Splunk Search

Splunk Search
Community Activity
shawngsharp
I am trying to do a query that will search for arbitrary strings, but will ignore if the string is/isn't in a specifi...
by shawngsharp New Member in Splunk Search 05-09-2025
0 6
0
6
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-09-2025
0 5
0
5
dflynn235
I'm attempting to suppress an alert if a follow up event (condition) is received within 60 seconds of the initial eve...
by dflynn235 Loves-to-Learn in Splunk Search 05-08-2025
0 7
0
7
msarkaus
Hello,I have this Splunk log that contains tons of quotes, commas, and other special characters. I’m trying to only p...
by msarkaus Path Finder in Splunk Search 05-08-2025
0 17
0
17
u_m1580
Hi there,I would like to create a search to alert us based on an index not ingesting any event data by basing it off ...
by u_m1580 New Member in Splunk Search 05-08-2025
0 2
0
2
LIS
Hi Splunkers :-),We have nice feature it dashboard studio - "Select all matches" in multiselect filter.But, unfortuna...
by LIS Path Finder in Splunk Search 05-07-2025
0 20
0
20
sdanayak
I want to have result in table with 2 or 3 log events combined based on unique key in all events and return 1 single ...
by sdanayak Loves-to-Learn in Splunk Search 05-07-2025
0 9
0
9
Crabbok
I'm trying to track the duration of user sessions to a server.   I want to know WHICH users are connecting, and for h...
by Crabbok Engager in Splunk Search 05-07-2025
0 3
0
3
jialiu907
I am looking for a range of number within my results of my search query but I am getting no results back after adding...
by jialiu907 Path Finder in Splunk Search 05-07-2025
0 12
0
12
Casial06
I'm creating Mutiple Locked account search query while checking the account first if it has 4767 (unlocked) it should...
by Casial06 Explorer in Splunk Search 05-07-2025
0 4
0
4
Alan_Chan
We found that the search job size becomes extremely large during searches. My Splunk instance is a newly installed te...
by Alan_Chan Explorer in Splunk Search 05-07-2025
0 1
0
1
Harikiranjammul
I am running tstats command with span of 2hrs for index and source.It returns the data for every 2hrs.But I want to i...
by Harikiranjammul Explorer in Splunk Search 05-06-2025
0 4
0
4
irfanarif
Hi, I completed a course titled “Intro to Superman Mission Control” earlier, but it no longer appears in the free cou...
by irfanarif Engager in Splunk Search 05-06-2025
0 2
0
2
jat75
I have a search where I am doing 2 inputlookups for 2 different lookups and appending them. Then I search them. Can I...
by jat75 Explorer in Splunk Search 05-06-2025
0 1
0
1
timgren
Id like to create table of results, and convert each row into an unordered bullet list using html. Such as: | table r...
by timgren Path Finder in Splunk Search 05-06-2025
0 1
0
1
Jessydan
Hello,I'm working on a Splunk query to track REST calls in our logs. Specifically, I’m trying to use the transaction ...
by Jessydan Explorer in Splunk Search 05-05-2025
0 10
0
10
Ara
I am trying to loop over a table and perform a subsearch for each item. I can confirm I am generating the first table...
by Ara Engager in Splunk Search 05-05-2025
0 6
0
6
Ghost
Hello,Got tasked with finding all hosts that didnt have the crowdstrike agent installed and running into problems wit...
by Ghost New Member in Splunk Search 05-05-2025
0 2
0
2
RSS_STT
I have multiple disk like C, D & E on server and want to do the prediction for multiple disk in same query.index=main...
by RSS_STT Explorer in Splunk Search 05-05-2025
0 2
0
2
AJH2000
Hi community,I'm running into a permissions/visibility issue (I don't know) with an index created for receiving data ...
by AJH2000 Explorer in Splunk Search 05-05-2025
0 3
0
3
avikc100
I want to replace hard coded text "Today" by current system date in splunk report. Please help if it is possible.Plea...
by avikc100 Path Finder in Splunk Search 05-03-2025
0 6
0
6
pck_npluyaud
Hello.For reasons of JSON log splitting, I have a problem with a complex structure.The integration is in a forwarder ...
by pck_npluyaud Explorer in Splunk Search 05-03-2025
0 8
0
8
nithys
Hi Team,Currently in my dashboard i am using two separate query for data and search lambda separetly and added to the...
by nithys Communicator in Splunk Search 05-02-2025
0 2
0
2
dlm
I have a unique situation with my customer. I want to create a lookup table that the customer can put  fields they wa...
by dlm Path Finder in Splunk Search 05-02-2025
0 7
0
7
Charlize
Added the config for the new metadata field in the inputs.conf file and created a fields.conf file to set the field a...
by Charlize Engager in Splunk Search 05-02-2025
0 4
0
4
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...
Top Solution Authors