RonWonkers Path Finder in Splunk Search 06-19-2024
0 4
0
4
KulvinderSingh
Hi All,Need some help with SPL query to compare the data from same host on 2 different dates and give me a status as ...
by KulvinderSingh Path Finder in Splunk Search 06-19-2024
0 1
0
1
cjoelly
Coming from SQL, I want to do stuff like GROUP BY and HAVING ...The data is available with a transaction identifier.G...
by cjoelly Loves-to-Learn in Splunk Search 06-18-2024
0 3
0
3
jsven7
| dedup _raw | where NOT MsgId=="AUT22673" OR MsgId=="AUT23574" OR MsgId=="AUT20915" OR MsgId=="AUT22886" What am I...
by jsven7 Communicator in Splunk Search 06-18-2024
1 9
1
9
jose_sepulveda
I need to filter a part of a log using regex, I have the following loglog: {dx.trace_id=xxxxx, dx.span_id=yyyyy, dx.t...
by jose_sepulveda Loves-to-Learn in Splunk Search 06-18-2024
0 6
0
6
sgtwolf1
Thank you everyone for taking the time to ready this. I am new in Splunk and interested in learning more. I have a pr...
by sgtwolf1 Explorer in Splunk Search 06-18-2024
0 1
0
1
Cmiddleton-oppd
Hello, my current search is  index=winsec source=WinEventLog:Security EventCode=6272 | eval date_hour = strftime(_ti...
by Cmiddleton-oppd Explorer in Splunk Search 06-18-2024
0 4
0
4
Silah
I asked in a previous thread for help to get response time based on time differential between two events connected by...
by Silah Path Finder in Splunk Search 06-18-2024
0 2
0
2
Woodpecker
Hi,I have a search as below. I want to find count of recipients by action where how many users received the email vs ...
by Woodpecker Path Finder in Splunk Search 06-18-2024
0 1
0
1
abhinav_go
Hello team ,I am trying to create macro and than use in my splunk dashboard . The purpose is to get time of entered i...
by abhinav_go Explorer in Splunk Search 06-18-2024
0 3
0
3
Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...