Splunk Search

Splunk Search
Community Activity
rrovers
Hi,I have a json-file in splunk with an arguments{}-field like this field1=[content_field1] field2=[content_field2] f...
by rrovers Contributor in Splunk Search 05-23-2024
0 1
0
1
CSNinja
We are receiving some notables that reference an encoded command being used with PowerShell, and the notable lists th...
by CSNinja New Member in Splunk Search 05-23-2024
0 0
0
0
kenbaugher
I have two sources that I'd like to combine/join or search on one based on the other.Source 1 - has two fields  name ...
by kenbaugher Path Finder in Splunk Search 05-23-2024
0 2
0
2
jaibalaraman
Hi How to write spl search query by adding multiple field in single search  Field 1 - contain data like authorization...
by jaibalaraman Path Finder in Splunk Search 05-23-2024
0 6
0
6
Richard_400
I want chart as follow. I could show count each count value (cannot Calc field) (index=interface_count devicename IN ...
by Richard_400 Engager in Splunk Search 05-23-2024
0 2
0
2
cbiraris
Hi Team,I need help to create a alert which can raise if latest hour count is 10% less than last week same day same h...
by cbiraris Path Finder in Splunk Search 05-23-2024
0 1
0
1
mia
my search as below, the two <my search command for list user rating list> search command is the same, how to reduce t...
by mia Explorer in Splunk Search 05-22-2024
0 4
0
4
ViniciusMariano
Hey guys, I'm having trouble joining two datasets with similar valuesI'm trying to join two datasets, both have a com...
by ViniciusMariano Explorer in Splunk Search 05-22-2024
0 5
0
5
paragg
index="xyz" sourcetype = abc" | search Country="ggg" statusCode=200 | stats count as Registration | where Registrati...
by paragg Loves-to-Learn Lots in Splunk Search 05-22-2024
0 1
0
1
rar0
I have a search that returns the following table (after transpose):columnrow 1row 2search_nameUC-315UC-231ID7zAt/75Df...
by rar0 Loves-to-Learn Lots in Splunk Search 05-21-2024
0 4
0
4
loganramirez
I have a dbxquery command that queries an Oracle server that has a DATE format value stored in GMT.My SQL converts it...
by loganramirez Path Finder in Splunk Search 05-21-2024
0 4
0
4
larryaucoin
Since upgrading to 9.1.2, I am no longer able to see table output on the Splunk Search.  Even with the most simplisti...
by larryaucoin Observer in Splunk Search 05-21-2024
0 2
0
2
ash2
Hi All, hope you are having a great day, I have a quick question. I have the data given as below, how do i extract ju...
by ash2 Explorer in Splunk Search 05-20-2024
0 8
0
8
alfredoh14
hello I need to determine the app name based on a lookup table for the SPL search below.the SPL search results has a ...
by alfredoh14 Explorer in Splunk Search 05-20-2024
0 3
0
3
whitecat001
Pls can i get a query that shows statistics on search activity in splunk 
by whitecat001 Explorer in Splunk Search 05-20-2024
0 3
0
3
triva79
we have data in Splunk for user sessions in an app and I am trying to produce a line graph to show usage every hour. ...
by triva79 Explorer in Splunk Search 05-20-2024
0 5
0
5
LearningGuy
Hello,I am currently correlating an index with CSV file using lookup.I am planning to move CSV file to database and w...
by LearningGuy Motivator in Splunk Search 05-19-2024
0 13
0
13
NC_AS
Please tell me how to make the output replace some characters in the field definitions.Specifically, the problem is t...
by NC_AS Explorer in Splunk Search 05-19-2024
0 2
0
2
mrsplunx
Hi guys I need to find all dashboards not used in x days. I saw this has already been asked in this forum but I can'...
by mrsplunx New Member in Splunk Search 05-19-2024
0 4
0
4
kagarlickij
I need to see all events with fields that have "PROD*" in name, e.g. "PROD deploy", "PROD update", etc.`index=myIndex...
by kagarlickij Explorer in Splunk Search 05-19-2024
0 19
0
19
Pere
Hi,I am quite new to Splunk, so sorry in advance if I ask silly questions.I have below task to do: "The logs show tha...
by Pere New Member in Splunk Search 05-18-2024
0 1
0
1
kombi
Event Actions > Show sources failing at 100/1000 events with the below 2 errors - [e430ac81-66f7-40b8-8c76-baa24d2813...
by kombi Loves-to-Learn Lots in Splunk Search 05-17-2024
0 0
0
0
jrs42
Here's a part of my query, ignoring where the data is coming from: | eval bucket=case(dur < 30, "Less than 30sec", du...
by jrs42 Path Finder in Splunk Search 05-17-2024
0 4
0
4
fishn
I have the following query that gives me a list of pods that are missing based off the comparison of what should be d...
by fishn Explorer in Splunk Search 05-17-2024
0 10
0
10
mgutschelhofer
I want to combine two search results, whereby I'm only interested in the last x/y events from each subquery. Somethin...
by mgutschelhofer Explorer in Splunk Search 05-17-2024
0 5
0
5
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...