Splunk Search

Splunk Search
Community Activity
whipstash
I am trying to find the duration for a time span. The "in" and "out" numbers are included in the data as type: number...
by whipstash Engager in Splunk Search 04-09-2024
0 3
0
3
BigJohnQ
Hi all, thank in advance for your time!I have a problem writing a properly working query with this case study:I need ...
by BigJohnQ New Member in Splunk Search 04-09-2024
0 4
0
4
jbuecse
We have several summary searches that collect data into metric indexes. They run nightly and some of them create quit...
by jbuecse New Member in Splunk Search 04-08-2024
0 1
0
1
avii7326
Hi All,I have one log that is ABC and it is present in sl-sfdc api and have another log EFG that is present in sl-gcd...
by avii7326 New Member in Splunk Search 04-08-2024
0 4
0
4
Jasmine
i am using below to load colur in drop downlist . Data loading propertly. but it always shows - Could not create sear...
by Jasmine Path Finder in Splunk Search 04-08-2024
0 3
0
3
matoulas
Data Summary is not showing host at all even I already added UDP with ip address on port 514.
by matoulas Path Finder in Splunk Search 04-08-2024
0 1
0
1
alexspunkshell
Below are the CIM Macros where i am using and there are different indexes mapped in individual macros.I want to get t...
by alexspunkshell Contributor in Splunk Search 04-08-2024
0 1
0
1
EG1
Hi,I have this search for example:index=test elb_status_code=200  | timechart count as total span=1s | stats count as...
by EG1 Engager in Splunk Search 04-08-2024
0 4
0
4
KingUs80
I'm looking to craft a query  (a correlation search) that would trigger an alert in the event that an internal system...
by KingUs80 Loves-to-Learn Lots in Splunk Search 04-07-2024
0 1
0
1
simon007
I am using the | fields _raw to show the entire content of the source file as a single event.  It works for most of m...
by simon007 Observer in Splunk Search 04-06-2024
0 1
0
1
kranthimutyala2
curl -k -u svc_aas -d search="search index=aas sourcetype=syslog" https://splunk-prod-api.internal.xxxx.com/services/...
by kranthimutyala2 Engager in Splunk Search 04-06-2024
0 2
0
2
aiguofer
I've written a search that creates a stats table with a medium sized result with around 5 cols and 100k+ rows. When I...
by aiguofer Engager in Splunk Search 04-05-2024
1 4
1
4
jiaqya
Hi, need help to get difference records between 2 lookups with same column name. ex: lookup 1 has the data below: co...
by jiaqya Builder in Splunk Search 04-05-2024
0 5
0
5
avi123
Hi All,I have time field having time range in this format in output of one splunk query:TeamWorkTimings09:00:00-18:00...
by avi123 Explorer in Splunk Search 04-05-2024
0 3
0
3
kriptonpt
Hi  Assuming a sample of data from this example:    | makeresults count=5 | eval f1=random()%2 | eval f2=random()%2 |...
by kriptonpt Engager in Splunk Search 04-05-2024
0 5
0
5
karthi2809
Hi Guys,In my scenario i need show error details for correlation id .There are field called tracePoint="EXCEPTION" an...
by karthi2809 Builder in Splunk Search 04-05-2024
0 4
0
4
bhaskar5428
My apologiesi was using "eventTimestamp" instead of  "@timestamp" in my rex command i just realized and its working n...
by bhaskar5428 Explorer in Splunk Search 04-05-2024
0 5
0
5
IAskALotOfQs
Hi all, getting to grips with SPL and would be forever grateful if someone could lend their brain for the below:   I'...
by IAskALotOfQs Path Finder in Splunk Search 04-04-2024
0 4
0
4
morinb
My environment consists of 1 search head, 1 manager, and 3 indexers. I added another search head so that I can put en...
by morinb Explorer in Splunk Search 04-04-2024
0 3
0
3
Manasa_401
Hello Splunkers,My Splunk instance is configured with default SAML authentication. Now i wanted to add users from ext...
by Manasa_401 Communicator in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
===========================================Query used index=* namespace="dk1017-j" sourcetype="kube:container:kafka-c...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 13
0
13
jaibalaraman
Hi TeamCan anyone help me with Splunk search query to split the successful login from invalid? Ex - I want to exclude...
by jaibalaraman Path Finder in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
I am planning to provide basic splunk session to my team.Can you help if any cheatsheet available online which I can ...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 1
0
1
billchen99k
is it possible to have expression in case command for argument Y?case(x,y)|eval test=case(x=="X", 'a+b') The Y argume...
by billchen99k Engager in Splunk Search 04-03-2024
0 3
0
3
NAGA4
Hi All,I am having a requirement like this. First I need to fetch all the failed searches (lets say skipped searches)...
by NAGA4 Engager in Splunk Search 04-03-2024
0 3
0
3
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...