Splunk Search

Splunk Search
Community Activity
mchoudhary
Hi Team,I have been observing 1 skipped search error indicating on my CMC. Error is -"The maximum number of concurren...
by mchoudhary Explorer in Splunk Search 06-09-2025
0 2
0
2
jcm
0
2
N3gativeSpace
Here is my code:index=example sourcetype=wineventlog computer_name="example"| transaction computer_name startswith="e...
by N3gativeSpace Engager in Splunk Search 06-05-2025
0 3
0
3
orpiczy
Hi Fellow Splunkers,How can I add multi-value field (array) directly to the index through `/var/spool/splunk`.I tried...
by orpiczy Splunk Employee Splunk Employee in Splunk Search 06-05-2025
0 1
0
1
kn450
opt/caspida/bin/Caspida setuphadoop ...............................Failed to run sudo -u hdfs hdfs namenode -format >...
by kn450 Explorer in Splunk Search 06-05-2025
0 1
0
1
anlePRH
I currently have this to group IPs into subnets and list the counts, I want it to also show the IP it has listed aswe...
by anlePRH Observer in Splunk Search 06-05-2025
0 3
0
3
mchoudhary
Hi everyone!I am working on building a dashboard which captures all the firewall, Web proxy, EDR, WAF, Email, DLP blo...
by mchoudhary Explorer in Splunk Search 06-05-2025
0 6
0
6
tomapatan
I'm working with a CSV lookup  that contains multiple fields which may include wildcard (*) values.The lookup is stru...
by tomapatan Contributor in Splunk Search 06-05-2025
0 1
0
1
sabbas
Hello folks,We use Splunk cloud platform (managed by Splunk) for our logging system. We want to implement role based ...
by sabbas Explorer in Splunk Search 06-04-2025
0 1
0
1
sdubey_splunk
Symptoms: It usually happen in the next couple of hours after we manually deleted the stuck search jobs It only happ...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk Search 06-04-2025
0 3
0
3
yeahnah
The xpath command does not work if the XML event contains valid prolog header lines (https://www.w3schools.com/xml/xm...
by yeahnah Motivator in Splunk Search 06-03-2025
0 2
0
2
Raj_Splunk_Ing
Hi,I have this very simple splunk search query and i was able to run in splunk search portal or UI and I am using the...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 10
0
10
Raj_Splunk_Ing
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in itafter ...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 7
0
7
Karthikeya
We are getting this particular error Waiting for queued jobs to start for most of our customers. When they click on m...
by Karthikeya Communicator in Splunk Search 06-03-2025
0 2
0
2
sabbas
Hello folks,We use Splunk cloud platform for our logging system. I was trying to use the Search Filter under the Rest...
by sabbas Explorer in Splunk Search 06-03-2025
0 1
0
1
a212830
Why is | tstats count where index=* by sourcetype so much faster than index=* | stats count by sourcetype ?
by a212830 Champion in Splunk Search 06-01-2025
20 8
20
8
asif_khan1
I am trying to get a list of all services that are in APM. The APM usage report does not provide the name and only pr...
by asif_khan1 New Member in Splunk Search 05-30-2025
0 0
0
0
harshal_chakran
Hi, I am working to list all the index with underlying sourcetypes and sources in it. For which I am currently usin...
by harshal_chakran Builder in Splunk Search 05-30-2025
0 7
0
7
smanojkumar
index=*sap sourcetype=FSC*| fields _time index Eventts ID FIELD_02 FIELD_01 CODE ID FIELD* source| rex field=index "^...
by smanojkumar Contributor in Splunk Search 05-30-2025
0 12
0
12
Pooja1
Hi Team,On May 20th, we successfully migrated from Splunk On-Prem to Splunk Cloud. We have a scheduled search that ru...
by Pooja1 Loves-to-Learn Everything in Splunk Search 05-29-2025
0 2
0
2
mchoudhary
Hi Everyone!I wrote a search query to get the blocked count of emails for last 6months and below is my query-| tstats...
by mchoudhary Explorer in Splunk Search 05-29-2025
0 9
0
9
dtaylor
Hopefully I've only got a small problem this time, but I've had no luck fixing it despite hours of trying. All I'm tr...
by dtaylor Path Finder in Splunk Search 05-28-2025
0 2
0
2
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-28-2025
0 1
0
1
Raj_Splunk_Ing
Hi ,  I have this scenario where i am getting data from one of the index with 2 other specified filters likeindex=ind...
by Raj_Splunk_Ing Path Finder in Splunk Search 05-28-2025
0 5
0
5
robertlynch2020
Hi I have the following data (Below).I have a situation where I want to search for "*" on a search and have it return...
by robertlynch2020 Influencer in Splunk Search 05-28-2025
0 8
0
8
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors