Splunk Search

Splunk Search
Community Activity
mipa04
Hi, I am completely new to splunk and have to parse field that looks like this:params="['field1: value1', 'field2: va...
by mipa04 Engager in Splunk Search 05-28-2024
0 2
0
2
msalghamdi
Hello Splunkers.   i need your help in creating a search that would count number of values for a field in a month and...
by msalghamdi Path Finder in Splunk Search 05-28-2024
0 2
0
2
karthi2809
Hi All,I have a Splunk dashboard with dynamic token, Here a simplified example of my setup. In the dashboard $new_val...
by karthi2809 Builder in Splunk Search 05-28-2024
0 3
0
3
Orange_girl
Hello, I'm still new to SPLUNK and still learning so apologies for any incorrect naming   I have a search in SPLUNK ...
by Orange_girl Loves-to-Learn Everything in Splunk Search 05-28-2024
0 2
0
2
SSJMBP
Hey all, I'm new to Splunk and only have basic knowledge of Python/Scripting and RegEx. I'm trying to build my hands-...
by SSJMBP New Member in Splunk Search 05-27-2024
0 2
0
2
zoe
HiI have the tablex, y1, y2 and plot them in the line chart. how can I find the value where the two lines cross ? 
by zoe Path Finder in Splunk Search 05-27-2024
0 6
0
6
Laurent
hello i have a list of events structured with the following fields : guid (uniqueid), property (name of a property ),...
by Laurent Explorer in Splunk Search 05-27-2024
0 20
0
20
munang
Hello, I'm Splunk Newbie.This is a post that I found while looking for improvement of Splunk's search performance, bu...
by munang Path Finder in Splunk Search 05-27-2024
0 3
0
3
joock3r
Hey all,I'm building new dashboard that contains 2 multiselect values:Site: USA, Romania, Turkey.... (only countries)...
by joock3r Explorer in Splunk Search 05-26-2024
0 4
0
4
sultanulariff
I have table as below DateOut AirlineBag TypeTotal Processed01/05/2024IXLocal10001/05/2024IXTransfer12002/05/2024BALo...
by sultanulariff Engager in Splunk Search 05-25-2024
0 7
0
7
av_
I have a time picker & a time dropdown which has static values.   <panel id="pqr"> <input type="time" token="time"> <...
by av_ Path Finder in Splunk Search 05-25-2024
0 14
0
14
saleshai
Hi, I tried to add a piece of code to change the color of values based on certain condition, but it is not reflecting...
by saleshai Explorer in Splunk Search 05-24-2024
0 5
0
5
rahulmittal2391
not able to search with any attribute which are having .(dot) like env.cookieSize NOT WORKING ------------------   in...
by rahulmittal2391 New Member in Splunk Search 05-24-2024
0 3
0
3
fabrizioalleva
Hi all,we've a procedure that's writes index only where there's a KO:So I've a sequence of events like these:DATE,RES...
by fabrizioalleva Path Finder in Splunk Search 05-24-2024
0 4
0
4
hem03
Hello community,I aim to compare the 'src_ip' referenced below with the CIDR IP ranges in the lookup file 'zscalerip....
by hem03 Loves-to-Learn Lots in Splunk Search 05-24-2024
0 6
0
6
mythili
Hi All,I am using transaction command to group events and get stop time of a device. | transaction sys_id startswith=...
by mythili Explorer in Splunk Search 05-24-2024
0 5
0
5
Pandey_21
Hi All, I am trying to rename a data but it is giving me error. I am doing in this way.| rename "Data Time series* *e...
by Pandey_21 New Member in Splunk Search 05-24-2024
0 1
0
1
Brenny
Hi,I got the following error message when trying to connect to an eventhub,Error occurred while connecting to eventhu...
by Brenny Explorer in Splunk Search 05-23-2024
0 2
0
2
Chirag812
index=abc sourcetype=abc | timechart span=1m eval(count(IP)) AS TimeTaken Now I want to get 95th percentile of this ...
by Chirag812 Explorer in Splunk Search 05-23-2024
0 3
0
3
MCW
Hi expert, My SPL looks something like: index=<> sourcetype::<> | <do some usual data manipulation> | timechart min(f...
by MCW Explorer in Splunk Search 05-23-2024
0 2
0
2
victorcorrea
Hi Splunk Community,I need to build an alert that will be triggered if a specific signature is not present in the log...
by victorcorrea Path Finder in Splunk Search 05-23-2024
0 6
0
6
rrovers
Hi,I have a json-file in splunk with an arguments{}-field like this field1=[content_field1] field2=[content_field2] f...
by rrovers Contributor in Splunk Search 05-23-2024
0 1
0
1
CSNinja
We are receiving some notables that reference an encoded command being used with PowerShell, and the notable lists th...
by CSNinja New Member in Splunk Search 05-23-2024
0 0
0
0
kenbaugher
I have two sources that I'd like to combine/join or search on one based on the other.Source 1 - has two fields  name ...
by kenbaugher Path Finder in Splunk Search 05-23-2024
0 2
0
2
jaibalaraman
Hi How to write spl search query by adding multiple field in single search  Field 1 - contain data like authorization...
by jaibalaraman Path Finder in Splunk Search 05-23-2024
0 6
0
6
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors