Splunk Search

Splunk Search
Community Activity
dtaylor
I'm building out a search to look through email logs. The main search is fine, but I'd like to add fields showing whe...
by dtaylor Path Finder in Splunk Search 08-23-2025
0 3
0
3
RookieSplunker
Hi everyone,I'm looking for some help with a Splunk issue I recently encountered. A user's search job consumed a larg...
by RookieSplunker Engager in Splunk Search 08-22-2025
0 4
0
4
rsruthi48
I'm trying to learn Splunk and i installed the Splunk Free trial version 9.1.2I've been using this free version for o...
by rsruthi48 Observer in Splunk Search 08-22-2025
0 3
0
3
hl
Hello looking for way to create an alert based off the difference between times and only execute if the time is great...
by hl Path Finder in Splunk Search 08-20-2025
0 3
0
3
karol
I got a stream of events in a following format:[ { "name": "event 1" "attributes": ["a", "b"], }, { ...
by karol Engager in Splunk Search 08-19-2025
0 2
0
2
michaelsplunk1
Is there a limit to the number of conditions we can use in a case() statement?I've reached a point where my ORs and A...
by michaelsplunk1 Path Finder in Splunk Search 08-19-2025
1 4
1
4
sabbas
Hi folks,We use Splunk Cloud Platform for our logging needs.We would like to know the following all for the last 9 mo...
by sabbas Explorer in Splunk Search 08-18-2025
0 2
0
2
sabbas
Hello!We use Splunk cloud platform for logging.We wanted to know how we can find highly recurring events.We have many...
by sabbas Explorer in Splunk Search 08-18-2025
0 3
0
3
helenashton
My specific situation concerns a bar chart, but I think it applies to all charts. When I have so many bars that the ...
by helenashton Path Finder in Splunk Search 08-18-2025
1 8
1
8
syaseensplunk
Hi,I'm running a test setup with some live kubernetes data and I want to do the following indexer:1) Route all data m...
by syaseensplunk Loves-to-Learn Lots in Splunk Search 08-17-2025
0 20
0
20
LogUx
Hello Splunkers!!I want to combined both the queries by using append but it doesnot work. its always giving me only o...
by LogUx Motivator in Splunk Search 08-17-2025
0 13
0
13
MacAllen
Doing a query on AD events for adding users to groups.  There are 3 events, one for each type of group.  2 of them ar...
by MacAllen Engager in Splunk Search 08-15-2025
0 2
0
2
Ste
Dear expertsI'm trying to move old xml dashboards to Dashboard Studio. Now I'm running into issues with a join which ...
by Ste Path Finder in Splunk Search 08-14-2025
0 6
0
6
Poojitha
Hi All, I need one help. I have created a savedsearch that writes data to metrics index. Timerange : -2m to -1mschedu...
by Poojitha Communicator in Splunk Search 08-14-2025
0 3
0
3
tdavison76
Hello,I am terrible at Regex and am in need of help on rexing a field from another field.  So an event snippet is:"In...
by tdavison76 Path Finder in Splunk Search 08-13-2025
0 7
0
7
dtaylor
Good day, I feel like this should be a simple problem, but I've looked at it too long and need some help. I have a CS...
by dtaylor Path Finder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,Here is what I have.Lookup file containing 52K rowsFields: DATE, USER, COUNTRequire forecasting user access, on...
by genesiusj Builder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,We have a lookup csv file: 1 million records (data1); and a kvstore: 3 million records (data2). We need to comp...
by genesiusj Builder in Splunk Search 08-13-2025
0 8
0
8
maigaard
Dear Splunk gurusI am trying to get the lookup command to accept the lookup table name from a variable. Example: | ev...
by maigaard New Member in Splunk Search 08-12-2025
0 4
0
4
isac_santana
Good afternoon,I need help changing the colors of two columns in my <panel>.I need to change the colors of the "Value...
by isac_santana Explorer in Splunk Search 08-12-2025
0 2
0
2
sagarikamahalik
Hi, I’m looking for a way to migrate Splunk cloud alerts (saved searches) from one environment to another.For my case...
by sagarikamahalik New Member in Splunk Search 08-12-2025
0 1
0
1
RanjiRaje
| loadjob savedsearch="userid:search:hostslists"| lookup lookupname Hostname as host OUTPUTNEW Hostname,IP| eval Host...
by RanjiRaje Explorer in Splunk Search 08-12-2025
0 5
0
5
RonaldCWWong
Hi community,I have a question on counting the number of events per values() value in stats command.For example havin...
by RonaldCWWong Explorer in Splunk Search 08-10-2025
0 4
0
4
bwheelerice1
We currently have a search that shows a timeline graph of daily SVC usage by index. 10 of these indexes are our highe...
by bwheelerice1 Loves-to-Learn Lots in Splunk Search 08-10-2025
0 6
0
6
LOP22456
We have a search app that a group of users are working from. All of the users have power role and we have given the p...
by LOP22456 Explorer in Splunk Search 08-08-2025
0 6
0
6
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Solution Authors