Splunk Search

Splunk Search
Community Activity
USA69
Can someone help me optimize this search so the results on the search and dashboard panel should be the same. The sea...
by USA69 Path Finder in Splunk Search an hour ago
0 7
0
7
LizAndy123
We currently have a DB Connection and a Query which brings in Project Details with the username Entitlements. The Que...
by LizAndy123 Path Finder in Splunk Search Wednesday
0 7
0
7
bdh5574
We are trying to replicate some data that was in an RMF report and imported into Excel for a graph. We are trying to...
by bdh5574 New Member in Splunk Search a week ago
0 4
0
4
Praz_123
How will i check the data stop coming  from a particular sourcetype previously the data was coming.   source - /abc/r...
by Praz_123 Communicator in Splunk Search 3 weeks ago
0 9
0
9
kjain041523
| tstats summariesonly count dc(IDS_Attacks.dest) as dest from datamodel=Intrusion_Detection.IDS_Attacks where * by I...
by kjain041523 Observer in Splunk Search 4 weeks ago
0 3
0
3
priyankavj
I am trying to build a single dashboard table in Splunk that shows data from two different sourcetypes. These sourcet...
by priyankavj New Member in Splunk Search 4 weeks ago
0 7
0
7
imsidrai
i need help in setting up federated search , the requirement is that i want to run some splunk search from dbconnect ...
by imsidrai Path Finder in Splunk Search a month ago
0 7
0
7
BradOH
We have a simple report which collates several lookups into a single lookup each night to support our dashboards. We ...
by BradOH Path Finder in Splunk Search 07-31-2026
1 11
1
11
brdr
I have a field to evaluate if the value of the field is an IP address or a hostname. if it is an IP address do someth...
by brdr Contributor in Splunk Search 07-28-2026
0 5
0
5
frknklnc
Hello everyone,We are investigating an intermittent Windows Event Log ingestion issue on multiple Windows Domain Cont...
by frknklnc Observer in Splunk Search 07-23-2026
0 9
0
9
verd4nd1
Hi Guys,is there any way to create a butten within Dashboard-Studio dashboard, to refresh all panels at the same time...
by verd4nd1 Engager in Splunk Search 07-21-2026
1 8
1
8
echojacques
Hello, I use Splunk's iplocation (not Maxmind or other) command extensively in our monitoring dashboards. Since thi...
by echojacques Builder in Splunk Search 07-17-2026
8 21
8
21
zeshan66
Hi everyone!I recently installed splunk and ingested botsv3 dataset through mentioned /etc/apps and gui too. The bots...
by zeshan66 New Member in Splunk Search 07-02-2026
0 2
0
2
0xAli
Hi,I hope all is well.I am writting to ensure i am getting the correct picture on the SHC search:Assumption: 3x searc...
by 0xAli Path Finder in Splunk Search 06-30-2026
0 13
0
13
SharonNJD
I wanted to check if there is a setting in splunk enterprise where i can disable users from creating alerts in privat...
by SharonNJD Engager in Splunk Search 06-28-2026
0 2
0
2
pcaser
I want a single search that shows my daily event count for the current week alongside the same days from the previous...
by pcaser Engager in Splunk Search 06-20-2026
0 1
0
1
AleCanzo
Hi everyone,I'm facing an issue when executing a Splunk search through a Splunk SOAR playbook using the Run Query act...
by AleCanzo Path Finder in Splunk Search 06-19-2026
0 2
0
2
kjain041523
drilldown search in splunk notable is not capturing the original host which is mentioned in correlation search and ge...
by kjain041523 Observer in Splunk Search 06-18-2026
0 2
0
2
SplunkWorthy
I am attempting to use the transaction field to identify when a  service fails and then the next time it runs success...
by SplunkWorthy Loves-to-Learn Lots in Splunk Search 06-16-2026
0 11
0
11
ekb
We recently moved some inputs from universal forwarders to a pair of heavy forwarders for pre-processing. Since then ...
by ekb Engager in Splunk Search 06-15-2026
0 2
0
2
gsbpp
search  | rex field=_raw "id=\"(?<id>[^\"]*)"| stats count by id | where count > 1 I just want to consider the total ...
by gsbpp Explorer in Splunk Search 06-08-2026
0 1
0
1
MakszimM
Hello Splunkers!We are at the end of migrating an old deployment, to a new one(C1).So far everything checks out, exce...
by MakszimM Engager in Splunk Search 06-01-2026
0 1
0
1
Dolly
Hello everyone, I am facing an issue related to a Splunk user role. A role was created with access to indexes 1, 2, 3...
by Dolly Explorer in Splunk Search 05-22-2026
0 5
0
5
MonkeyK
My engineers are using OpenTelemetry and somehow that results in only getting metadata from a source.  So unlike usua...
by MonkeyK Builder in Splunk Search 05-19-2026
0 4
0
4
amangeli
Hi Everyone,I need help getting past a license lock. My Enterprise trial expired and I moved it to a Free license. Th...
by amangeli New Member in Splunk Search 05-15-2026
0 3
0
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors