About 1,350,000 results
Open links in new tab
  1. Can I use the "IN" command like this? - Splunk Community

    Jul 10, 2019 · index=myIndex FieldA="A" AND LogonType IN (4,5,8,9,10,11,12) The documentation says it is used with "eval" or "where" and returns only the value "true". But it …

  2. Search Basics in Splunk!

    View our Tech Talk: Platform Edition, Search Basics in Splunk Search Basics is one of the most important learning topics for new users getting started with Splunk. Splunk’s powerful search …

  3. Solved: Add Line Breaks with Eval - Splunk Community

    Feb 3, 2012 · Rather than bending Splunk to my will, but I found that I could get what I was looking for by altering the search to split by permutations (one event returned per permutation) …

  4. Splunk Search

    Find Answers Using Splunk Splunk SearchOptions

  5. What are the basics for using the Splunk search interface?

    Oct 21, 2019 · Review Get started with Search and familiarize yourself with Splunk Web. For extra credit, Splunk Cloud users can complete the Splunk Cloud Search Tutorial, and Splunk …

  6. Solved: What is the best way to search for blank (null) fi... - Splunk ...

    Feb 22, 2016 · Is there a best way to search for blank fields in a search? isnull() or ="" doesn't seem to work. Is there way to do this? The only thing we have been able to do is do a f-llnull …

  7. Solved: Add a comment to a search? - Splunk Community

    May 24, 2012 · I'm working on a really large search right now (on the order of 35 lines long). Is there a good way to insert a comment into a search query to remind a future search editor …

  8. How to Use variables in 'search' command? - Splunk Community

    Aug 23, 2023 · Note: I am absolutely NOT interested in how to use date ranges. Which is all you find when you try to google anything to do with 'search' and 'date' as concepts together. I …

  9. How to implement "NOT IN" in Splunk - Splunk Community

    Sep 4, 2018 · Hi griffinpair, try something like this: your_search NOT [ search sourcetype="si_Export_FileMissed" earliest=-24h@h | eval clearExport = ClientID + " " + …

  10. Solved: How to search for events that have null values for.

    Oct 20, 2014 · How to search for events that have null values for a field?