Splunk Search

Splunk Search
Community Activity
hoytn
Can I define a custom key field in a kvstore? I've created the kvstore with following configuration: _key, targetUse...
by hoytn Explorer in Splunk Search 03-15-2019
1 1
1
1
alc2019
Hi, I'm doing a device count based on device latest time event registration. I'm getting the correct device registr...
by alc2019 New Member in Splunk Search 03-14-2019
0 4
0
4
paullt12345
Hi all I want to extract Hostname, date and time from the log, Kindly help sample log: Mar 12 09:13:46 hostname1 <...
by paullt12345 Explorer in Splunk Search 03-14-2019
0 2
0
2
mmdacutanan
I have got 3 queries that I need to join together. First query has a subsearch. I used a subsearch because I need to...
by mmdacutanan Explorer in Splunk Search 03-14-2019
0 3
0
3
ejmin
I know this is a silly question but for some cases I need to know where the unmatched events go because my regex is t...
by ejmin Path Finder in Splunk Search 03-14-2019
0 20
0
20
anthonycopus
Hi, I need help deduplicating in a search where only half the data contains an id. Basically, the old data has a fie...
by anthonycopus Path Finder in Splunk Search 03-14-2019
2 4
2
4
jeck11
This is the regex I've come up with so far. Unfortunately, it's either matching too much or not enough. I want it to ...
by jeck11 Path Finder in Splunk Search 03-14-2019
0 4
0
4
krisalexroberts
Hello, I have two sources: 1: Device, SiteName, Long, Lat 2: Device, Clients (Number of current clients) I wish to...
by krisalexroberts New Member in Splunk Search 03-14-2019
0 1
0
1
aking76
I created a map showing connections outside the US but when I hover over the markers it only shows the lon and lat. I...
by aking76 Path Finder in Splunk Search 03-14-2019
0 0
0
0
sagar1992
Hi Team, I am facing issue after using group by clause. (Need date of the grouped event in DD-MM-YYYY ) The search ...
by sagar1992 Explorer in Splunk Search 03-14-2019
0 3
0
3
ndaniel88
Hello, I have 1 single table that comes from two different searches/indexes/sourcetypes using append. I need to join...
by ndaniel88 Explorer in Splunk Search 03-14-2019
0 6
0
6
alai
Hi all, we do have a table showing (besides other information) HTTP status codes. I'm trying to implement a tooltip ...
by alai Explorer in Splunk Search 03-14-2019
0 7
0
7
oliverj
One of my ongoing gripes with splunk is that there is no way to see the IP and the hostname -- either my forwarder se...
by oliverj Communicator in Splunk Search 03-14-2019
0 4
0
4
JarrettM
This search works well and gives me the results I want as shown below: index="index1" sourcetype="source_type1" resp...
by JarrettM Path Finder in Splunk Search 03-14-2019
0 2
0
2
jip31
Hello I dont understand why: index="x" sourcetype="wmi:BatteryFull" OR sourcetype="wmi:BatteryStatic" | dedu...
by jip31 Motivator in Splunk Search 03-14-2019
0 11
0
11
mailmetoramu
Hello All, I have an ongoing issue with my Splunk environment. Actually an user "Alex" have added remote desktop use...
by mailmetoramu Explorer in Splunk Search 03-14-2019
0 8
0
8
Reddi694325
In my environment I got one scenario like have to find common errors in iis log, applog,apache log and db log. How to...
by Reddi694325 Path Finder in Splunk Search 03-14-2019
0 3
0
3
sjimenezp
Hi, This is the search that we are using for the dashboard and it brings all events with value "-". index=wineventl...
by sjimenezp New Member in Splunk Search 03-14-2019
0 2
0
2
damucka
Hello, I have the following string pattern (source): /trace/DB_BWP/xsengine_ls5925.30246.crashdump.20190312-213001....
by damucka Builder in Splunk Search 03-14-2019
0 2
0
2
kiranpatil1985
Hello, I have a KV file that is auto generated with username using a script running every hour. I want to match the u...
by kiranpatil1985 New Member in Splunk Search 03-13-2019
0 2
0
2
yutaka1005
When I want to update lookup using search like below, it updates lookup table even if there is no results, but I want...
by yutaka1005 Builder in Splunk Search 03-13-2019
0 4
0
4
gokool2u
How to resize the width of single value dashboard panels in case if I have only one column in a row, instead of makin...
by gokool2u Explorer in Splunk Search 03-13-2019
0 7
0
7
jvmerilla
Hello All, I was wondering if there's a way to manage lookup files in Splunk. What I want to do is to create/upload...
by jvmerilla Path Finder in Splunk Search 03-13-2019
0 1
0
1
JWBailey
I have an "interesting event," how can I find an event meeting specific criteria that happened before my interesting ...
by JWBailey Communicator in Splunk Search 03-13-2019
0 2
0
2
feldunost
Hello Splunk Folks ! Currently I am experiencing Splunk as student, and I'm having a hard time with some mail logs, ...
by feldunost Engager in Splunk Search 03-13-2019
0 13
0
13
Get Updates on the Splunk Community!

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology ...

At .conf26, Don’t Just See What’s Next. Help Shape It at Innovation Labs.

Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At ...

Data Management Digest – August 2026

Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month ...