Splunk Search

Splunk Search
Community Activity
pedroma
Background I have a date string that I want to use in a search, but I don't know how. Log I have this text (called...
by pedroma Engager in Splunk Search 11-15-2019
0 2
0
2
cb046891
I have a field called File_Name that I've generate by trimming the filepath off of my source from a local data input....
by cb046891 New Member in Splunk Search 11-15-2019
0 6
0
6
raja8220
How can i run some script (python or powershell) if i receive some particular log ?? either in search or in alert ??
by raja8220 New Member in Splunk Search 11-15-2019
0 1
0
1
mmasalas
I've read other answers related to conditional searches, still cannot find an answer to my problem. The situation is ...
by mmasalas Explorer in Splunk Search 11-15-2019
0 1
0
1
Gowtham0809
I have a table output like Date Title Product Count ...
by Gowtham0809 New Member in Splunk Search 11-15-2019
0 4
0
4
gill1723
index=main host=10.247.82.1 user=* | rex field=duration "((?\d+)h:)?(?\d+)m:(?\d+)s" | eval duration=duration_second...
by gill1723 Engager in Splunk Search 11-15-2019
0 9
0
9
geraldcontreras
Hi, Thanks in advance This is hard one to put well in the title Basically i have sets of data which contain Student...
by geraldcontreras Path Finder in Splunk Search 11-15-2019
0 2
0
2
gravi
I need to join two searches that do not have a common fields. First search has a field FileName=Test.json Second sea...
by gravi Explorer in Splunk Search 11-15-2019
0 4
0
4
aaalexander
I've just run across an interesting issue with the use of urldecode: if the attempt to decode fails, the function ret...
by aaalexander Engager in Splunk Search 11-14-2019
2 4
2
4
bestSplunker
hello everyone. I have an alert requirement . an administort has login the device. I want to compare his current IP a...
by bestSplunker Contributor in Splunk Search 11-14-2019
0 4
0
4
rashi83
Hi , I am using the below REST command to create 30+ indexes. But they are getting created with default size as 500 G...
by rashi83 Path Finder in Splunk Search 11-14-2019
0 2
0
2
jwalzerpitt
I'd like to be able to search for the following: 1) timechart over X days for the sum of the count of a field 2) spi...
by jwalzerpitt Influencer in Splunk Search 11-14-2019
0 1
0
1
hanikawadhwa
Hi Splunkers, I have been given a requirement where I need to read more than 10k input lookup files to get some resu...
by hanikawadhwa Explorer in Splunk Search 11-14-2019
0 2
0
2
pstamati
I have a lookup table with all active server names and I want to validate which servers on this lists are running a s...
by pstamati Path Finder in Splunk Search 11-14-2019
0 5
0
5
rajagurup
Some events have time as string as "Tue Jun 12 00:00:00 CDT 2018" and some have "Fri Nov 16 00:00:00 CST 2018" in END...
by rajagurup New Member in Splunk Search 11-14-2019
0 3
0
3
tunchi
I have a base search and there are multiple events that I can find depending on some set of the subtstring. Let's say...
by tunchi New Member in Splunk Search 11-14-2019
0 1
0
1
fdw
I have a search that returns information about usernames and their IP, machine name, etc. I want to cross-reference a...
by fdw New Member in Splunk Search 11-14-2019
0 2
0
2
thisissplunk
I'm having trouble conceptually understanding what Datamodels and Pivots provide over just simple lookup tables and w...
by thisissplunk Builder in Splunk Search 11-14-2019
1 1
1
1
ccschulstad
I am trying to create a search that returns events where a field's value equals any value from a specific column of a...
by ccschulstad New Member in Splunk Search 11-14-2019
0 1
0
1
dani9
Where must the data retention be settled in indexer or in my case distributed environment in search head? Then seen t...
by dani9 Explorer in Splunk Search 11-14-2019
0 6
0
6
numeroinconnu12
Bonjour à tous, Ci dessous ma recherche (pas très propre, je suis novice  ) Par contre j'ai une idée, j'ai regro...
by numeroinconnu12 Path Finder in Splunk Search 11-14-2019
0 4
0
4
spluzer
Newbie here. I'm trying to set an alert that runs every 5 minutes and looks back over the past hour. It would trigger...
by spluzer Communicator in Splunk Search 11-14-2019
0 4
0
4
ram254481493
Hi I have implemented ignoreOlderThan for 7 days , I want to verify it if its working or not ? Is their any query or ...
by ram254481493 Explorer in Splunk Search 11-14-2019
0 10
0
10
nagendra008
I am upgrading my Splunk version from 6.3 to the latest and seeing the XML validation issue in one of my dashboards. ...
by nagendra008 Explorer in Splunk Search 11-14-2019
0 1
0
1
kamryn
I have an event that has two fields. PROGRESS_START and PROGRESS_END. Both of these fields contain multiple values....
by kamryn Explorer in Splunk Search 11-14-2019
0 2
0
2
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...