Splunk Search

Splunk Search
Community Activity
ztayluh
Hello, I am trying to perform calculations on multiple fields. I am working with data in the format of Key='value1,...
by ztayluh New Member in Splunk Search 03-26-2019
0 5
0
5
jsoderling
I have a dashboard panel with a radio input. If the user choose Selection A (4624), I need to add a field to the sea...
by jsoderling New Member in Splunk Search 03-26-2019
0 7
0
7
sarit_s
Hello, i have these 3 stanzas in my transforms.conf file: [set_f270_header] REGEX = (^\$\w+\s\d+|^\-\-\-\-\- heade...
by sarit_s Communicator in Splunk Search 03-26-2019
0 3
0
3
Nadhiyaa
hi , Below is my single event indexing into splunk.I want to break the events into single events .It should break an...
by Nadhiyaa Path Finder in Splunk Search 03-26-2019
0 11
0
11
pavanae
I have a query which displays some tabular results and when a certain condition is matched for 2 field values I want ...
by pavanae Builder in Splunk Search 03-26-2019
0 2
0
2
JyotiP
Wanted to retrieve the transaction id from the given string Level="ERROR", Date="2019-03-25 23:02:59,600", Message=...
by JyotiP Path Finder in Splunk Search 03-26-2019
0 1
0
1
mcohen13
I have 2 different fields that both contain threat names. I want to show which of the threat name are in field1 and n...
by mcohen13 Loves-to-Learn in Splunk Search 03-26-2019
0 15
0
15
kuki_junior
How to search all users who access a particular domain/ip I have a list of source ips and i wish to find users who a...
by kuki_junior New Member in Splunk Search 03-26-2019
0 1
0
1
maulikdesai21
I have been running into a problem where I need to fetch the value from JSON data in the log. I am aware of spath bu...
by maulikdesai21 Engager in Splunk Search 03-25-2019
0 3
0
3
raj_mpl
Hi All , Good Day My log will generate 2 types of log events 1)tid and mid in single log event 2)multiple field va...
by raj_mpl Path Finder in Splunk Search 03-25-2019
0 4
0
4
sahil237888
Hi, I need help in creating one query. There is one field "Operator" having multiple values like airphone,bphone,vsph...
by sahil237888 Path Finder in Splunk Search 03-25-2019
0 4
0
4
jpreis
Is there a way to search a cidr notation without using "src_ip OR dest_ip"? I have a bunch of ips i want to search f...
by jpreis New Member in Splunk Search 03-25-2019
0 1
0
1
dbashyam
Hi, I am trying to get a table type of alerting but I am not getting the output index = ops host = Sr*xxxx* sourcet...
by dbashyam Explorer in Splunk Search 03-25-2019
0 2
0
2
awmorris
I am super stoked about the potential of Schema Accelerated Event Searches- might be one of the best improvements i'v...
by awmorris Path Finder in Splunk Search 03-25-2019
1 8
1
8
swangertyler
In my data, events can have children. There is data in those events that I would want to associate with the parent ev...
by swangertyler Path Finder in Splunk Search 03-25-2019
0 4
0
4
ramesh12345
Hi, index=os sourcetype=Service status=* (Group="Data" OR Group="Secur") AND (Section="Local" OR Section="data heal...
by ramesh12345 Explorer in Splunk Search 03-25-2019
0 1
0
1
jwiley_splunk
Currently having a hard time figuring out how to create a column chart where the field values show up in the side, so...
by jwiley_splunk Splunk Employee Splunk Employee in Splunk Search 03-25-2019
0 4
0
4
saulverde
I am having trouble with field extraction. I have a regex which works in a pcre regex tester but when I attempt to us...
by saulverde Path Finder in Splunk Search 03-25-2019
0 2
0
2
javanue
I am trying to compare multivalue fields, but I cannot figure out how to do it correctly? Here is the original query...
by javanue New Member in Splunk Search 03-25-2019
0 1
0
1
seva98
Hi, does anyone know how can I change fieldColors after chart was rendered? Thing is that we have two different visu...
by seva98 Path Finder in Splunk Search 03-25-2019
0 2
0
2
jimmymccauley
Hi All This is my second SOS this week as I get acquainted with Splunk. I've exhausted all possibilities trying to s...
by jimmymccauley Explorer in Splunk Search 03-25-2019
0 4
0
4
gimbil
Hi, I am trying to do a search which basically generates measures based on the value of a field such as X: search ...
by gimbil Explorer in Splunk Search 03-25-2019
0 4
0
4
veerendra_modi
I have a field FQ with the value as "ServerName.domain.com" I want to get only the server name in another field. Pl...
by veerendra_modi Loves-to-Learn in Splunk Search 03-25-2019
0 2
0
2
jip31
hello I use the search below in order to do a total count by OS and by build It mean that it counts only events whic...
by jip31 Motivator in Splunk Search 03-25-2019
0 2
0
2
henrysoon80
Recently i create a transaction search, command and result a per below Search command: search | transaction Session...
by henrysoon80 New Member in Splunk Search 03-25-2019
0 5
0
5
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...