Splunk Search

Splunk Search
Community Activity
Jasmine
i am using below to load colur in drop downlist . Data loading propertly. but it always shows - Could not create sear...
by Jasmine Path Finder in Splunk Search 04-08-2024
0 3
0
3
matoulas
Data Summary is not showing host at all even I already added UDP with ip address on port 514.
by matoulas Path Finder in Splunk Search 04-08-2024
0 1
0
1
alexspunkshell
Below are the CIM Macros where i am using and there are different indexes mapped in individual macros.I want to get t...
by alexspunkshell Contributor in Splunk Search 04-08-2024
0 1
0
1
EG1
Hi,I have this search for example:index=test elb_status_code=200  | timechart count as total span=1s | stats count as...
by EG1 Engager in Splunk Search 04-08-2024
0 4
0
4
KingUs80
I'm looking to craft a query  (a correlation search) that would trigger an alert in the event that an internal system...
by KingUs80 Loves-to-Learn Lots in Splunk Search 04-07-2024
0 1
0
1
simon007
I am using the | fields _raw to show the entire content of the source file as a single event.  It works for most of m...
by simon007 Observer in Splunk Search 04-06-2024
0 1
0
1
kranthimutyala2
curl -k -u svc_aas -d search="search index=aas sourcetype=syslog" https://splunk-prod-api.internal.xxxx.com/services/...
by kranthimutyala2 Engager in Splunk Search 04-06-2024
0 2
0
2
aiguofer
I've written a search that creates a stats table with a medium sized result with around 5 cols and 100k+ rows. When I...
by aiguofer Engager in Splunk Search 04-05-2024
1 4
1
4
jiaqya
Hi, need help to get difference records between 2 lookups with same column name. ex: lookup 1 has the data below: co...
by jiaqya Builder in Splunk Search 04-05-2024
0 5
0
5
avi123
Hi All,I have time field having time range in this format in output of one splunk query:TeamWorkTimings09:00:00-18:00...
by avi123 Explorer in Splunk Search 04-05-2024
0 3
0
3
kriptonpt
Hi  Assuming a sample of data from this example:    | makeresults count=5 | eval f1=random()%2 | eval f2=random()%2 |...
by kriptonpt Engager in Splunk Search 04-05-2024
0 5
0
5
karthi2809
Hi Guys,In my scenario i need show error details for correlation id .There are field called tracePoint="EXCEPTION" an...
by karthi2809 Builder in Splunk Search 04-05-2024
0 4
0
4
bhaskar5428
My apologiesi was using "eventTimestamp" instead of  "@timestamp" in my rex command i just realized and its working n...
by bhaskar5428 Explorer in Splunk Search 04-05-2024
0 5
0
5
IAskALotOfQs
Hi all, getting to grips with SPL and would be forever grateful if someone could lend their brain for the below:   I'...
by IAskALotOfQs Path Finder in Splunk Search 04-04-2024
0 4
0
4
morinb
My environment consists of 1 search head, 1 manager, and 3 indexers. I added another search head so that I can put en...
by morinb Explorer in Splunk Search 04-04-2024
0 3
0
3
Manasa_401
Hello Splunkers,My Splunk instance is configured with default SAML authentication. Now i wanted to add users from ext...
by Manasa_401 Communicator in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
===========================================Query used index=* namespace="dk1017-j" sourcetype="kube:container:kafka-c...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 13
0
13
jaibalaraman
Hi TeamCan anyone help me with Splunk search query to split the successful login from invalid? Ex - I want to exclude...
by jaibalaraman Path Finder in Splunk Search 04-04-2024
0 6
0
6
bhaskar5428
I am planning to provide basic splunk session to my team.Can you help if any cheatsheet available online which I can ...
by bhaskar5428 Explorer in Splunk Search 04-04-2024
0 1
0
1
billchen99k
is it possible to have expression in case command for argument Y?case(x,y)|eval test=case(x=="X", 'a+b') The Y argume...
by billchen99k Engager in Splunk Search 04-03-2024
0 3
0
3
NAGA4
Hi All,I am having a requirement like this. First I need to fetch all the failed searches (lets say skipped searches)...
by NAGA4 Engager in Splunk Search 04-03-2024
0 3
0
3
djras123
I am trying to exclude this from a search. They are almost all the same just the sshd instance changes can someone he...
by djras123 Observer in Splunk Search 04-03-2024
0 2
0
2
rcrisan09
I created a field extractor for different fields for an event. Now I would like to search all the events from a sourc...
by rcrisan09 Engager in Splunk Search 04-03-2024
1 11
1
11
tom_porter
I have a search for which I need to tune out a large number of values (about 25) in a proctitle command field.  Curre...
by tom_porter Explorer in Splunk Search 04-03-2024
0 4
0
4
search_in_splun
Requesting help with search query. I have application logs in Splunk like,2024-04-02T12:26:02.244-04:00,severity=DEBU...
by search_in_splun Explorer in Splunk Search 04-03-2024
0 6
0
6
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...