Splunk Search

Splunk Search
Community Activity
cuongnguyen112
i have an button that change the search command string, i want to update that string to "search" of searchManager and...
by cuongnguyen112 Engager in Splunk Search 11-12-2019
0 1
0
1
madingdisk
Hi, I have user names in the field ContextUsername in index/ sourcetype index=otcs sourcetype=OtcsSummarytimings. To...
by madingdisk Explorer in Splunk Search 11-12-2019
0 2
0
2
dbashyam
Hi, I have a script which needs parameters to be passed. I know that I can enroll the script in the input.conf file...
by dbashyam Explorer in Splunk Search 11-12-2019
0 3
0
3
kamryn
I have two fields that each contain the same number of multiple values. One contains epoch times for the start of an ...
by kamryn Explorer in Splunk Search 11-12-2019
0 6
0
6
sbentley_ea
Currently I have index=* Name=rateA OR rateB OR rateC OR rateD OR rateE | stats sum(Rate) as sumRate by _time, Name ...
by sbentley_ea Explorer in Splunk Search 11-12-2019
0 3
0
3
lmzheng
For the following search, I want to display the earliest and latest events within a duration of a year. However, I wa...
by lmzheng Explorer in Splunk Search 11-12-2019
0 1
0
1
cchange
I need to show my table column header in below format. I need to get column name and static header under my column. ...
by cchange Path Finder in Splunk Search 11-12-2019
0 4
0
4
pavanae
I have an eval condition in my query as follows My_query | eval object=host." (".id.")" | table host object whic...
by pavanae Builder in Splunk Search 11-12-2019
0 1
0
1
genesiusj
Hello, Here is my SPL (although I don't believe it is necessary(?) as this is a (mis)functioning of SPL in general). ...
by genesiusj Builder in Splunk Search 11-12-2019
0 4
0
4
kishan2356
Hi I have a table in Splunk dashboard where there is one time input that picks what gets displayed on the panel. Say...
by kishan2356 Explorer in Splunk Search 11-12-2019
0 0
0
0
leandromatperei
Hi Splunkers! Just wondering whether anyone can advise me on how to tune the following search statement? The reason...
by leandromatperei Path Finder in Splunk Search 11-12-2019
0 3
0
3
angshul
I am plotting a timechart based on a datetime field (timestamp) in the event. The search looks like: * "logname=cus...
by angshul Path Finder in Splunk Search 11-12-2019
0 6
0
6
bdh5574
We are trying to replicate some data that was in an RMF report and imported into Excel for a graph. We are trying to...
by bdh5574 New Member in Splunk Search 11-12-2019
0 3
0
3
danielbb
The following works on one value - | eval devicedowntime2 = round(devicedowntime,4) but not on two or more. Is there...
by danielbb Motivator in Splunk Search 11-12-2019
0 3
0
3
VijaySrrie
Hi, Please help us to get the plain text of pass4Symmkey. Is there a way to decrypt it?
by VijaySrrie Builder in Splunk Search 11-12-2019
1 4
1
4
igschloessl
I need to compare a list consisting of one field from day1 to day2 and get what values where not listed on day 1 but ...
by igschloessl Explorer in Splunk Search 11-12-2019
0 0
0
0
cb046891
This issue comes from the error logs of a login service. When a user scans their badge and attempts to log in with an...
by cb046891 New Member in Splunk Search 11-12-2019
0 2
0
2
infcl
I have one type of log (let's call A) with format: type=log a; name={name}; I also have log type B with format: type...
by infcl Explorer in Splunk Search 11-12-2019
0 2
0
2
genesiusj
Hello, Can the Returned Value From a Case Function be a Search? index="pay_test" AND host IN ("pay20", "pay21") ...
by genesiusj Builder in Splunk Search 11-12-2019
0 8
0
8
willadams
I am trying to figure out how to create a search where I am using multiple counts for an alert I am wanting to write....
by willadams Contributor in Splunk Search 11-12-2019
0 4
0
4
kranthimutyala
I need to combine 3 fields as single field eg: Field1 Field2 Field3 3 6 xyz 4 7 ...
by kranthimutyala Path Finder in Splunk Search 11-12-2019
0 3
0
3
bbraun
Hi My end goal is to create a custom IP reputation table that tracks successful and failed logins by IP address and...
by bbraun New Member in Splunk Search 11-12-2019
0 2
0
2
lllidan
I have two sources as below: source x: CreateTime, CreateUser,ChangeTime,ChangeUser,....... 2019/0...
by lllidan New Member in Splunk Search 11-11-2019
0 2
0
2
fmatera
I would like to extract the time, did, and callerid from the event with the min(id) by apiid Additionally, extract ex...
by fmatera Explorer in Splunk Search 11-11-2019
0 4
0
4
justinnaldzin
I have events from one source that look like: source=foo fieldA=100 source=foo fieldB=200 source=foo fieldA=300 fie...
by justinnaldzin Engager in Splunk Search 11-11-2019
3 7
3
7
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...