Splunk Search

Splunk Search
Community Activity
questionsdaniel
Hi, I'm attempting to write a search where I return a top 10 of a value. However, I am noticing that I return differe...
by questionsdaniel Observer in Splunk Search 06-24-2025
0 2
0
2
super_edition
Hello Everyone,I have 2 splunk search queriesquery-1index="my_index" kubernetes_namespace="my_ns" kubernetes_cluste...
by super_edition Path Finder in Splunk Search 06-24-2025
0 3
0
3
BraxcBT
I am logged in as the admin user, but whenever I try to access Tokens, Users, or other settings pages, I get a blank ...
by BraxcBT Explorer in Splunk Search 06-23-2025
0 3
0
3
LizAndy123
So I have successfully configured some reports and alerts that send the $result to Mattermost.My question is how to d...
by LizAndy123 Path Finder in Splunk Search 06-23-2025
0 1
0
1
hendriks
Hello, I have a simple distributed search config on a windows host, 1 SH, 1 IDX and 1 License server. Running a searc...
by hendriks Path Finder in Splunk Search 06-23-2025
0 9
0
9
jrodriguezap
I'm trying to split a pair of rows with a pair of multivalued columns. The value in both columns is related to each p...
by jrodriguezap Contributor in Splunk Search 06-22-2025
0 8
0
8
jfraley
I am looking for away to join results from two indexes based on the hostname. The main index has the hostname as just...
by jfraley Path Finder in Splunk Search 06-21-2025
0 3
0
3
mdorobek
Hello there, I try to import Azure NSG flow Events. To get the data into Splunk I use the Splunk Add-on for Microsoft...
by mdorobek Path Finder in Splunk Search 06-20-2025
1 14
1
14
bmer
Hello,I have 2 seperate splunks as below . One is "v1 endpoint" and other is "v2 endpoint"v1 endpoint: index="abc" "u...
by bmer Explorer in Splunk Search 06-19-2025
0 3
0
3
NanSplk01
I want to use the 2nd search as a subsearch only bringing back the actions. How can I do this?SEARCH| rest /servicesN...
by NanSplk01 Communicator in Splunk Search 06-19-2025
0 1
0
1
ashish_d
Please help share query to check > network logs and firewall blocks for specific Host machine> LDAP password login fa...
by ashish_d New Member in Splunk Search 06-19-2025
0 1
0
1
LogUx
Hello Splunkers !!How can I efficiently use the mvexpand command to expand multiple multi-value fields, considering i...
by LogUx Motivator in Splunk Search 06-18-2025
0 12
0
12
avikc100
this is my log avikc100_0-1750165643287.png i need a report like below: where I can see price difference in a single ...
by avikc100 Path Finder in Splunk Search 06-17-2025
0 2
0
2
bhawana2192
I am using Splunk Cloud 6.5.0 version. How can i remove latitude and longitude values while hovering over map and di...
by bhawana2192 New Member in Splunk Search 06-17-2025
0 8
0
8
anthonyi
Hello.This search returns zero results, but a manual "OR" search shows results. I cannot find the reason (neither can...
by anthonyi Explorer in Splunk Search 06-16-2025
0 3
0
3
Raj_Splunk_Ing
Hi, I have this search query where i aggregate using the stats and sum by few fields...When I run the query in splunk...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-15-2025
0 6
0
6
InspiredSplunk
Hi I want to know how long and when either of two games are being played on the PS4 or a laptop and be notified via e...
by InspiredSplunk Observer in Splunk Search 06-13-2025
0 5
0
5
Soonerseast
Hi my data is comma delimited   , there  are 2 rows with a header. I'fd like the columns to be split by the comma int...
by Soonerseast Loves-to-Learn in Splunk Search 06-13-2025
0 3
0
3
rishabhpatel20
Hello, I have lookup file uploaded and now I want to see the data, I am not able to see it on map , I can see the det...
by rishabhpatel20 Explorer in Splunk Search 06-13-2025
0 2
0
2
AleCanzo
Hi, i'm searching for a way to modify my app/dashboard to be able to modify the entries of a table (such as delete/du...
by AleCanzo Path Finder in Splunk Search 06-13-2025
0 2
0
2
cdevoe57
I have a query that detects missing systems.  the lookup table has fields System, Location, responsible.I am trying t...
by cdevoe57 Path Finder in Splunk Search 06-12-2025
0 8
0
8
ripvw32
I have the below query I've written - I am used to SQL, SPL is still new to me. I feel like there has to be some way ...
by ripvw32 Explorer in Splunk Search 06-12-2025
0 5
0
5
Cybers1
Hi Splunk Community,We’re currently trying to drop specific logs using props.conf and transforms.conf, but our config...
by Cybers1 Explorer in Splunk Search 06-11-2025
0 5
0
5
Kemark
Does splunk support fill-forward or "last observation carried forward".I want to create a daily based monitoring.One ...
by Kemark Explorer in Splunk Search 06-11-2025
0 10
0
10
AleCanzo
Hi, this is my first interaction with Splunk Community so be patient please  I'm trying to output some fields from a...
by AleCanzo Path Finder in Splunk Search 06-11-2025
0 3
0
3
Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...