Splunk Search

Splunk Search
Community Activity
mahesh27
Query: |mstats sum(error.count) as Count where index=metrics_data by provider errorid errorname |search errorname=ap...
by mahesh27 Communicator in Splunk Search 05-06-2024
0 5
0
5
Jasmine
Please help me on the below items:#1)| chart count(WriteType) over Collection by WriteType | sort Collectionfor abov...
by Jasmine Path Finder in Splunk Search 05-06-2024
0 1
0
1
sintjm
I want to get the values from the path field but I can't extract this alone as data.initial_state.path would output e...
by sintjm Path Finder in Splunk Search 05-06-2024
0 4
0
4
maiks1
Hi all!I'm currently trying to create a RDP session analysis dashboard.  I'm using sysmon eventlogs, specifically Eve...
by maiks1 Engager in Splunk Search 05-06-2024
0 1
0
1
kranthimutyala2
I want to extract all the key value pairs from this event  dynamicallyCan someone help with the query INFO 2024-04-29...
by kranthimutyala2 Engager in Splunk Search 05-06-2024
0 14
0
14
Wise_Women
Hello,I am in need of some help from the community. Is it possible to create a  token in a schedule report and create...
by Wise_Women Engager in Splunk Search 05-06-2024
1 2
1
2
james_n
Hi, we could see message ="executed" for started state field. so, would like to replace with same massage where state...
by james_n Path Finder in Splunk Search 05-06-2024
0 8
0
8
Sotu
I am able to pull my AD users account information successfully except for their email addresses.  What am I doing wro...
by Sotu Engager in Splunk Search 05-04-2024
0 2
0
2
karthi2809
Hi All,I am using case statement to map values instead of other values. But i am not getting the values.I am getting ...
by karthi2809 Builder in Splunk Search 05-03-2024
0 4
0
4
karthi2809
Hi All,I am trying to get count of enabled and disabled from field. Then i want to show the field values based on lat...
by karthi2809 Builder in Splunk Search 05-03-2024
0 11
0
11
kuul13
Hi, I am new to Splunk. I am trying to figure out how to extract count of errors per api calls made for each client. ...
by kuul13 Explorer in Splunk Search 05-02-2024
0 1
0
1
guru333
_raw=line 1line 2line 3line 4line 5line 6how to define another new field "copyofraw"  to contain just line 5 and line...
by guru333 Engager in Splunk Search 05-02-2024
0 7
0
7
BARNEYRUDD
Hi, I'm testing thawing of some frozen data and it's not working. I have thawed some previously frozen data and am ex...
by BARNEYRUDD Explorer in Splunk Search 05-02-2024
0 12
0
12
SplunkDash
Hello,  I have a use case to get the index name from the field of one of the index/sourcetype and use that index name...
by SplunkDash Motivator in Splunk Search 05-01-2024
0 6
0
6
mjones414
I have a summary index that pulls in normalized data from 2 different sources (entirely different applications that c...
by mjones414 Contributor in Splunk Search 05-01-2024
0 2
0
2
Badger
DescriptionHow can I produce a URL in an alert email that uses field values, either by in-line results or in the body...
by Badger New Member in Splunk Search 05-01-2024
0 1
0
1
LizAndy123
I have a simple search index=xxxxx "User ID" and I need the correct syntax to get the actual username in the results....
by LizAndy123 Path Finder in Splunk Search 05-01-2024
0 1
0
1
Sotu
I wrote a simple query to parse my Windows Event Security logs to look for a user account, however I am looking to ad...
by Sotu Engager in Splunk Search 05-01-2024
0 2
0
2
bhupalbobbadi
Is there any way to search for events which has any special characters? thanks in advance for any help.
by bhupalbobbadi Path Finder in Splunk Search 05-01-2024
0 4
0
4
jwhughes58
I'm working with a field named Match_Details.match.properties.user.  It contains domain\user information that I'm try...
by jwhughes58 Contributor in Splunk Search 04-30-2024
0 2
0
2
Roy_9
Hi,I am facing a executable permission issue for the few scripts for a splunk app and seeing these errors on various ...
by Roy_9 Motivator in Splunk Search 04-30-2024
0 5
0
5
saidAb
Hi all,A query, can calculate http calls, success responses and error response. I need an addition to the  query to g...
by saidAb Explorer in Splunk Search 04-30-2024
0 10
0
10
anissabnk
Hello,  I'm having problems using roles.I use this search, which gives me results via the admin role. [search index="...
by anissabnk Path Finder in Splunk Search 04-30-2024
0 1
0
1
saidAb
Hello everyone,I am looking for a Splunk search query to get the duration time of three sequential response code 200....
by saidAb Explorer in Splunk Search 04-30-2024
0 9
0
9
bigll
in raw data I have portion that I would like to use in report. "changes":{"description":{"before":"<some text or empt...
by bigll Path Finder in Splunk Search 04-30-2024
0 4
0
4
Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...