Splunk Search

Splunk Search
Community Activity
BARNEYRUDD
Hi, I'm testing thawing of some frozen data and it's not working. I have thawed some previously frozen data and am ex...
by BARNEYRUDD Explorer in Splunk Search 05-02-2024
0 12
0
12
SplunkDash
Hello,  I have a use case to get the index name from the field of one of the index/sourcetype and use that index name...
by SplunkDash Motivator in Splunk Search 05-01-2024
0 6
0
6
mjones414
I have a summary index that pulls in normalized data from 2 different sources (entirely different applications that c...
by mjones414 Contributor in Splunk Search 05-01-2024
0 2
0
2
Badger
DescriptionHow can I produce a URL in an alert email that uses field values, either by in-line results or in the body...
by Badger New Member in Splunk Search 05-01-2024
0 1
0
1
LizAndy123
I have a simple search index=xxxxx "User ID" and I need the correct syntax to get the actual username in the results....
by LizAndy123 Path Finder in Splunk Search 05-01-2024
0 1
0
1
Sotu
I wrote a simple query to parse my Windows Event Security logs to look for a user account, however I am looking to ad...
by Sotu Engager in Splunk Search 05-01-2024
0 2
0
2
bhupalbobbadi
Is there any way to search for events which has any special characters? thanks in advance for any help.
by bhupalbobbadi Path Finder in Splunk Search 05-01-2024
0 4
0
4
jwhughes58
I'm working with a field named Match_Details.match.properties.user.  It contains domain\user information that I'm try...
by jwhughes58 Contributor in Splunk Search 04-30-2024
0 2
0
2
Roy_9
Hi,I am facing a executable permission issue for the few scripts for a splunk app and seeing these errors on various ...
by Roy_9 Motivator in Splunk Search 04-30-2024
0 5
0
5
saidAb
Hi all,A query, can calculate http calls, success responses and error response. I need an addition to the  query to g...
by saidAb Explorer in Splunk Search 04-30-2024
0 10
0
10
anissabnk
Hello,  I'm having problems using roles.I use this search, which gives me results via the admin role. [search index="...
by anissabnk Path Finder in Splunk Search 04-30-2024
0 1
0
1
saidAb
Hello everyone,I am looking for a Splunk search query to get the duration time of three sequential response code 200....
by saidAb Explorer in Splunk Search 04-30-2024
0 9
0
9
bigll
in raw data I have portion that I would like to use in report. "changes":{"description":{"before":"<some text or empt...
by bigll Path Finder in Splunk Search 04-30-2024
0 4
0
4
chimuru84
Hello community!I want to extract data from 2 different logs like bellow:Log 1: 2024-04-28 06:38:51 INFO Start auth f...
by chimuru84 Path Finder in Splunk Search 04-30-2024
0 3
0
3
guru333
Hi,How do I extract word "Dev" from below file locationsource=/test1/folder1/scripts/monitor/log/env/dev/Error.logand...
by guru333 Engager in Splunk Search 04-30-2024
0 7
0
7
fredsnertz
This is probably an entry level question.  I have raw data that looks something like this:{"id": 99999, "type": "HOST...
by fredsnertz Observer in Splunk Search 04-29-2024
0 2
0
2
abi2023
In my index I don't see all the logs being forwarder by the Splunk UF. How can monitor when event is drop from event ...
by abi2023 Path Finder in Splunk Search 04-29-2024
0 1
0
1
MVK1
Hello I have the following sample log lines from a splunk search query   line1 line2 line3: field1 : some msg line4 l...
by MVK1 Path Finder in Splunk Search 04-29-2024
0 7
0
7
karthi2809
Hi All,I have a field called File1 and File2  and I combined in coalesce .In the table but the value is not getting i...
by karthi2809 Builder in Splunk Search 04-29-2024
0 7
0
7
dannepannesthlm
Hi,I have a background with T-SQL and reading the forums I start to realize that "join" is not so good to use with Sp...
by dannepannesthlm Explorer in Splunk Search 04-29-2024
0 8
0
8
Ismail_BSA
Hello,I recently encountered an issue with Splunk Cloud. After creating a new eval in the "Fields" menu under "calcul...
by Ismail_BSA Path Finder in Splunk Search 04-29-2024
0 2
0
2
cbiraris
Hi Team,I am trying to setup an alert if the count of errors are in range of  between 10 to19(more then 10 and less t...
by cbiraris Path Finder in Splunk Search 04-29-2024
0 2
0
2
Real_captain
Hi Can someone help me to find a way to create a Dropdown Input on the field which is extracted using a REX command.E...
by Real_captain Path Finder in Splunk Search 04-29-2024
0 3
0
3
VamshiBavu
when I run below query I am not able to get the sla_violation_count index=* execution-time=* uri="v1/validatetoken"  ...
by VamshiBavu Engager in Splunk Search 04-29-2024
0 3
0
3
ashraf_sj
Just in a situation where I have 2 servers, where 1 is active and the other is passive. I had to deploy the TA on bot...
by ashraf_sj Explorer in Splunk Search 04-29-2024
0 2
0
2
Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...