Splunk Search

Splunk Search
Community Activity
Ste
Dear expertsI'm trying to move old xml dashboards to Dashboard Studio. Now I'm running into issues with a join which ...
by Ste Path Finder in Splunk Search 08-14-2025
0 6
0
6
Poojitha
Hi All, I need one help. I have created a savedsearch that writes data to metrics index. Timerange : -2m to -1mschedu...
by Poojitha Communicator in Splunk Search 08-14-2025
0 3
0
3
tdavison76
Hello,I am terrible at Regex and am in need of help on rexing a field from another field.  So an event snippet is:"In...
by tdavison76 Path Finder in Splunk Search 08-13-2025
0 7
0
7
dtaylor
Good day, I feel like this should be a simple problem, but I've looked at it too long and need some help. I have a CS...
by dtaylor Path Finder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,Here is what I have.Lookup file containing 52K rowsFields: DATE, USER, COUNTRequire forecasting user access, on...
by genesiusj Builder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,We have a lookup csv file: 1 million records (data1); and a kvstore: 3 million records (data2). We need to comp...
by genesiusj Builder in Splunk Search 08-13-2025
0 8
0
8
maigaard
Dear Splunk gurusI am trying to get the lookup command to accept the lookup table name from a variable. Example: | ev...
by maigaard New Member in Splunk Search 08-12-2025
0 4
0
4
isac_santana
Good afternoon,I need help changing the colors of two columns in my <panel>.I need to change the colors of the "Value...
by isac_santana Explorer in Splunk Search 08-12-2025
0 2
0
2
sagarikamahalik
Hi, I’m looking for a way to migrate Splunk cloud alerts (saved searches) from one environment to another.For my case...
by sagarikamahalik New Member in Splunk Search 08-12-2025
0 1
0
1
RanjiRaje
| loadjob savedsearch="userid:search:hostslists"| lookup lookupname Hostname as host OUTPUTNEW Hostname,IP| eval Host...
by RanjiRaje Explorer in Splunk Search 08-12-2025
0 5
0
5
RonaldCWWong
Hi community,I have a question on counting the number of events per values() value in stats command.For example havin...
by RonaldCWWong Explorer in Splunk Search 08-10-2025
0 4
0
4
bwheelerice1
We currently have a search that shows a timeline graph of daily SVC usage by index. 10 of these indexes are our highe...
by bwheelerice1 Loves-to-Learn Lots in Splunk Search 08-10-2025
0 6
0
6
LOP22456
We have a search app that a group of users are working from. All of the users have power role and we have given the p...
by LOP22456 Explorer in Splunk Search 08-08-2025
0 6
0
6
SN1
hello i have a search and i want only latest result of this search . ok so the problem is for 1 DeviceName there are ...
by SN1 Path Finder in Splunk Search 08-07-2025
0 11
0
11
danielbb
I have this regex -^(?:[^ \\n]* ){7}(?P<src_host>[^ ]+)[^:\\n]*:\\s+(?P<event_id>[a-f0-9]+:\\d+)(?:[^/\\n]*/){2}(?P<d...
by danielbb Motivator in Splunk Search 08-07-2025
0 1
0
1
danielbb
Does anybody know where the failures of sendemail are being logged? I wonder about cases where the e-mail address no ...
by danielbb Motivator in Splunk Search 08-06-2025
0 8
0
8
Diana_a
Hi everyone!I am new with Splunk and probably this should be really easy for many of you. I am trying to left join a ...
by Diana_a Explorer in Splunk Search 08-03-2025
0 3
0
3
kuul13
I have tried to write a query that outputs the transaction counts, and response times but not sure how to group it by...
by kuul13 Explorer in Splunk Search 08-01-2025
0 4
0
4
alvinsullivan01
I have issue to transform data and extracting the fields value. Here is my sample data.2025-07-20T10:15:30+08:00 h1 t...
by alvinsullivan01 Explorer in Splunk Search 08-01-2025
0 16
0
16
neerajs_81
Hello All,  Below is my dataset from a base query. How can i calculate the average value of the column ?Incidentavg_t...
by neerajs_81 Builder in Splunk Search 07-31-2025
0 9
0
9
Karthikeya
We will create two indexes per application one for non_prod and one for prod logs in same splunk. They create 2 AD gr...
by Karthikeya Communicator in Splunk Search 07-31-2025
0 29
0
29
arvind_Sugajeev
We have the "Reassign Knowledge Objects" option via SplunkCloud portal in the settings but is it possible to do it vi...
by arvind_Sugajeev Explorer in Splunk Search 07-30-2025
0 5
0
5
Manjunathmuni
Hello Splunkers,The hardcoded time parameters inside a simple search don't work with v9.4.3.  It only takes the input...
by Manjunathmuni Observer in Splunk Search 07-30-2025
0 9
0
9
meetmshah
I want to configure Federated Search so that Deployment A can search Deployment B, and Deployment B can also search D...
by SplunkTrust SplunkTrust in Splunk Search 07-30-2025
0 3
0
3
splunklearner
We are having multiple roles created in Splunk restricted by their index and users will be added to this role via AD ...
by splunklearner Communicator in Splunk Search 07-29-2025
0 7
0
7
Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...