Splunk Search

Splunk Search
Community Activity
atsin
I can't get a search to work, the column I want to add with a lookup stays empty. The following example lookup I'm u...
by atsin New Member in Splunk Search 11-13-2019
0 1
0
1
bux187
Hi, I have 3 lines in 1 chart (average, threshold, total_alarm) I would like to use different marker types for the 3 ...
by bux187 New Member in Splunk Search 11-13-2019
0 1
0
1
cgkades
I'm sending my splunk server /var/log/audit.log data from each client machine (splunkforwarder). I have logging of TT...
by cgkades Explorer in Splunk Search 11-13-2019
1 5
1
5
eden881
Hi, I need to perform a search on forwarder data from the _internal index, but I need to exclude my indexers from th...
by eden881 Path Finder in Splunk Search 11-13-2019
0 2
0
2
madingdisk
Hi, I have sent a query manually to the background as a job. It will run quite long since the disks are not the fast...
by madingdisk Explorer in Splunk Search 11-13-2019
0 1
0
1
nilbak1
I have following below scenario Different stages of orders placed happens in below sequence order-process started -...
by nilbak1 Communicator in Splunk Search 11-12-2019
0 3
0
3
cuongnguyen112
i have an button that change the search command string, i want to update that string to "search" of searchManager and...
by cuongnguyen112 Engager in Splunk Search 11-12-2019
0 1
0
1
madingdisk
Hi, I have user names in the field ContextUsername in index/ sourcetype index=otcs sourcetype=OtcsSummarytimings. To...
by madingdisk Explorer in Splunk Search 11-12-2019
0 2
0
2
dbashyam
Hi, I have a script which needs parameters to be passed. I know that I can enroll the script in the input.conf file...
by dbashyam Explorer in Splunk Search 11-12-2019
0 3
0
3
kamryn
I have two fields that each contain the same number of multiple values. One contains epoch times for the start of an ...
by kamryn Explorer in Splunk Search 11-12-2019
0 6
0
6
sbentley_ea
Currently I have index=* Name=rateA OR rateB OR rateC OR rateD OR rateE | stats sum(Rate) as sumRate by _time, Name ...
by sbentley_ea Explorer in Splunk Search 11-12-2019
0 3
0
3
lmzheng
For the following search, I want to display the earliest and latest events within a duration of a year. However, I wa...
by lmzheng Explorer in Splunk Search 11-12-2019
0 1
0
1
cchange
I need to show my table column header in below format. I need to get column name and static header under my column. ...
by cchange Path Finder in Splunk Search 11-12-2019
0 4
0
4
pavanae
I have an eval condition in my query as follows My_query | eval object=host." (".id.")" | table host object whic...
by pavanae Builder in Splunk Search 11-12-2019
0 1
0
1
genesiusj
Hello, Here is my SPL (although I don't believe it is necessary(?) as this is a (mis)functioning of SPL in general). ...
by genesiusj Builder in Splunk Search 11-12-2019
0 4
0
4
kishan2356
Hi I have a table in Splunk dashboard where there is one time input that picks what gets displayed on the panel. Say...
by kishan2356 Explorer in Splunk Search 11-12-2019
0 0
0
0
leandromatperei
Hi Splunkers! Just wondering whether anyone can advise me on how to tune the following search statement? The reason...
by leandromatperei Path Finder in Splunk Search 11-12-2019
0 3
0
3
angshul
I am plotting a timechart based on a datetime field (timestamp) in the event. The search looks like: * "logname=cus...
by angshul Path Finder in Splunk Search 11-12-2019
0 6
0
6
danielbb
The following works on one value - | eval devicedowntime2 = round(devicedowntime,4) but not on two or more. Is there...
by danielbb Motivator in Splunk Search 11-12-2019
0 3
0
3
VijaySrrie
Hi, Please help us to get the plain text of pass4Symmkey. Is there a way to decrypt it?
by VijaySrrie Builder in Splunk Search 11-12-2019
1 4
1
4
igschloessl
I need to compare a list consisting of one field from day1 to day2 and get what values where not listed on day 1 but ...
by igschloessl Explorer in Splunk Search 11-12-2019
0 0
0
0
cb046891
This issue comes from the error logs of a login service. When a user scans their badge and attempts to log in with an...
by cb046891 New Member in Splunk Search 11-12-2019
0 2
0
2
infcl
I have one type of log (let's call A) with format: type=log a; name={name}; I also have log type B with format: type...
by infcl Explorer in Splunk Search 11-12-2019
0 2
0
2
genesiusj
Hello, Can the Returned Value From a Case Function be a Search? index="pay_test" AND host IN ("pay20", "pay21") ...
by genesiusj Builder in Splunk Search 11-12-2019
0 8
0
8
willadams
I am trying to figure out how to create a search where I am using multiple counts for an alert I am wanting to write....
by willadams Contributor in Splunk Search 11-12-2019
0 4
0
4
Get Updates on the Splunk Community!

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...