Splunk Search

Splunk Search
Community Activity
splunkuser320
I am trying to use parameter into the search using IN condition.  Query is retuning results if I put data directly in...
by splunkuser320 Path Finder in Splunk Search 03-13-2024
0 8
0
8
Deprasad
I've below 3 different types of API logs where I've to treat all 3 as same and get the count of the API.There are mul...
by Deprasad Path Finder in Splunk Search 03-13-2024
0 5
0
5
ipoluda
Hello!I have a log that shows locking/unlocking PCs:1710320306,u09,unlocked1710320356,u09,locked1710320360,u10,unlock...
by ipoluda Explorer in Splunk Search 03-13-2024
0 1
0
1
Splunk-Star
We have a Splunk Dashboard for our Team in Splunk  Cluster. Almost every report item is having exclamation symbol and...
by Splunk-Star Loves-to-Learn Lots in Splunk Search 03-13-2024
0 2
0
2
Tron-spectron47
if i had to write a document for myself on basic learning of splunk: to create a dashboard i can either use inputs li...
by Tron-spectron47 Loves-to-Learn in Splunk Search 03-13-2024
0 3
0
3
Splunk-Star
On splunk user is getting the following error:Could not load lookup=LOOKUP-pp_vms  but admin is not getting any such ...
by Splunk-Star Loves-to-Learn Lots in Splunk Search 03-13-2024
0 2
0
2
PaulaCom
Good Morning  i have a field that i've called problem_detail in our Helpdesk index. it contains all the types of prob...
by PaulaCom Path Finder in Splunk Search 03-13-2024
0 2
0
2
karthi2809
How to extract the two fields from the message ?In this need to extract after API: START: /v1/expense/extract/demand/...
by karthi2809 Builder in Splunk Search 03-13-2024
0 3
0
3
parthiban
Hi team,I mentioned that the payload field contains the entity-internal-id and lead-id in an array format. I want to ...
by parthiban Path Finder in Splunk Search 03-13-2024
0 5
0
5
Splunk-Star
Please let me know the correct data extraction? index=* "Unknown message for StatusConsumer" topicId marshall | rex f...
by Splunk-Star Loves-to-Learn Lots in Splunk Search 03-12-2024
0 3
0
3
1tiger105
I have all the relevant data I need from a single source but I am wanting to present it in a way that I can't get it ...
by 1tiger105 Engager in Splunk Search 03-12-2024
0 2
0
2
RSS_STT
I want to call lookup within case statement. if possible, please share sample query.
by RSS_STT Explorer in Splunk Search 03-12-2024
0 6
0
6
jason_hotchkiss
I have a weird date/time value:  20240307105530.358753-360I would like to make it more user friendly  2024/03/07 10:5...
by jason_hotchkiss Communicator in Splunk Search 03-12-2024
0 3
0
3
teknet7
Hello Team, I could see a lot of discussions on this forum, but none solving my issue. I have a log with content li...
by teknet7 Engager in Splunk Search 03-12-2024
1 3
1
3
ChocolateRocket
Any reason why this can't be visualized in a geo cluster map?source="udp:514" index="syslog" NOT src_ip IN (10.0.0.0/...
by ChocolateRocket Explorer in Splunk Search 03-12-2024
0 7
0
7
samkaj
I am using REST service - my requirement is to use Splunk REST URL to fetch details from a saved search .. but I want...
by samkaj Explorer in Splunk Search 03-12-2024
1 4
1
4
karthi2809
Hi Guys, Thanks in Advance. So i have case conditions to be match in my splunk query.below the message based on corre...
by karthi2809 Builder in Splunk Search 03-12-2024
0 5
0
5
Satyapv
Hello All, I have an Index = Application123 and it contains an Unique ID known as TraceNumber. For each Trace number ...
by Satyapv Engager in Splunk Search 03-12-2024
0 3
0
3
mappu
Hello,I'm trying to find average response time of all events after the field totalTimeTaken. Thing is, when I tested ...
by mappu Engager in Splunk Search 03-12-2024
0 3
0
3
losttranslation
Hi All,I am attempting to use lookup table "is_windows_system_file"  for the following SPL where the Processes.proces...
by losttranslation New Member in Splunk Search 03-11-2024
0 1
0
1
Allampally
Hi Team,I want to calculate peak hourly volume of each month for each service. Each service can have different peak t...
by Allampally Path Finder in Splunk Search 03-11-2024
0 7
0
7
Harish2
|tstats count where index=app-idx host="*abfd*" sourcetype=app-source-logs by hostThis is my alert query, i want to m...
by Harish2 Path Finder in Splunk Search 03-11-2024
0 18
0
18
karthi2809
Thanks in Advance.1.I have a json object as content.payload{} and need to extract the values inside the payload.Alrea...
by karthi2809 Builder in Splunk Search 03-10-2024
0 3
0
3
zach-keener
How would I add a permanent search or field to a sourctype? For example: I have a set of a data that I have been able...
by zach-keener Explorer in Splunk Search 03-10-2024
0 2
0
2
Yhwhison3
Hello, I'm currently doing some training as part of a SOC analyst intern position. One of the questions in the little...
by Yhwhison3 Loves-to-Learn Lots in Splunk Search 03-09-2024
0 2
0
2
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors