Splunk Search

Splunk Search
Community Activity
dmitrynt
Hello guys, I have below query which uses join. I see lots of examples how to replace that with stats, but I am not a...
by dmitrynt Engager in Splunk Search 02-15-2024
0 12
0
12
mwcentracomm
I am using the search below | metadata type=hosts | where recentTime < now() - 10800| eval lastSeen = strftime(recent...
by mwcentracomm Explorer in Splunk Search 02-15-2024
0 3
0
3
Taruchit
Hello All,I have the below SPL to compare hourly event data and indexed data to find if they follow similar pattern a...
by Taruchit Contributor in Splunk Search 02-15-2024
0 8
0
8
Branden
Quick question: how can I view a user's search history?
by Branden Builder in Splunk Search 02-15-2024
14 24
14
24
guywood13
  index=myindex source="/var/log/nginx/access.log" | eval status_group=case(status!=200, "fail", status=200, "succe...
by guywood13 Path Finder in Splunk Search 02-15-2024
0 2
0
2
HPACHPANDE
Hello Team,Required help regarding below points :1] how to add entry of  the ran search with the fields Host, SourceI...
by HPACHPANDE Explorer in Splunk Search 02-14-2024
0 1
0
1
Ho_Wai_Yung
I am relatively new to the Splunk coding space so bare with me in regards to my inquiry.Currently I am trying to crea...
by Ho_Wai_Yung Explorer in Splunk Search 02-14-2024
0 10
0
10
LHumberto
I'm new to REX and trying to extract strings from _raw (which is actually a malformed JSON, so SPATH is not a good op...
by LHumberto Explorer in Splunk Search 02-14-2024
0 4
0
4
ilhwan
I have a distributed environment with 2 independent search heads.  I run the same search on both, and one shows a fie...
by ilhwan Path Finder in Splunk Search 02-14-2024
0 4
0
4
splunktrainingu
Hello,   I am trying to count how many days out of the last 12 months our users logged into two of our servers.  And ...
by splunktrainingu Communicator in Splunk Search 02-14-2024
0 6
0
6
smanojkumar
Hi Splunkers,   I would like to pass the label value to the macro based on some condition, when a single value is sel...
by smanojkumar Contributor in Splunk Search 02-14-2024
0 1
0
1
Abass42
I need some help updating the mmdb file for the iplocation command. Ive read the other forum questions regarding this...
by Abass42 Communicator in Splunk Search 02-13-2024
0 0
0
0
sfghjkl
Hi,I am working my way through some of the splunk courses. I am currently on "working with time".In one of the videos...
by sfghjkl New Member in Splunk Search 02-13-2024
0 1
0
1
NishantKrishna
I am using the below query to merge 2 queries using append. However, I am unable to get the value of the field named ...
by NishantKrishna Loves-to-Learn in Splunk Search 02-13-2024
0 7
0
7
thaghost99
hi i would like some help on how to extract the next 5 lines after a keyword where it extracts the full line where th...
by thaghost99 Path Finder in Splunk Search 02-13-2024
0 5
0
5
Arani_Hari
How to extract alphanumeric and numeric values from aline,  both are dynamic values<Alphanumeric>_ETC_RFG: play this ...
by Arani_Hari Loves-to-Learn Lots in Splunk Search 02-13-2024
0 7
0
7
martinmasif
I have a "cost" for two different indexes that I want to calculate in one and the same SPL. As the "price" is differe...
by martinmasif Explorer in Splunk Search 02-13-2024
0 2
0
2
Strangertinz
Hi, I created a column chart in Splunk that shows month but will like to also indicate the day of the week for each o...
by Strangertinz Path Finder in Splunk Search 02-13-2024
0 6
0
6
adamsobczykhsbc
I have raw data like:  Error=REQUEST ERROR | request is not valid.|","time":"1707622073040"  and I want to extract "R...
by adamsobczykhsbc Explorer in Splunk Search 02-13-2024
0 5
0
5
iainp
I have a number of devices that send logs to Splunk.I want to know when devices stop logging.For this example search:...
by iainp New Member in Splunk Search 02-13-2024
0 2
0
2
mwcentracomm
I created an alert from the search below, and it emails a pdf - is there a way to add the most recent event from each...
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 5
0
5
EPitch
Hi Everyone,  I am looking for a little advice, I am currently searching splunk against multiple sets of variables to...
by EPitch Observer in Splunk Search 02-12-2024
0 4
0
4
0p3r4t0r8089
I have a report that lists malware received by email that is part of a dashboard. Some months the list for each perso...
by 0p3r4t0r8089 Explorer in Splunk Search 02-12-2024
0 7
0
7
marshalll3302
Splunk sirs, I am trying to add a boolean column to my data called 'new_IP_detected' which will tell me whether an an...
by marshalll3302 Explorer in Splunk Search 02-12-2024
0 4
0
4
mwcentracomm
HelloI would like a search to show the last entry of host="1.1.1.1", and show the full entry. Thank you
by mwcentracomm Explorer in Splunk Search 02-12-2024
0 1
0
1
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...