Splunk Search

Splunk Search
Community Activity
AnanthaS
following query yields no results: index=shared_data source="lambda:maintenance_window_handler" sourcetype="httpevent...
by AnanthaS Path Finder in Splunk Search 06-15-2024
0 10
0
10
sajbutler
Fellow Splunkers I am building a query where I want to report on location based on source IP address. For example wi...
by sajbutler Path Finder in Splunk Search 06-14-2024
9 16
9
16
anil1219
I have 2 records for PaymentType as send and receive. I would like to extract PaymentType as receive only so that I c...
by anil1219 Engager in Splunk Search 06-14-2024
0 2
0
2
rdhdr
Hello, I have programs which write status events to Splunk. At the beginning they write EVENT=START and at the end, t...
by rdhdr Explorer in Splunk Search 06-14-2024
0 7
0
7
wealot
For CIM compliance I am trying to fill the action field from some logs using a case. This works in search but not in ...
by wealot Explorer in Splunk Search 06-14-2024
0 1
0
1
heskez
Hi there,I am trying to get some data from MS Defender into a Splunk query. My original KQL query in azure contains |...
by heskez Engager in Splunk Search 06-14-2024
0 1
0
1
Be_JAR
hello,has anyone worked with traces (generated with opentelemetry) of an application on a splunk enterprise?i am inge...
by Be_JAR Path Finder in Splunk Search 06-14-2024
0 0
0
0
Iris_Pi
When navigating to "ESS" -> "Data" -> "Data Availability", will get the following error:>>>Error in 'lookup' command:...
by Iris_Pi Path Finder in Splunk Search 06-14-2024
0 2
0
2
scottrunyon
I have a lookup file that contains two columns, ip and mac. I want to update this file daily by running a query that...
by scottrunyon Contributor in Splunk Search 06-14-2024
0 4
0
4
syk19567
Hi community, My forwarder is putting logs in index A before 2024/06/01, and in index B after this date. To avoid mis...
by syk19567 Explorer in Splunk Search 06-13-2024
0 5
0
5
jrs42
I have data with two fields that share a static range of 10 values.  I'd like to show a column chart with the buckets...
by jrs42 Path Finder in Splunk Search 06-13-2024
0 1
0
1
loganramirez
Splunk Enterprise 9.0.6 and building a summary index of sourcenumbers (count) and distinct destinations called (dc(de...
by loganramirez Path Finder in Splunk Search 06-13-2024
1 1
1
1
nkavouris
I would like to extract the results of each test within the logs array by distinct count of serial number.That is, fo...
by nkavouris Path Finder in Splunk Search 06-13-2024
0 3
0
3
antoniolamonica
Say I create a query that outputs (as a csv) the last 14 days of hosts and the dest_ports the host has communicated o...
by SplunkTrust SplunkTrust in Splunk Search 06-13-2024
0 3
0
3
jthomasc
Current query,  this shows the how many successful login attempts there have been.index=abc granttype=mobile| fields ...
by jthomasc Loves-to-Learn in Splunk Search 06-13-2024
0 2
0
2
Silah
HiI am getting a log feed for a transactional system. Each log entry has a status either End, Begin or something in b...
by Silah Path Finder in Splunk Search 06-13-2024
0 7
0
7
Raja_Selvaraj
  Hi all, Can you please help me with the Splunk query to list the Windows Process Names and CPU utilizations for the...
by Raja_Selvaraj Explorer in Splunk Search 06-13-2024
0 4
0
4
ganeshkumarmoha
Hi Team,For a business requirement, I need to validate log file generated for last an hour with combination of host a...
by ganeshkumarmoha Explorer in Splunk Search 06-13-2024
0 2
0
2
the_wolverine
I had some Splunk users who were deleted from UI Manager page. Is there some way to search for deleted Splunk users ...
by the_wolverine Champion in Splunk Search 06-13-2024
1 6
1
6
Jitendra33
Hi Team,   I am trying to put conversion of transaction for all days of the week in a line chart for successful trans...
by Jitendra33 Engager in Splunk Search 06-13-2024
0 1
0
1
cjohnk
Is it possible to action multiple operations in a single if condition, like what can be done in other languages?For e...
by cjohnk Explorer in Splunk Search 06-12-2024
0 3
0
3
MH1
Newbie here. Trying get the results from the index to match result int he inputlookup to only return result from the ...
by MH1 Engager in Splunk Search 06-12-2024
0 4
0
4
LearningGuy
If I used variable in the mvfilter match, i got the following errorError in 'EvalCommand': The arguments to the 'mvfi...
by LearningGuy Motivator in Splunk Search 06-12-2024
0 3
0
3
Splunk_sid
Hello All,I'm trying to remove leading zeros in IP addresses using rex and mode=sed . the regular expression I'm tryi...
by Splunk_sid Explorer in Splunk Search 06-12-2024
0 4
0
4
ClubMed
Hi,I have the following JSON object that is indexed via the default JSON extraction (INDEXED_EXTRACTIONS){ "asset...
by ClubMed Path Finder in Splunk Search 06-12-2024
0 5
0
5
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...