Splunk Search

Splunk Search
Community Activity
Pooja1
Hi Team,On May 20th, we successfully migrated from Splunk On-Prem to Splunk Cloud. We have a scheduled search that ru...
by Pooja1 Loves-to-Learn Everything in Splunk Search 05-29-2025
0 2
0
2
mchoudhary
Hi Everyone!I wrote a search query to get the blocked count of emails for last 6months and below is my query-| tstats...
by mchoudhary Explorer in Splunk Search 05-29-2025
0 9
0
9
dtaylor
Hopefully I've only got a small problem this time, but I've had no luck fixing it despite hours of trying. All I'm tr...
by dtaylor Path Finder in Splunk Search 05-28-2025
0 2
0
2
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-28-2025
0 1
0
1
Raj_Splunk_Ing
Hi ,  I have this scenario where i am getting data from one of the index with 2 other specified filters likeindex=ind...
by Raj_Splunk_Ing Path Finder in Splunk Search 05-28-2025
0 5
0
5
robertlynch2020
Hi I have the following data (Below).I have a situation where I want to search for "*" on a search and have it return...
by robertlynch2020 Influencer in Splunk Search 05-28-2025
0 8
0
8
Cheng2Ready
This is what I have setupindex=xxxxxx| eval HDate=strftime(_time,"%Y-%m-%d")| search NOT [ | inputlookup Date_Test.cs...
by Cheng2Ready Communicator in Splunk Search 05-27-2025
0 13
0
13
Benny87
Hi,got some problem in my searches since a few days.I really don´t know what happend and no one changed the configura...
by Benny87 Loves-to-Learn in Splunk Search 05-27-2025
0 7
0
7
ebailey
I have a distributed Splunk instance with the search head separated from the Indexers. I want to drop a CSV file with...
by ebailey Communicator in Splunk Search 05-22-2025
2 10
2
10
SN1
hello So i want to make a search .i am using index=endpoint_defender source="AdvancedHunting-DeviceInfo" | rex field=...
by SN1 Path Finder in Splunk Search 05-22-2025
0 7
0
7
kaeleyt
Situation: I have 2 data sets:Dataset 1 is a set of logs which includes IP addresses. When aggregated, there are 200,...
by kaeleyt Path Finder in Splunk Search 05-22-2025
0 3
0
3
Harikiranjammul
Have a data that returns ip field and values as below.Ip = 0.0.0.11Ip= 0.0.0.12There is a lookup that contains field ...
by Harikiranjammul Explorer in Splunk Search 05-22-2025
0 2
0
2
kn450
Hi Splunk Community,I’m working on a use case where data is stored in Elasticsearch, and I’d like to use Splunk solel...
by kn450 Explorer in Splunk Search 05-21-2025
0 6
0
6
andrewkenth
I have 3 searches that I'm appending. Each returns a Name and Date. Then I take the maximum of each of the Dates and ...
by andrewkenth Communicator in Splunk Search 05-21-2025
0 4
0
4
bvivi57
Hi, I have to search saved as quickly as possible. I CSV indexes whose columns are sometimes empty. I have to put a ...
by bvivi57 Observer in Splunk Search 05-21-2025
0 9
0
9
tpchi
Hi team, There is following errors with my Splunk healtch check. "The number of extremely lagged searches (1) over th...
by tpchi New Member in Splunk Search 05-21-2025
0 5
0
5
Jimenez
Hi all, I have the following situation with a query returning a table of this kind:fieldAfieldBA2A2B4B4 I need to add...
by Jimenez Explorer in Splunk Search 05-21-2025
0 3
0
3
Anam
Hello Splunk Community! Welcome to another week of fun curated content as a part of our Splunk Answers Community Cont...
by Community Manager Community Manager in Splunk Search 05-20-2025
2 0
2
0
tdavison76
Hello,I have a Search that is taking 5 min to complete when looking at only the last 24 hrs.  If possible, could some...
by tdavison76 Path Finder in Splunk Search 05-20-2025
0 5
0
5
sarvesh_11
Hello ,My splunk query is simple: index=abc,source=xxx.trc| transaction host source max events=100000| table _time ho...
by sarvesh_11 Communicator in Splunk Search 05-20-2025
0 14
0
14
mpk_24
Hello @Splunkers,Can someone please help me on this ? Trying to use "lookup/ inputlookup" command in search.Use case:...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 6
0
6
mpk_24
Hey @Splunkers,Looking for valuable insights for this use case. I wanted to extract the numbers at the end of the log...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 2
0
2
te25
Hello. I am working on creating an alert in Splunk for detecting when a firewall stops sending logs. We have all logs...
by te25 Engager in Splunk Search 05-19-2025
0 3
0
3
m_zandinia
Hi Splunkers,I’m running a Splunk Search Head Cluster (SHC) with 3 search heads, authenticated via Active Directory (...
by m_zandinia Path Finder in Splunk Search 05-18-2025
0 16
0
16
tiimo
If you use timewrap without previously using the timechart command, you get a warning "The timewrap command is design...
by tiimo Engager in Splunk Search 05-16-2025
0 4
0
4
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...