Splunk Search

Splunk Search
Community Activity
surekhasplunk
Hi, Am using case statement to sort the fields according to user requirement and not alphabetically. eval sort_fie...
by surekhasplunk Communicator in Splunk Search 18 hours ago
2 5
2
5
ramuzzini
I have a system user lookup where all users are at least assigned to the GU group but can also be assigned to other g...
by ramuzzini Path Finder in Splunk Search yesterday
0 3
0
3
kchaitanya
We are trying to create a new Enterprise Security Search head cluster (with latest ES version ), Whats the best way t...
by kchaitanya Explorer in Splunk Search yesterday
1 1
1
1
spisiakmi
Hi, here is the description of the status quo. There is multiselect element defined by a token tkn1. Output variable ...
by spisiakmi Contributor in Splunk Search yesterday
0 2
0
2
im_bharath
Is Splunk Universal Forwader 9.2.5 supports to Windows Server 2025 ? Pls confirm. am seeing below in search community...
by im_bharath Path Finder in Splunk Search Wednesday
0 1
0
1
NanSplk01
I have a search started, but it's failing to run.  What I want is to eliminate some ID's and only bring back ID's tha...
by NanSplk01 Communicator in Splunk Search Tuesday
0 11
0
11
splunknoob4
I have two different searches which each get _time and username.I am trying to append these two searches, and compare...
by splunknoob4 Engager in Splunk Search Tuesday
0 12
0
12
karthi2809
Thank in Advance I have three source type Micro, application, CsID and i want to fetch details from these three sourc...
by karthi2809 Builder in Splunk Search Monday
0 2
0
2
BG_Splunk
Nightly, my organization puts a bunch of pieces of equipment into "maintenance mode" to do repairs and such on them. ...
by BG_Splunk Explorer in Splunk Search a week ago
0 7
0
7
munang
A) index=main 192.168.172.10B) index=main src_ip=192.168.172.10 I thought B) was faster.Because the index is the same...
by munang Path Finder in Splunk Search 2 weeks ago
0 2
0
2
JohnsonMarcus
Hi Team,Can someone help me with the Splunk query to input a lookupfile only when there is "no result & "no event"I t...
by JohnsonMarcus Engager in Splunk Search 2 weeks ago
0 5
0
5
danielbb
Is there a way to pass a parameter to a report when calling it via -    curl -u user:password -k https://<api_server>...
by danielbb Motivator in Splunk Search 2 weeks ago
0 3
0
3
PickleRick
Hello there.I was wondering... is there any way to generate _events_ in search?I mean, I know of the makeresults comm...
by SplunkTrust SplunkTrust in Splunk Search 2 weeks ago
0 7
0
7
yuanliu
To groupby?  Or not to groupby?  That is the question. (Not really.  The question arises because trellis splitby seem...
by SplunkTrust SplunkTrust in Splunk Search 2 weeks ago
0 2
0
2
SplunkDash
Hello, When I extract fields from the structured XML files using props.conf,  it is not extracted any key/value pairs...
by SplunkDash Motivator in Splunk Search 3 weeks ago
0 6
0
6
donaldwayne1976
Which Splunk Technical Application for Microsoft will pull the TLS details for email/Exchange?  Need to be able to re...
by donaldwayne1976 Engager in Splunk Search 3 weeks ago
0 2
0
2
SPLKrishna253
I am trying to onboard data from a syslog server. But the size on UF is increasing continuously and finally it gets b...
by SPLKrishna253 New Member in Splunk Search 3 weeks ago
0 1
0
1
eholz1
Hello All,I have a generic question on using splunk. I have two systems, system A, and system B.If a device changes s...
by eholz1 Builder in Splunk Search 3 weeks ago
0 4
0
4
wodrog
I've setup a dashboard based on charting trade queue information for our application which we are ingesting using a d...
by wodrog Engager in Splunk Search 4 weeks ago
0 4
0
4
SN1
| makeresults| eval sourcetype=split("BBCN-Kunshan,BSCN-Suzhou,BBSP-Malasiya,BTCN-Tianjin,BXCN-Xian,BCCN-Suzhouheadqu...
by SN1 Path Finder in Splunk Search 4 weeks ago
0 2
0
2
_olivier_
Hi splunkers,I need to decode base64 fields before indexing them.I found a very old post with no good proposal for th...
by _olivier_ Path Finder in Splunk Search a month ago
0 3
0
3
coo
| chart sparkline count by a,bI would like to have sparkline table like...a | b | count | sparklinething1 | fo...
by coo Explorer in Splunk Search a month ago
0 4
0
4
AbuNAM8
I am facin big issue while creating use case on splunk and adding the drill down on the content management. I went to...
by AbuNAM8 New Member in Splunk Search 01-07-2026
0 0
0
0
charliesfx
My splunk server is receiving metrics from collectd. I want to build a table showing the metrics, dimensions, and ...
by charliesfx Explorer in Splunk Search 01-06-2026
5 9
5
9
dinesh001kumar
I need to display the Success percentage for each service day wise.I am doing stats and then table getting output as ...
by dinesh001kumar Explorer in Splunk Search 01-05-2026
0 4
0
4
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...