Splunk Search

Splunk Search
Community Activity
maryamchar
I want to create a table with all fields from two different indexes. Index=A |rename fieldA as field1 |table field1...
by maryamchar Explorer in Splunk Search 05-08-2019
0 9
0
9
Prakash493
Hi Currently we have Splunk db connect installed on heavy forwarder and we have inputs configured on heavy forwarder ...
by Prakash493 Communicator in Splunk Search 05-08-2019
0 2
0
2
anholzer
I am attempting to create a search that returns data for a different time-range based on the current day of the week....
by anholzer Explorer in Splunk Search 05-08-2019
0 2
0
2
triest
Does anyone know a way to control the field order for the format command? For the default use case of format it AND'...
by triest Communicator in Splunk Search 05-08-2019
0 5
0
5
arpitpropay
I have several log files as source of Splunk events. C:\logs\Srv1\file1_2019-05-06.log C:\logs\Srv84\file3_2019-05-...
by arpitpropay Explorer in Splunk Search 05-08-2019
0 4
0
4
huibertsp
I like to run PowerShell scripts under "Powershell v3 Modular Input" and created a script. I noticed via our HIPS blo...
by huibertsp Engager in Splunk Search 05-08-2019
0 0
0
0
mikaellindstrom
Hi, I'm having a problem with setting up my data stream for scripted input. I have the splunk universal forwarder set...
by mikaellindstrom New Member in Splunk Search 05-08-2019
0 0
0
0
ryhluc01
Good Morning, I need to do a stat avg on the time difference between results. Problem is all of my fields are both ...
by ryhluc01 Communicator in Splunk Search 05-08-2019
0 4
0
4
Shashank_87
Hi, I am looking for some help related to one of the issues. So what i want is weekly view of users in last 90 days w...
by Shashank_87 Explorer in Splunk Search 05-08-2019
0 1
0
1
su_kumar
Hi, I am using the stats command with the list() function. , i am getting below error. Error : 'stats' command: lim...
by su_kumar New Member in Splunk Search 05-08-2019
0 12
0
12
jwalzerpitt
I have some ADFS logs that I'm trying to pull the IPs from. My regex is as follows: (?:(^Token\sType):\s*(?:\n(?!Cli...
by jwalzerpitt Influencer in Splunk Search 05-08-2019
0 5
0
5
ryanisibor
I receive a weekly report on terminated users and I’m trying to create a search that will identify events/domain acti...
by ryanisibor Engager in Splunk Search 05-08-2019
0 2
0
2
Shashank_87
Hi, I have one OS index in Splunk where i get the raw data in a tabular format like below. Now I need to extract thes...
by Shashank_87 Explorer in Splunk Search 05-08-2019
0 7
0
7
sjansma
I have made two indexes and set the values into a table. How can i find a value from table1 in table2 and present de ...
by sjansma Explorer in Splunk Search 05-08-2019
0 7
0
7
marxsabandana
I'm about to unite product codes from 2 different sourcetypes with different names, but with the same value. Here's ...
by marxsabandana Path Finder in Splunk Search 05-08-2019
1 1
1
1
virex
I have a main search and a lookup table I want to assign field called isCorrect to values from the main search that m...
by virex Engager in Splunk Search 05-07-2019
0 2
0
2
nick405060
Hey guys, I am ingesting VPN logs and would like to parse them out. Does anyone have regexes to use?
by nick405060 Motivator in Splunk Search 05-07-2019
0 1
0
1
bramkostermans
Dear fellow Splunkers, I'm running a saved search containing multiple sub searches and writing the results to a sum...
by bramkostermans Engager in Splunk Search 05-07-2019
1 0
1
0
jofish
Let's say I've got a timechart of URLs I'm serving. Over an hour, let's say I served this: server.com/MYcats.html -...
by jofish Engager in Splunk Search 05-07-2019
1 2
1
2
zacksoft
host = Mayhem sourcetype="phutans:servo" host=R00878 | eval headers=split(_raw," ") | eval plant_length=mvindex(heade...
by zacksoft Contributor in Splunk Search 05-07-2019
0 9
0
9
samn123
I have a lookup table with fields Application name and host, and i have a realtime Incident data with index, sourcety...
by samn123 New Member in Splunk Search 05-07-2019
0 3
0
3
johnraftery
Hello, I have a token called range (assume it has a value of "123-456"), and I am trying to use it inside a token eva...
by johnraftery Communicator in Splunk Search 05-07-2019
1 6
1
6
ghostdog920
I have looked at a ton of posts about breaking a multivalued field but having zero luck effecting a solution. I have...
by ghostdog920 Path Finder in Splunk Search 05-07-2019
0 23
0
23
singh3and12
Hi, I am trying to create a dashboard that shows % CPU Processor time avg (Value)..but the query i used to only givin...
by singh3and12 Path Finder in Splunk Search 05-07-2019
0 4
0
4
sarit_s
Hello i have source path that looks like : s3://splunk/OTHER/1/OTHER/Star J750/pjserialnumber/2019-05-06T13:40:37....
by sarit_s Communicator in Splunk Search 05-07-2019
0 5
0
5
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...
Top Solution Authors