Splunk Search

Splunk Search
Community Activity
cdevoe57
I have a query that detects missing systems.  the lookup table has fields System, Location, responsible.I am trying t...
by cdevoe57 Path Finder in Splunk Search 06-12-2025
0 8
0
8
ripvw32
I have the below query I've written - I am used to SQL, SPL is still new to me. I feel like there has to be some way ...
by ripvw32 Explorer in Splunk Search 06-12-2025
0 5
0
5
Cybers1
Hi Splunk Community,We’re currently trying to drop specific logs using props.conf and transforms.conf, but our config...
by Cybers1 Explorer in Splunk Search 06-11-2025
0 5
0
5
Kemark
Does splunk support fill-forward or "last observation carried forward".I want to create a daily based monitoring.One ...
by Kemark Explorer in Splunk Search 06-11-2025
0 10
0
10
AleCanzo
Hi, this is my first interaction with Splunk Community so be patient please  I'm trying to output some fields from a...
by AleCanzo Path Finder in Splunk Search 06-11-2025
0 3
0
3
caschmid
I need a query that will tell me the count of a substring within a string like this ..."This is my [string]" and I ne...
by caschmid Observer in Splunk Search 06-10-2025
0 5
0
5
cfernaca
Good afternoon,I have a monitoring architecture with three nodes with the Splunk Enterprise product. One node acts as...
by cfernaca Explorer in Splunk Search 06-10-2025
0 4
0
4
super_edition
Hello Everyone,Below is my splunk query:index="my_index" uri="*/experience/*" | stats count as hits by uri | sort -h...
by super_edition Path Finder in Splunk Search 06-09-2025
0 7
0
7
dashe
Hi,I'm trying to clean up an old splunk cloud instance. one thought that occurred to me is find scheduled searches th...
by dashe Engager in Splunk Search 06-09-2025
0 3
0
3
mchoudhary
Hi Team,I have been observing 1 skipped search error indicating on my CMC. Error is -"The maximum number of concurren...
by mchoudhary Explorer in Splunk Search 06-09-2025
0 2
0
2
jcm
0
2
N3gativeSpace
Here is my code:index=example sourcetype=wineventlog computer_name="example"| transaction computer_name startswith="e...
by N3gativeSpace Engager in Splunk Search 06-05-2025
0 3
0
3
orpiczy
Hi Fellow Splunkers,How can I add multi-value field (array) directly to the index through `/var/spool/splunk`.I tried...
by orpiczy Splunk Employee Splunk Employee in Splunk Search 06-05-2025
0 1
0
1
kn450
opt/caspida/bin/Caspida setuphadoop ...............................Failed to run sudo -u hdfs hdfs namenode -format >...
by kn450 Explorer in Splunk Search 06-05-2025
0 1
0
1
anlePRH
I currently have this to group IPs into subnets and list the counts, I want it to also show the IP it has listed aswe...
by anlePRH Observer in Splunk Search 06-05-2025
0 3
0
3
mchoudhary
Hi everyone!I am working on building a dashboard which captures all the firewall, Web proxy, EDR, WAF, Email, DLP blo...
by mchoudhary Explorer in Splunk Search 06-05-2025
0 6
0
6
tomapatan
I'm working with a CSV lookup  that contains multiple fields which may include wildcard (*) values.The lookup is stru...
by tomapatan Contributor in Splunk Search 06-05-2025
0 1
0
1
sabbas
Hello folks,We use Splunk cloud platform (managed by Splunk) for our logging system. We want to implement role based ...
by sabbas Explorer in Splunk Search 06-04-2025
0 1
0
1
sdubey_splunk
Symptoms: It usually happen in the next couple of hours after we manually deleted the stuck search jobs It only happ...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk Search 06-04-2025
0 3
0
3
yeahnah
The xpath command does not work if the XML event contains valid prolog header lines (https://www.w3schools.com/xml/xm...
by yeahnah Motivator in Splunk Search 06-03-2025
0 2
0
2
Raj_Splunk_Ing
Hi,I have this very simple splunk search query and i was able to run in splunk search portal or UI and I am using the...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 10
0
10
Raj_Splunk_Ing
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in itafter ...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 7
0
7
Karthikeya
We are getting this particular error Waiting for queued jobs to start for most of our customers. When they click on m...
by Karthikeya Communicator in Splunk Search 06-03-2025
0 2
0
2
sabbas
Hello folks,We use Splunk cloud platform for our logging system. I was trying to use the Search Filter under the Rest...
by sabbas Explorer in Splunk Search 06-03-2025
0 1
0
1
a212830
Why is | tstats count where index=* by sourcetype so much faster than index=* | stats count by sourcetype ?
by a212830 Champion in Splunk Search 06-01-2025
20 8
20
8
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Solution Authors