Splunk Search

Splunk Search
Community Activity
sabbas
Hello!We use Splunk cloud platform for logging.We wanted to know how we can find highly recurring events.We have many...
by sabbas Explorer in Splunk Search 08-18-2025
0 3
0
3
helenashton
My specific situation concerns a bar chart, but I think it applies to all charts. When I have so many bars that the ...
by helenashton Path Finder in Splunk Search 08-18-2025
1 8
1
8
syaseensplunk
Hi,I'm running a test setup with some live kubernetes data and I want to do the following indexer:1) Route all data m...
by syaseensplunk Loves-to-Learn Lots in Splunk Search 08-17-2025
0 20
0
20
LogUx
Hello Splunkers!!I want to combined both the queries by using append but it doesnot work. its always giving me only o...
by LogUx Motivator in Splunk Search 08-17-2025
0 13
0
13
MacAllen
Doing a query on AD events for adding users to groups.  There are 3 events, one for each type of group.  2 of them ar...
by MacAllen Engager in Splunk Search 08-15-2025
0 2
0
2
Ste
Dear expertsI'm trying to move old xml dashboards to Dashboard Studio. Now I'm running into issues with a join which ...
by Ste Path Finder in Splunk Search 08-14-2025
0 6
0
6
Poojitha
Hi All, I need one help. I have created a savedsearch that writes data to metrics index. Timerange : -2m to -1mschedu...
by Poojitha Communicator in Splunk Search 08-14-2025
0 3
0
3
tdavison76
Hello,I am terrible at Regex and am in need of help on rexing a field from another field.  So an event snippet is:"In...
by tdavison76 Path Finder in Splunk Search 08-13-2025
0 7
0
7
dtaylor
Good day, I feel like this should be a simple problem, but I've looked at it too long and need some help. I have a CS...
by dtaylor Path Finder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,Here is what I have.Lookup file containing 52K rowsFields: DATE, USER, COUNTRequire forecasting user access, on...
by genesiusj Builder in Splunk Search 08-13-2025
0 4
0
4
genesiusj
Hello,We have a lookup csv file: 1 million records (data1); and a kvstore: 3 million records (data2). We need to comp...
by genesiusj Builder in Splunk Search 08-13-2025
0 8
0
8
maigaard
Dear Splunk gurusI am trying to get the lookup command to accept the lookup table name from a variable. Example: | ev...
by maigaard New Member in Splunk Search 08-12-2025
0 4
0
4
isac_santana
Good afternoon,I need help changing the colors of two columns in my <panel>.I need to change the colors of the "Value...
by isac_santana Explorer in Splunk Search 08-12-2025
0 2
0
2
sagarikamahalik
Hi, I’m looking for a way to migrate Splunk cloud alerts (saved searches) from one environment to another.For my case...
by sagarikamahalik New Member in Splunk Search 08-12-2025
0 1
0
1
RanjiRaje
| loadjob savedsearch="userid:search:hostslists"| lookup lookupname Hostname as host OUTPUTNEW Hostname,IP| eval Host...
by RanjiRaje Explorer in Splunk Search 08-12-2025
0 5
0
5
RonaldCWWong
Hi community,I have a question on counting the number of events per values() value in stats command.For example havin...
by RonaldCWWong Explorer in Splunk Search 08-10-2025
0 4
0
4
bwheelerice1
We currently have a search that shows a timeline graph of daily SVC usage by index. 10 of these indexes are our highe...
by bwheelerice1 Loves-to-Learn Lots in Splunk Search 08-10-2025
0 6
0
6
LOP22456
We have a search app that a group of users are working from. All of the users have power role and we have given the p...
by LOP22456 Explorer in Splunk Search 08-08-2025
0 6
0
6
SN1
hello i have a search and i want only latest result of this search . ok so the problem is for 1 DeviceName there are ...
by SN1 Path Finder in Splunk Search 08-07-2025
0 11
0
11
danielbb
I have this regex -^(?:[^ \\n]* ){7}(?P<src_host>[^ ]+)[^:\\n]*:\\s+(?P<event_id>[a-f0-9]+:\\d+)(?:[^/\\n]*/){2}(?P<d...
by danielbb Motivator in Splunk Search 08-07-2025
0 1
0
1
danielbb
Does anybody know where the failures of sendemail are being logged? I wonder about cases where the e-mail address no ...
by danielbb Motivator in Splunk Search 08-06-2025
0 8
0
8
Diana_a
Hi everyone!I am new with Splunk and probably this should be really easy for many of you. I am trying to left join a ...
by Diana_a Explorer in Splunk Search 08-03-2025
0 3
0
3
kuul13
I have tried to write a query that outputs the transaction counts, and response times but not sure how to group it by...
by kuul13 Explorer in Splunk Search 08-01-2025
0 4
0
4
alvinsullivan01
I have issue to transform data and extracting the fields value. Here is my sample data.2025-07-20T10:15:30+08:00 h1 t...
by alvinsullivan01 Explorer in Splunk Search 08-01-2025
0 16
0
16
neerajs_81
Hello All,  Below is my dataset from a base query. How can i calculate the average value of the column ?Incidentavg_t...
by neerajs_81 Builder in Splunk Search 07-31-2025
0 9
0
9
Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...