Splunk Search

Splunk Search
Community Activity
danielbb
We wonder what is better for this query - index=_audit action=alert_fired ss_app=<app name> | stats count as Total...
by danielbb Motivator in Splunk Search 12-03-2019
0 2
0
2
helge
I would like to use the Simple XML format rule to specify the formatting of table columns as documented here, e.g.: ...
by helge Builder in Splunk Search 12-03-2019
0 7
0
7
cheriemilk
Hi Team, I have several fields which values are array. For example, event1: ktf2="[Background_Criteria,Profile_Cr...
by cheriemilk Path Finder in Splunk Search 12-03-2019
1 1
1
1
kunwarjit
I am trying to use the token passed through the time input in a dashboard to a search query. In this specific example...
by kunwarjit Engager in Splunk Search 12-03-2019
0 3
0
3
ryangillan
I have the following as my search but wanted to see if a log does not update for X hours then send an alert. If the l...
by ryangillan Explorer in Splunk Search 12-03-2019
0 5
0
5
sylim_splunk
upgraded to 7.3 and they can no longer see all 208 indexes that we have when editing roles. When you edit a role and...
by sylim_splunk Splunk Employee Splunk Employee in Splunk Search 12-03-2019
0 4
0
4
indeed_2000
Hi, I have IBM Informix schema and want to extract data with Splunk from it like this: table name | Index | Trig...
by indeed_2000 Motivator in Splunk Search 12-03-2019
0 16
0
16
afolabia
I'm having errors resolving several missing lookup tables. Any help to resolve these will be appreciated. The lookup...
by afolabia Path Finder in Splunk Search 12-03-2019
0 2
0
2
ehowardl3
I have a three-node search head cluster, when I create a field extraction through the GUI, it takes hours for it to b...
by ehowardl3 Path Finder in Splunk Search 12-03-2019
1 4
1
4
samsonusmc
Providing Splunk 8 the following: | tstats allow_old_summaries=t count from datamodel=Network_Traffic.All_Traffic w...
by samsonusmc New Member in Splunk Search 12-03-2019
0 1
0
1
harshparikhxlrd
Hello, I am using the rex command to extra information on the automation and having it count the number of times a ho...
by harshparikhxlrd Path Finder in Splunk Search 12-03-2019
0 4
0
4
bmendez0428
I've only been "Splunking" for about a month now so I am pretty new to this. I want to add a button to expand certa...
by bmendez0428 Explorer in Splunk Search 12-03-2019
0 0
0
0
jenniferhao
I have the following fields: x, value, I want to get number that count by value of x. for example : 267 is the small...
by jenniferhao Explorer in Splunk Search 12-03-2019
0 4
0
4
adrien_dereumau
So I already have a set of data that I can access and on which I build a chart. Under, you will find my actual resul...
by adrien_dereumau Path Finder in Splunk Search 12-03-2019
1 5
1
5
nathanluke86
Hi, I was wondering if anyone could help with this problem. I have created a lookup for DHCP logs which consists of ...
by nathanluke86 Communicator in Splunk Search 12-03-2019
0 5
0
5
yimcam1980
Hi Splunk enterprise. We currently have many event rules to manage from various sources in PagerDuty, the issue we ...
by yimcam1980 New Member in Splunk Search 12-03-2019
0 0
0
0
pavanraghav
| eval created_upper_token=if("$time_token.latest$"="" OR like("$time_token.latest$","%now%"),"@s","$time_token.lates...
by pavanraghav Explorer in Splunk Search 12-03-2019
1 3
1
3
xiaoyunwuxie
In my subquery, I'm using results returned from main query, when main query have results it works. But when main quer...
by xiaoyunwuxie Explorer in Splunk Search 12-02-2019
1 7
1
7
JAvnaim
Hello, I have an index with ALPR (license plate) data. I'd like to create a table, that shows unique plates detected...
by JAvnaim Explorer in Splunk Search 12-02-2019
0 2
0
2
btorresgil
I need to join two large tstats namespaces on multiple fields. For example, I have these two tstats: | tstats count...
by btorresgil Builder in Splunk Search 12-02-2019
2 10
2
10
galindimitrov
Hi all, My question is focused on open ports but the condition applies to a wide range of scenarios. My question is ...
by galindimitrov Explorer in Splunk Search 12-02-2019
0 10
0
10
harshparikhxlrd
Hello, I was using the round function in my search to limit the results to 2 decimal places. I have gotten it to wor...
by harshparikhxlrd Path Finder in Splunk Search 12-02-2019
0 1
0
1
ayush8878
Eg eg in fuse.log I have a entry like userId=abc while in access.log i have entry like sessionid-12232 | abc | xyz O...
by ayush8878 New Member in Splunk Search 12-02-2019
0 5
0
5
pal_sumit1
I have one props placed in location , opt splunk etc apps appname local props Below is the code [db_accounts] ...
by pal_sumit1 Path Finder in Splunk Search 12-02-2019
0 1
0
1
kishan2356
_time A B C D 6:05 1 1 5 8 6:10 0 3 2 2 6:15 5 0 6 2 6:20 8 9 2 7 6:25 9...
by kishan2356 Explorer in Splunk Search 12-02-2019
0 4
0
4
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...