Splunk Search

Splunk Search
Community Activity
mdorobek
Hello there, I try to import Azure NSG flow Events. To get the data into Splunk I use the Splunk Add-on for Microsoft...
by mdorobek Path Finder in Splunk Search 06-20-2025
1 14
1
14
bmer
Hello,I have 2 seperate splunks as below . One is "v1 endpoint" and other is "v2 endpoint"v1 endpoint: index="abc" "u...
by bmer Explorer in Splunk Search 06-19-2025
0 3
0
3
NanSplk01
I want to use the 2nd search as a subsearch only bringing back the actions. How can I do this?SEARCH| rest /servicesN...
by NanSplk01 Communicator in Splunk Search 06-19-2025
0 1
0
1
ashish_d
Please help share query to check > network logs and firewall blocks for specific Host machine> LDAP password login fa...
by ashish_d New Member in Splunk Search 06-19-2025
0 1
0
1
uagraw01
Hello Splunkers !!How can I efficiently use the mvexpand command to expand multiple multi-value fields, considering i...
by uagraw01 Motivator in Splunk Search 06-18-2025
0 12
0
12
avikc100
this is my log  i need a report like below: where I can see price difference in a single report. I don't want to put ...
by avikc100 Path Finder in Splunk Search 06-17-2025
0 2
0
2
bhawana2192
I am using Splunk Cloud 6.5.0 version. How can i remove latitude and longitude values while hovering over map and di...
by bhawana2192 New Member in Splunk Search 06-17-2025
0 8
0
8
anthonyi
Hello.This search returns zero results, but a manual "OR" search shows results. I cannot find the reason (neither can...
by anthonyi Explorer in Splunk Search 06-16-2025
0 3
0
3
Raj_Splunk_Ing
Hi, I have this search query where i aggregate using the stats and sum by few fields...When I run the query in splunk...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-15-2025
0 6
0
6
InspiredSplunk
Hi I want to know how long and when either of two games are being played on the PS4 or a laptop and be notified via e...
by InspiredSplunk Observer in Splunk Search 06-13-2025
0 5
0
5
Soonerseast
Hi my data is comma delimited   , there  are 2 rows with a header. I'fd like the columns to be split by the comma int...
by Soonerseast Loves-to-Learn in Splunk Search 06-13-2025
0 3
0
3
rishabhpatel20
Hello, I have lookup file uploaded and now I want to see the data, I am not able to see it on map , I can see the det...
by rishabhpatel20 Explorer in Splunk Search 06-13-2025
0 2
0
2
AleCanzo
Hi, i'm searching for a way to modify my app/dashboard to be able to modify the entries of a table (such as delete/du...
by AleCanzo Path Finder in Splunk Search 06-13-2025
0 2
0
2
cdevoe57
I have a query that detects missing systems.  the lookup table has fields System, Location, responsible.I am trying t...
by cdevoe57 Path Finder in Splunk Search 06-12-2025
0 8
0
8
ripvw32
I have the below query I've written - I am used to SQL, SPL is still new to me. I feel like there has to be some way ...
by ripvw32 Explorer in Splunk Search 06-12-2025
0 5
0
5
Cybers1
Hi Splunk Community,We’re currently trying to drop specific logs using props.conf and transforms.conf, but our config...
by Cybers1 Explorer in Splunk Search 06-11-2025
0 5
0
5
Kemark
Does splunk support fill-forward or "last observation carried forward".I want to create a daily based monitoring.One ...
by Kemark Explorer in Splunk Search 06-11-2025
0 10
0
10
AleCanzo
Hi, this is my first interaction with Splunk Community so be patient please  I'm trying to output some fields from a...
by AleCanzo Path Finder in Splunk Search 06-11-2025
0 3
0
3
caschmid
I need a query that will tell me the count of a substring within a string like this ..."This is my [string]" and I ne...
by caschmid Observer in Splunk Search 06-10-2025
0 5
0
5
cfernaca
Good afternoon,I have a monitoring architecture with three nodes with the Splunk Enterprise product. One node acts as...
by cfernaca Explorer in Splunk Search 06-10-2025
0 4
0
4
super_edition
Hello Everyone,Below is my splunk query:index="my_index" uri="*/experience/*" | stats count as hits by uri | sort -h...
by super_edition Path Finder in Splunk Search 06-09-2025
0 7
0
7
dashe
Hi,I'm trying to clean up an old splunk cloud instance. one thought that occurred to me is find scheduled searches th...
by dashe Engager in Splunk Search 06-09-2025
0 3
0
3
mchoudhary
Hi Team,I have been observing 1 skipped search error indicating on my CMC. Error is -"The maximum number of concurren...
by mchoudhary Explorer in Splunk Search 06-09-2025
0 2
0
2
jcm
0
2
N3gativeSpace
Here is my code:index=example sourcetype=wineventlog computer_name="example"| transaction computer_name startswith="e...
by N3gativeSpace Engager in Splunk Search 06-05-2025
0 3
0
3
Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Request for Professional Development: Attending .conf26

Winning Over the Boss: Your Pass to .conf26 conf26 is going to be here before you know it. If don't already ...