Splunk Search

Splunk Search
Community Activity
yuanliu
To groupby?  Or not to groupby?  That is the question. (Not really.  The question arises because trellis splitby seem...
by SplunkTrust SplunkTrust in Splunk Search 2 hours ago
0 2
0
2
SplunkDash
Hello, When I extract fields from the structured XML files using props.conf,  it is not extracted any key/value pairs...
by SplunkDash Motivator in Splunk Search Sunday
0 6
0
6
donaldwayne1976
Which Splunk Technical Application for Microsoft will pull the TLS details for email/Exchange?  Need to be able to re...
by donaldwayne1976 Engager in Splunk Search Thursday
0 2
0
2
SPLKrishna253
I am trying to onboard data from a syslog server. But the size on UF is increasing continuously and finally it gets b...
by SPLKrishna253 New Member in Splunk Search Wednesday
0 1
0
1
eholz1
Hello All,I have a generic question on using splunk. I have two systems, system A, and system B.If a device changes s...
by eholz1 Builder in Splunk Search Wednesday
0 4
0
4
wodrog
I've setup a dashboard based on charting trade queue information for our application which we are ingesting using a d...
by wodrog Engager in Splunk Search a week ago
0 4
0
4
SN1
| makeresults| eval sourcetype=split("BBCN-Kunshan,BSCN-Suzhou,BBSP-Malasiya,BTCN-Tianjin,BXCN-Xian,BCCN-Suzhouheadqu...
by SN1 Path Finder in Splunk Search a week ago
0 2
0
2
_olivier_
Hi splunkers,I need to decode base64 fields before indexing them.I found a very old post with no good proposal for th...
by _olivier_ Path Finder in Splunk Search 2 weeks ago
0 3
0
3
coo
| chart sparkline count by a,bI would like to have sparkline table like...a | b | count | sparklinething1 | fo...
by coo Explorer in Splunk Search 2 weeks ago
0 4
0
4
AbuNAM8
I am facin big issue while creating use case on splunk and adding the drill down on the content management. I went to...
by AbuNAM8 New Member in Splunk Search 2 weeks ago
0 0
0
0
charliesfx
My splunk server is receiving metrics from collectd. I want to build a table showing the metrics, dimensions, and ...
by charliesfx Explorer in Splunk Search 2 weeks ago
5 9
5
9
dinesh001kumar
I need to display the Success percentage for each service day wise.I am doing stats and then table getting output as ...
by dinesh001kumar Explorer in Splunk Search 2 weeks ago
0 4
0
4
yuanliu
Riding the coattail of Re: Why is the null value in a JSON event not being parsed properly as NULL?, I constructed tw...
by SplunkTrust SplunkTrust in Splunk Search 2 weeks ago
1 4
1
4
Didalready
When I use the search below, the event is 25 days ago, set search to last 30 takes 10 seconds, set to 90 days takes 2...
by Didalready Explorer in Splunk Search 3 weeks ago
0 1
0
1
ThuLe
Hello everyone,I am trying to create a custom report that lists Investigations alongside the Notable Events (Findings...
by ThuLe Explorer in Splunk Search 3 weeks ago
0 5
0
5
satyaallaparthi
Hi everyone,I need some help with a SPL query.I am trying to create an inventory of all queries running in my dashboa...
by satyaallaparthi Communicator in Splunk Search 4 weeks ago
0 9
0
9
dtaylor
I'm working with a search that starts by filtering for all process events in Windows and then sending them to a looku...
by dtaylor Path Finder in Splunk Search 4 weeks ago
0 2
0
2
bmer
Hi,Iam using below splunk to help identify least common values of runTime field in myEventRecType file . i get the re...
by bmer Explorer in Splunk Search a month ago
0 4
0
4
andrewpense825
Good day, I often run up against the issue of wanting to drag the text of a field name from the browser into a separa...
by andrewpense825 Explorer in Splunk Search 12-18-2025
1 4
1
4
JohnEGones
Hi Team,I have been trying to work on a query I found on a blog that was trying to calculate and tag a week over week...
by JohnEGones Communicator in Splunk Search 12-17-2025
0 4
0
4
nawazns5038
how can we get the oldest index time of an index ? Does retention policy depend on indextime or _time ?
by nawazns5038 Builder in Splunk Search 12-17-2025
1 20
1
20
bpenny
Executive overview: We're using Splunk Cloud (Victoria Experience), and we're in the process of spinning up a new ins...
by bpenny Explorer in Splunk Search 12-15-2025
0 1
0
1
tscroggins
Hi Splunkers!In the current json_extend documentation <https://help.splunk.com/en/splunk-enterprise/spl-search-refere...
by tscroggins Champion in Splunk Search 12-14-2025
0 5
0
5
zeshan66
Hi everyone!I recently installed splunk and ingested botsv3 dataset through mentioned /etc/apps and gui too. The bots...
by zeshan66 New Member in Splunk Search 12-14-2025
0 1
0
1
agneticdk
Hi guys   I have an installation on Splunk 8.1.2 where we have XmlWinEventLog data ingested. When we run this search:...
by agneticdk Path Finder in Splunk Search 12-12-2025
1 4
1
4
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Solution Authors