Splunk Search

Splunk Search
Community Activity
russell120
Hi, Can I run a search with two or more indexes and specify a different time range in each one? For example, would ...
by russell120 Communicator in Splunk Search 03-08-2019
1 11
1
11
magun
Scenario: In a way, the local admin user can be retrieved, the computer to remove the domain, and without the domain ...
by magun New Member in Splunk Search 03-08-2019
0 7
0
7
uppukumar
Hi all, I am new to splunk Following is the information: Column1 Column2 column3 f...
by uppukumar Explorer in Splunk Search 03-08-2019
0 2
0
2
emipintus
Hi, I have a search which returns a list of records, some of them have a duplicate Value. Here's an example of the ou...
by emipintus Explorer in Splunk Search 03-08-2019
0 7
0
7
chirsf
I've seen a lot about not using join subsearches, how it's slow, etc etc. Which proves to be true in practice. What ...
by chirsf Explorer in Splunk Search 03-08-2019
0 2
0
2
evinasco
Hi team i have been working a new project with banking sector where they are using the Core Banking T24. Does anyon...
by evinasco Communicator in Splunk Search 03-08-2019
1 3
1
3
mdmaala
hi! I want to create a stacked bar chart like in a timline series like this |[----RUN TIME----]|[----IDLE TIME----]|...
by mdmaala Communicator in Splunk Search 03-07-2019
0 2
0
2
jasonlow
Hi. I need to schedule a recurring search that would alert/email me if an index, say "web", is missing data feeds ...
by jasonlow Loves-to-Learn in Splunk Search 03-07-2019
0 3
0
3
balcv
I'm wanting to find out if it's possible to take a list of items in a text file, conduct a search against that list a...
by balcv Contributor in Splunk Search 03-07-2019
0 6
0
6
michael_ermino_
I have events that have a value called "Date First Found" that is of the format: "%m/%d/%Y". I calculate the number o...
by michael_ermino_ New Member in Splunk Search 03-07-2019
0 2
0
2
su_kumar
Hello, I am having an issue with some regex that I wrote. it is working fine except for this blank space. Regex : ...
by su_kumar New Member in Splunk Search 03-07-2019
0 7
0
7
robertlynch2020
Hi I have a real time search over the past 5 minutes, however it works for 30 seconds an then it dies. any ideas? I...
by robertlynch2020 Influencer in Splunk Search 03-07-2019
1 6
1
6
ADRIANODL
Hi folks, I have 2 indexes containing information as below: index ABC _time sessionkey ...
by ADRIANODL Explorer in Splunk Search 03-07-2019
0 4
0
4
davidmills
We have: - Index Cluster Master - Search head cluster (3 nodes) - Index Cluster (3 nodes) - Heavy forwarder (1 node) ...
by davidmills Explorer in Splunk Search 03-07-2019
0 2
0
2
rbal_splunk
unable to search data using SPL index=test ssp=3538 following search does return the result index=test ssp=*3538 ...
by rbal_splunk Splunk Employee Splunk Employee in Splunk Search 03-07-2019
0 1
0
1
ryhluc01
What is wrong with this? | eval Count=case((sourcetype="input1" OR sourcetype="input2") AND index="foo1", "NA" (sou...
by ryhluc01 Communicator in Splunk Search 03-07-2019
0 15
0
15
rsantoso_splunk
Since upgraded to Splunk version 7.2.3, some fields extractions aren’t showing on the searches properly. In particula...
by rsantoso_splunk Splunk Employee Splunk Employee in Splunk Search 03-07-2019
0 2
0
2
russell120
Hi, Just as the question says. My current search results in something similar to this: ip device ----------...
by russell120 Communicator in Splunk Search 03-07-2019
0 3
0
3
splbsm
Hi, I have a summery index with events like this :- 3/06/2019 00:00:00 +0000, search_name=ABCD , search_now=15519168...
by splbsm Explorer in Splunk Search 03-07-2019
1 3
1
3
someone4321
I'm using Splunks REST API to post a search job and then get the results. Ideally I would like to use a where conditi...
by someone4321 Explorer in Splunk Search 03-07-2019
0 6
0
6
VijaySrrie
I have a lookup file with indexes in it, I want a query i need the eventcount of the indexes mentioned in the lookup ...
by VijaySrrie Builder in Splunk Search 03-07-2019
0 2
0
2
inovexsean
I'm trying to write an ANTLR grammar for Splunk queries and an example of the queries that my system receives is as f...
by inovexsean Explorer in Splunk Search 03-07-2019
0 4
0
4
htomi
Hi all, I would like to create a dashboard displaying average transaction time / day / test type. Tests are running...
by htomi New Member in Splunk Search 03-07-2019
0 3
0
3
DBattisto
Before I begin work on what is likely to be a multi-day excursion, I wanted to see if this has already been done. I ...
by DBattisto Communicator in Splunk Search 03-07-2019
0 6
0
6
andrewtrobec
Good morning, I've noticed a strange phenomenon with Splunk Enterprise 7.1.4 base searches and I wanted to see wheth...
by andrewtrobec Motivator in Splunk Search 03-07-2019
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...