Splunk Search

Splunk Search
Community Activity
mohammedk01
Hi, I have a field called Location and It have data like Call Type, Site, Wing and Room all in just one field called...
by mohammedk01 Explorer in Splunk Search 10-25-2019
0 4
0
4
kartm2020
We have two different scheduled search and it is providing the two different result. I would like send the both of th...
by kartm2020 Communicator in Splunk Search 10-25-2019
0 1
0
1
Deepz2612
I have the below set of events where I wanted to write regex to capture only the last word Kindly help
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 3
0
3
reneedeleon
I have been working on a search that gives a duration breakdown. I am trying to achieve: thehost theip c...
by reneedeleon Engager in Splunk Search 10-25-2019
0 22
0
22
vkrishnachand
I have a table as shown below team open>3 days open>4 days Avg_days_task_open A 2 4...
by vkrishnachand New Member in Splunk Search 10-25-2019
0 1
0
1
sandeepmakkena
I have data something like this Name. Accepted Rejected Posted Total Change ...
by sandeepmakkena Contributor in Splunk Search 10-25-2019
1 4
1
4
bineetadas
events are like this : number = INCXXXXXX dv_sys = yyyy-mm-dd hh:mm:ss group = lx ........ for a particular value of ...
by bineetadas New Member in Splunk Search 10-25-2019
0 2
0
2
williamcharlton
This cli search command works from a machine with a universal forwarder: splunk search "index="foo" earliest=-7d | ...
by williamcharlton Path Finder in Splunk Search 10-25-2019
0 6
0
6
milky88
I have a field called data. Example of what is in the data field. 1234567890 9999999999 7638278823 1234567891 8475627...
by milky88 New Member in Splunk Search 10-25-2019
0 1
0
1
jeff
I have a pretty complex search where I'm trying to get the DHCP and ACS authentication logs correlated by MAC address...
by jeff Contributor in Splunk Search 10-25-2019
1 3
1
3
simonselvin2019
2 heavy forwarders are configured to receive syslog inputs on port UDP / TCP 1600.Linux servers are configured to sen...
by simonselvin2019 Explorer in Splunk Search 10-25-2019
1 5
1
5
w564432
Hi guys, I am trying to chart multiple days on the same line chart, kind of like in this example (https://docs.splunk...
by w564432 Explorer in Splunk Search 10-25-2019
0 5
0
5
kristofvdbdavin
Hi everyone, I'm trying to get my head around this foreach statement but no luck so far ... Foreach seems like th...
by kristofvdbdavin New Member in Splunk Search 10-25-2019
0 7
0
7
Deepz2612
I have a lookup file which has below 3 columns. Exception_Name Exception_Keyword Comments REXC RemoteException Alert...
by Deepz2612 Explorer in Splunk Search 10-25-2019
0 2
0
2
jip31
hi I use the search below and I call it from a loadjob command After the loadjob execution, I need to filter the da...
by jip31 Motivator in Splunk Search 10-25-2019
0 4
0
4
ldurham
Hi all, After finally getting a automatic DB Lookup working it fails after loading in a couple of value. I've setup ...
by ldurham New Member in Splunk Search 10-24-2019
0 3
0
3
keldridg2
I want to show all the results within the field itself as I do not want it just show the top 10 limits from the list....
by keldridg2 New Member in Splunk Search 10-24-2019
0 5
0
5
Esperteyu
Hi, I'm struggling with the below query "presentable" in a dashboard. Initially, my idea was to have time on the x-a...
by Esperteyu Explorer in Splunk Search 10-24-2019
0 2
0
2
quadrant8
I'm writing a search to parse the command line arguments of 4688 events, and want to be able to sort by what matched ...
by quadrant8 New Member in Splunk Search 10-24-2019
0 2
0
2
Graham_Hanningt
It seems very strange to me to be asking this question in 2019 for Splunk 7.3.1, but I've used Splunk, I've read the ...
by Graham_Hanningt Builder in Splunk Search 10-24-2019
3 3
3
3
jtg1703
Hi, I need some help with a little issue, I have 2 sorcetypes like this: SOURCETYPE A: ID_1 | DESCRIPCION 1 ...
by jtg1703 New Member in Splunk Search 10-24-2019
0 2
0
2
jgillman
We have a sourcetype and I am trying to filter and everytime I do it shows not events. But I know that there are even...
by jgillman Explorer in Splunk Search 10-24-2019
0 4
0
4
NAVEEN_CTS
For last 30 days(which i will select in time filter) I would like to get the count of field X only if it is older tha...
by NAVEEN_CTS Path Finder in Splunk Search 10-24-2019
0 1
0
1
ss026381
I want to change the sourcetype for all incoming logs with sourcetypes not starting with abc. I have following settin...
by ss026381 Communicator in Splunk Search 10-24-2019
0 4
0
4
dreeck
Hey All, I'm trying to make a timechart that shows the % of un-successful requests processed every hour. Success (o...
by dreeck Path Finder in Splunk Search 10-24-2019
1 3
1
3
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...