Splunk Search

Splunk Search
Community Activity
Manasa_401
Hello Splunkers,My Splunk instance is configured with default SAML authentication. Now i wanted to add users from ext...
by Manasa_401 Communicator in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
===========================================Query used index=* namespace="dk1017-j" sourcetype="kube:container:kafka-c...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 13
0
13
jaibalaraman
Hi TeamCan anyone help me with Splunk search query to split the successful login from invalid? Ex - I want to exclude...
by jaibalaraman Path Finder in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
I am planning to provide basic splunk session to my team.Can you help if any cheatsheet available online which I can ...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 1
0
1
billchen99k
is it possible to have expression in case command for argument Y?case(x,y)|eval test=case(x=="X", 'a+b') The Y argume...
by billchen99k Engager in Splunk Search 04-03-2024
0 3
0
3
NAGA4
Hi All,I am having a requirement like this. First I need to fetch all the failed searches (lets say skipped searches)...
by NAGA4 Engager in Splunk Search 04-03-2024
0 3
0
3
djras123
I am trying to exclude this from a search. They are almost all the same just the sshd instance changes can someone he...
by djras123 Observer in Splunk Search 04-03-2024
0 2
0
2
rcrisan09
I created a field extractor for different fields for an event. Now I would like to search all the events from a sourc...
by rcrisan09 Engager in Splunk Search 04-03-2024
1 11
1
11
tom_porter
I have a search for which I need to tune out a large number of values (about 25) in a proctitle command field.  Curre...
by tom_porter Explorer in Splunk Search 04-03-2024
0 4
0
4
search_in_splun
Requesting help with search query. I have application logs in Splunk like,2024-04-02T12:26:02.244-04:00,severity=DEBU...
by search_in_splun Explorer in Splunk Search 04-03-2024
0 6
0
6
AnmolKohli
Please help share the exact cron schedule that can be used here. Existing posts are not helping Thanks
by AnmolKohli Explorer in Splunk Search 04-03-2024
0 4
0
4
rikinet
I have three tables. Each has one or more ID fields (out of ID_A, ID_B, ID_C) and assigns values Xn, Yn, Zn to these ...
by rikinet Path Finder in Splunk Search 04-03-2024
0 3
0
3
mahesh27
 |msats sum(count-error) as Failed where index=metrics_index by service errorNumber errortype Results:serviceerrorNum...
by mahesh27 Communicator in Splunk Search 04-03-2024
0 2
0
2
SplunkDash
Hello,How do I compare 2 source types within the same index and find the Gap. For Example: index=compare sourcetype=a...
by SplunkDash Motivator in Splunk Search 04-03-2024
0 4
0
4
raoul
I have a dataset of user data including the user's LastLogin. The LastLogin field is slightly oddly formatted but ver...
by raoul Path Finder in Splunk Search 04-03-2024
0 2
0
2
PawelSplunk
Hello EveryoneI'm trying to calculate the "time_difference" between one column and another in Splunk. The problem is ...
by PawelSplunk Engager in Splunk Search 04-02-2024
0 2
0
2
Ramtejachode
open the "Search & Reporting" application, and find through SPL searches against all data the password utilized durin...
by Ramtejachode Observer in Splunk Search 04-02-2024
0 1
0
1
jaibalaraman
Hi Can anyone help me with below query I have created a pie chart based on the error message, however i am not sure h...
by jaibalaraman Path Finder in Splunk Search 04-02-2024
0 3
0
3
mahesh27
I want to compare pervious hour data with present hour data and get the percentage using below query.|mstats sum(tran...
by mahesh27 Communicator in Splunk Search 04-02-2024
0 5
0
5
Shan
Hi All, Need your support in resolving an issue in a pie chart. I can see the below-mentioned results in statistics a...
by Shan Builder in Splunk Search 04-02-2024
0 11
0
11
abroun
Hey, I have a problem preparing a Splunjk query. Could you assist me?I have a simple query that returns a table with ...
by abroun Engager in Splunk Search 04-02-2024
0 3
0
3
karthi2809
Hi Guys,I am using timeline visualization in my Splunk dashboard to show total elapsed time. But in some times its no...
by karthi2809 Builder in Splunk Search 04-02-2024
0 1
0
1
rajatsinghbagga
Hello Everyone, I am trying to get the top 3 max values of a field "elapseJobTime" for all the instances associated ...
by rajatsinghbagga Explorer in Splunk Search 04-02-2024
0 12
0
12
kc_prane
Hello, I am looking for my search results for only 6pm to 9pm over the last 90 days. How can I achieve this with the ...
by kc_prane Communicator in Splunk Search 04-02-2024
0 1
0
1
UdayBhaskar
Below I provided a sample trace where we have message with below format Error_Request_Response for URI: {}, and Excep...
by UdayBhaskar Engager in Splunk Search 04-02-2024
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...