Splunk Search

Splunk Search
Community Activity
Raj_Splunk_Ing
Hi,I have this very simple splunk search query and i was able to run in splunk search portal or UI and I am using the...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 10
0
10
Raj_Splunk_Ing
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in itafter ...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 7
0
7
Karthikeya
We are getting this particular error Waiting for queued jobs to start for most of our customers. When they click on m...
by Karthikeya Communicator in Splunk Search 06-03-2025
0 2
0
2
sabbas
Hello folks,We use Splunk cloud platform for our logging system. I was trying to use the Search Filter under the Rest...
by sabbas Explorer in Splunk Search 06-03-2025
0 1
0
1
a212830
Why is | tstats count where index=* by sourcetype so much faster than index=* | stats count by sourcetype ?
by a212830 Champion in Splunk Search 06-01-2025
20 8
20
8
asif_khan1
I am trying to get a list of all services that are in APM. The APM usage report does not provide the name and only pr...
by asif_khan1 New Member in Splunk Search 05-30-2025
0 0
0
0
harshal_chakran
Hi, I am working to list all the index with underlying sourcetypes and sources in it. For which I am currently usin...
by harshal_chakran Builder in Splunk Search 05-30-2025
0 7
0
7
smanojkumar
index=*sap sourcetype=FSC*| fields _time index Eventts ID FIELD_02 FIELD_01 CODE ID FIELD* source| rex field=index "^...
by smanojkumar Contributor in Splunk Search 05-30-2025
0 12
0
12
Pooja1
Hi Team,On May 20th, we successfully migrated from Splunk On-Prem to Splunk Cloud. We have a scheduled search that ru...
by Pooja1 Loves-to-Learn Everything in Splunk Search 05-29-2025
0 2
0
2
mchoudhary
Hi Everyone!I wrote a search query to get the blocked count of emails for last 6months and below is my query-| tstats...
by mchoudhary Explorer in Splunk Search 05-29-2025
0 9
0
9
dtaylor
Hopefully I've only got a small problem this time, but I've had no luck fixing it despite hours of trying. All I'm tr...
by dtaylor Path Finder in Splunk Search 05-28-2025
0 2
0
2
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-28-2025
0 1
0
1
Raj_Splunk_Ing
Hi ,  I have this scenario where i am getting data from one of the index with 2 other specified filters likeindex=ind...
by Raj_Splunk_Ing Path Finder in Splunk Search 05-28-2025
0 5
0
5
robertlynch2020
Hi I have the following data (Below).I have a situation where I want to search for "*" on a search and have it return...
by robertlynch2020 Influencer in Splunk Search 05-28-2025
0 8
0
8
Cheng2Ready
This is what I have setupindex=xxxxxx| eval HDate=strftime(_time,"%Y-%m-%d")| search NOT [ | inputlookup Date_Test.cs...
by Cheng2Ready Communicator in Splunk Search 05-27-2025
0 13
0
13
Benny87
Hi,got some problem in my searches since a few days.I really don´t know what happend and no one changed the configura...
by Benny87 Loves-to-Learn in Splunk Search 05-27-2025
0 7
0
7
ebailey
I have a distributed Splunk instance with the search head separated from the Indexers. I want to drop a CSV file with...
by ebailey Communicator in Splunk Search 05-22-2025
2 10
2
10
SN1
hello So i want to make a search .i am using index=endpoint_defender source="AdvancedHunting-DeviceInfo" | rex field=...
by SN1 Path Finder in Splunk Search 05-22-2025
0 7
0
7
kaeleyt
Situation: I have 2 data sets:Dataset 1 is a set of logs which includes IP addresses. When aggregated, there are 200,...
by kaeleyt Path Finder in Splunk Search 05-22-2025
0 3
0
3
Harikiranjammul
Have a data that returns ip field and values as below.Ip = 0.0.0.11Ip= 0.0.0.12There is a lookup that contains field ...
by Harikiranjammul Explorer in Splunk Search 05-22-2025
0 2
0
2
kn450
Hi Splunk Community,I’m working on a use case where data is stored in Elasticsearch, and I’d like to use Splunk solel...
by kn450 Explorer in Splunk Search 05-21-2025
0 6
0
6
andrewkenth
I have 3 searches that I'm appending. Each returns a Name and Date. Then I take the maximum of each of the Dates and ...
by andrewkenth Communicator in Splunk Search 05-21-2025
0 4
0
4
bvivi57
Hi, I have to search saved as quickly as possible. I CSV indexes whose columns are sometimes empty. I have to put a ...
by bvivi57 Observer in Splunk Search 05-21-2025
0 9
0
9
Jimenez
Hi all, I have the following situation with a query returning a table of this kind:fieldAfieldBA2A2B4B4 I need to add...
by Jimenez Explorer in Splunk Search 05-21-2025
0 3
0
3
Anam
Hello Splunk Community! Welcome to another week of fun curated content as a part of our Splunk Answers Community Cont...
by Community Manager Community Manager in Splunk Search 05-20-2025
2 0
2
0
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...