Splunk Search

Splunk Search
Community Activity
artkhod
Hi,I haven't seen the acceleration mentioned anywhere in regards to SPL2.I have saved a sample search as a report for...
by artkhod New Member in Splunk Search Thursday
0 0
0
0
wp-uk-36
Hi,From time to time I make typos in field names in my Splunk SPL searches and very rightly Splunk returns nothing in...
by wp-uk-36 Explorer in Splunk Search a week ago
1 6
1
6
kjain041523
Hi, I need a splunk query to find the license utilization per host per day in last 4 months, to know which host/serve...
by kjain041523 New Member in Splunk Search 2 weeks ago
0 3
0
3
SN1
I have admin role in splunk , I was able to edit alert searches before but now i am not able to do so. 
by SN1 Path Finder in Splunk Search 2 weeks ago
0 4
0
4
sdk32
hi Every one i am new to splunk , but here my query goes:Sample Data and json : {id: 1 , executor: "executor1" , time...
by sdk32 Engager in Splunk Search 2 weeks ago
1 4
1
4
Kobi998
Hi,I’d appreciate your help extracting attachments/notes that users add to Findings (Mission Control) for reporting p...
by Kobi998 New Member in Splunk Search 2 weeks ago
0 1
0
1
BradOH
Hey community, another weird question.  We have scheduled reports which use dbxlookups to enrich the data for analysi...
by BradOH Path Finder in Splunk Search 2 weeks ago
0 3
0
3
koyachi
Hi All,We have been experiencing intermittent indexing delays on our Splunk environment, which consists of three stan...
by koyachi Explorer in Splunk Search 3 weeks ago
0 3
0
3
manchou0709
Hi everyone, I am trying to find out index name , sourcetype for 100+  (128) hosts. Since I am working in a multisite...
by manchou0709 Explorer in Splunk Search 3 weeks ago
0 2
0
2
Poojary
I am using n8n automation to fetch information from a Splunk search. However, when I use the n8n node, I get an authe...
by Poojary New Member in Splunk Search 3 weeks ago
0 3
0
3
splunkreal
Hello,when using index=si_cisco we get results however if we add index=si_cisco sourcetype="cisco:ise:syslog" then no...
by splunkreal Influencer in Splunk Search 4 weeks ago
0 8
0
8
Darthsplunker
Simple one for you all!I have a query that shows files(cs_uri_stem) on a webserver accessed and the http status codes...
by Darthsplunker Path Finder in Splunk Search 4 weeks ago
0 12
0
12
Darkvader
When mapping fields to the CIM in an indexer cluster can I use search time field extractions like IFX, tags and field...
by Darkvader Explorer in Splunk Search 4 weeks ago
0 6
0
6
LexSplunker
I know this has always been kind of a sore subject due to the use of the userAccountControl property flags being in s...
by LexSplunker Engager in Splunk Search 4 weeks ago
0 2
0
2
manas
Capture in a field from log message and it is in below format : [{"request":"ID1","statusCode":"200"},{"request":"ID2...
by manas Explorer in Splunk Search 4 weeks ago
0 4
0
4
MakszimM
Hello Splunkers!We are at the end of migrating an old deployment, to a new one(C1).So far everything checks out, exce...
by MakszimM Engager in Splunk Search 03-24-2026
0 0
0
0
cipher
Hi,I’ve set up an alert in Splunk that triggers whenever there are log gaps (missing logs) from hosts, based on the R...
by cipher Explorer in Splunk Search 03-23-2026
0 1
0
1
MJ_27
I'm trying to figure out when some of my correlation searches was created ?i tried it with rest, but only getting upd...
by MJ_27 New Member in Splunk Search 03-23-2026
0 3
0
3
imsidrai
i need help in setting up federated search , the requirement is that i want to run some splunk search from dbconnect ...
by imsidrai Explorer in Splunk Search 03-22-2026
0 3
0
3
mcaulsc
I'm trying to create an alert based on a field as shown below, I want to search for the EDC5133I text. However the TE...
by mcaulsc Path Finder in Splunk Search 03-18-2026
0 6
0
6
ManjunathNargun
Team , how to get an extract of threshold values set in Splunk ITSI. Kindly suggest.
by ManjunathNargun New Member in Splunk Search 03-18-2026
0 0
0
0
tpchi
Hi team, There is following errors with my Splunk healtch check. "The number of extremely lagged searches (1) over th...
by tpchi New Member in Splunk Search 03-16-2026
0 7
0
7
dtaylor
If I look at this long enough, I'm sure I'll eventually figure it out, but that could be a whole month at my current ...
by dtaylor Path Finder in Splunk Search 03-14-2026
0 3
0
3
beetlegeuse
I have a dropdown input type in a dashboard that has a token aligned with it (we'll call it $dropdown_value$); the va...
by beetlegeuse Path Finder in Splunk Search 03-11-2026
0 2
0
2
RSS_STT
"resource_id": "/subscriptions/850686fe-9b2b-48ab-81a6-80600a0ca5z1/resourceGroups/vg-weu-ltaprod-rg/providers/Micros...
by RSS_STT Explorer in Splunk Search 03-11-2026
0 5
0
5
Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...
Top Solution Authors