Splunk Search

Splunk Search
Community Activity
Hemnaath
Hi All, Currently we are running out of space in our indexer instance and we wanted to remove the oldest data that is...
by Hemnaath Motivator in Splunk Search 09-04-2019
0 8
0
8
bapun18
I have a inputlookup which have fields like index and count need to create an alert which should trigger when count o...
by bapun18 Communicator in Splunk Search 09-04-2019
0 8
0
8
HattrickNZ
my search looks like this ... | fields _time fieldname | eval wday = strftime(_time, "%a") | where wday = ...
by HattrickNZ Motivator in Splunk Search 09-04-2019
0 0
0
0
landen99
I want to count the events from dc server hosts by hour using tstats: | tstats count where host="srv*dc*" by host GR...
by landen99 Motivator in Splunk Search 09-04-2019
0 6
0
6
uhaba
I am trying to determine the right SPL to dig through a financial data set and look for duplicate entries. The data g...
by uhaba Explorer in Splunk Search 09-04-2019
0 1
0
1
vinaykataaig
I have a below query which shows the recent windows patches installed in the servers, So most of the servers got inst...
by vinaykataaig Explorer in Splunk Search 09-04-2019
0 2
0
2
pavanae
The following are my transforms.conf and props.conf in my cluster master which are sending all the logs for the below...
by pavanae Builder in Splunk Search 09-04-2019
0 4
0
4
reigerourich
Hello, all. I'm looking for the best method to tally a particular field by value and source and then run division wi...
by reigerourich Engager in Splunk Search 09-04-2019
0 2
0
2
vnguyen46
Hi, Let say I have field lastTime (sample value lastTime = 09/01/2019 11:52:31). There are records with lastTime re...
by vnguyen46 Contributor in Splunk Search 09-04-2019
0 7
0
7
marktechuk
I trying to search a lookup table for matching field=user the field contains multiple values for example user=ID, na...
by marktechuk New Member in Splunk Search 09-04-2019
0 1
0
1
marktechuk
Hi trying to search two lookup tables for matching fields values, both tables have the same fields. Just looking to c...
by marktechuk New Member in Splunk Search 09-04-2019
0 3
0
3
bciancio
So I have a regex: rex field=requestUrl "^\w+:\/\/[^\/]+\/(?<uri>.+)$" And then I use the value of that in a looku...
by bciancio New Member in Splunk Search 09-04-2019
0 1
0
1
cyber_castle
For one of the Security usecase, we need to extract Group Memberships from the Domain. The trickier part is some of ...
by cyber_castle Path Finder in Splunk Search 09-04-2019
0 5
0
5
sandeepmakkena
Here is the sample log I want a timechart. {"dtm":"2019-09-04 07:17:39.129 PDT", "logger":".WEB_ORDER_RELEASE", "app...
by sandeepmakkena Contributor in Splunk Search 09-04-2019
0 3
0
3
jaxjohnny2000
Just to be sure, does the admin password need to be the same for each component in the Search Head or Index Cluster?
by jaxjohnny2000 Builder in Splunk Search 09-04-2019
0 5
0
5
bapun18
I have an inputlookup which have 2 fields index and count, I need to create an alert so that alert will trigger when ...
by bapun18 Communicator in Splunk Search 09-04-2019
0 1
0
1
yasein
I have logs like msg="some string here method=aaaa" method=bbbb splunk may extract method=aaaa out of the quoted st...
by yasein Engager in Splunk Search 09-04-2019
0 3
0
3
ips_mandar
I am extracting one field at index time from source field using regex and while searching field value sometime I am u...
by ips_mandar Builder in Splunk Search 09-04-2019
0 2
0
2
russell120
Hi, I have a sample CSV called original.csv. Each day, a search is ran and saved to new.csv. What search to do I need...
by russell120 Communicator in Splunk Search 09-04-2019
0 3
0
3
dzejsonborn
Hi Guys, Can you please tell me how to exclude/whitelist multiple ip adresses from the datamodel search here is the...
by dzejsonborn New Member in Splunk Search 09-04-2019
0 6
0
6
pavanae
The following is the regex I am working on and what I'm trying to do is exclude any username events that ends with "Z...
by pavanae Builder in Splunk Search 09-04-2019
0 2
0
2
abhijitd
index=app sourcetype=accesslog uri="some uri" user!="-" (context="display" OR context="pages") earliest=-7d | rex fi...
by abhijitd New Member in Splunk Search 09-04-2019
0 2
0
2
moonyoungjung
Same SPL result is different by user A and admin SPL-> index=xxx when I do search with userA's userid "interestin...
by moonyoungjung New Member in Splunk Search 09-04-2019
0 5
0
5
Arpmjdr
Hello, I am using Splunk enterprise and splunk enterprise security. I have windows IIS TA configured as well.How to ...
by Arpmjdr Explorer in Splunk Search 09-04-2019
0 1
0
1
duyuzhuo
I don't want to modify the pdfgen_chart.py, is there any other way? and when I use 'https://localhost:8089/services/p...
by duyuzhuo Explorer in Splunk Search 09-04-2019
0 0
0
0
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...