Splunk Search

Splunk Search
Community Activity
ktrumpol
Hello everyone, Our company just started using Splunk, and after experimenting with some basic commands it certainly...
by ktrumpol Path Finder in Splunk Search 07-22-2018
1 4
1
4
jdlocklin526
I'm having a difficult time calculating a percentage based on two reports (searches). Search 1 | inputlookup mydata...
by jdlocklin526 Observer in Splunk Search 07-22-2018
0 3
0
3
bollam
I'm fetching data by hitting an API, and the data I get will be a single event which consists of cpu_used and corresp...
by bollam Path Finder in Splunk Search 07-21-2018
0 2
0
2
iberecamara
I have to calculate the response time from an application that depends on the response of another application. For th...
by iberecamara Engager in Splunk Search 07-20-2018
0 15
0
15
richnavis
Hey all, this one has be stumped. I'm trying to join two searches where the first search includes a single field w...
by richnavis Contributor in Splunk Search 07-20-2018
0 7
0
7
tmeader
I'm trying to get a result table of all he hosts in our OSSEC environment that have changed status over the past 24 h...
by tmeader Contributor in Splunk Search 07-20-2018
2 6
2
6
angelinealex
I use the below saved search and scheduled it and enabled the summary index. | dbxquery connection=connectionname qu...
by angelinealex Communicator in Splunk Search 07-20-2018
0 5
0
5
nehaprasad14
Unable to get billing details in Splunk App for AWS. I have configured the billing input in Splunk Add-on apps.
by nehaprasad14 New Member in Splunk Search 07-20-2018
0 6
0
6
dwong2
I have the raw data below. How do I get the strings after the "action": and put all the results into a new field? ...
by dwong2 New Member in Splunk Search 07-20-2018
0 10
0
10
krusty
Hi, we use in our environment (indexer cluster, searchhaed/deployment server) Splunk enterprise version 7.1.1. If w...
by krusty Contributor in Splunk Search 07-20-2018
0 3
0
3
Danielle2018V
Hello index="cs_test" "Splunktest" "Refund succeeded" OR *"action"=>"refund"* I have a below raw text log, I want ...
by Danielle2018V New Member in Splunk Search 07-20-2018
0 2
0
2
weicheng98
hi want to compare the email header and count by dest_port =25. (Im trying to detect a phishing email via email title...
by weicheng98 Path Finder in Splunk Search 07-20-2018
0 13
0
13
mstrigl
,Is it possible to collect inventory, performance information, and status events from DellEMC VPLEX?
by mstrigl New Member in Splunk Search 07-20-2018
0 0
0
0
neilhiley
Hi. I have a bar chart that shows an SLA line and response times for today and the previous day. What I want is whe...
by neilhiley Explorer in Splunk Search 07-20-2018
1 2
1
2
dave0970
Hello, please help create a search add another condition to fire this alert if there are no results Here is the splu...
by dave0970 Engager in Splunk Search 07-20-2018
0 2
0
2
kuljeetss
Hi All, I am wondering if someone has implemented multi value fields at index time similar to the following The fol...
by kuljeetss Explorer in Splunk Search 07-20-2018
0 2
0
2
payal23
I have a data model with root events, but now as per the latest requirement added root search as well in the same dat...
by payal23 Path Finder in Splunk Search 07-20-2018
0 0
0
0
ajayathmakuri
Hello All, When I ran a query to check disk usgae in GB & % ,I could see for hot bucket looks same for both GB & % b...
by ajayathmakuri Engager in Splunk Search 07-20-2018
0 1
0
1
jacqu3sy
Hi, I need a regex to extract the value 'Fred' in quotes after the User declaration below; ,"User:"Fred", So any v...
by jacqu3sy Path Finder in Splunk Search 07-20-2018
0 4
0
4
apietersen
Hi, I like to setup a kind of help-text library based on unique msgcode-xx.csv text files. (or internal/external tml...
by apietersen Contributor in Splunk Search 07-20-2018
0 3
0
3
aqudoos
Hi all! I am currently getting stats of current day as followed Port Count 25 25 443 75...
by aqudoos Explorer in Splunk Search 07-20-2018
0 1
0
1
lyanwoah2
Hi, in the doc I can see we can use the list function with the pivot commands, but when I tried I got this error mes...
by lyanwoah2 Engager in Splunk Search 07-20-2018
0 0
0
0
jip31
Hi i have a value like this in a field 2018067155420 and i want to format it with this format : yyyymmddhhmmss so co...
by jip31 Motivator in Splunk Search 07-20-2018
0 8
0
8
syh
Hi, what I am trying to do is to create a search query based on two sources. Source 1 will be the logs I want to inv...
by syh Engager in Splunk Search 07-19-2018
0 3
0
3
adityapavan18
I have a extracted field call CallDuration and in logs it in format %H:%M:%S.%2N like 00:00:38.60 That means the ca...
by adityapavan18 Contributor in Splunk Search 07-19-2018
3 8
3
8
Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...