Splunk Search

Splunk Search
Community Activity
caschmid
I need a query that will tell me the count of a substring within a string like this ..."This is my [string]" and I ne...
by caschmid Observer in Splunk Search 06-10-2025
0 5
0
5
cfernaca
Good afternoon,I have a monitoring architecture with three nodes with the Splunk Enterprise product. One node acts as...
by cfernaca Explorer in Splunk Search 06-10-2025
0 4
0
4
super_edition
Hello Everyone,Below is my splunk query:index="my_index" uri="*/experience/*" | stats count as hits by uri | sort -h...
by super_edition Path Finder in Splunk Search 06-09-2025
0 7
0
7
dashe
Hi,I'm trying to clean up an old splunk cloud instance. one thought that occurred to me is find scheduled searches th...
by dashe Engager in Splunk Search 06-09-2025
0 3
0
3
mchoudhary
Hi Team,I have been observing 1 skipped search error indicating on my CMC. Error is -"The maximum number of concurren...
by mchoudhary Explorer in Splunk Search 06-09-2025
0 2
0
2
jcm
0
2
N3gativeSpace
Here is my code:index=example sourcetype=wineventlog computer_name="example"| transaction computer_name startswith="e...
by N3gativeSpace Engager in Splunk Search 06-05-2025
0 3
0
3
orpiczy
Hi Fellow Splunkers,How can I add multi-value field (array) directly to the index through `/var/spool/splunk`.I tried...
by orpiczy Splunk Employee Splunk Employee in Splunk Search 06-05-2025
0 1
0
1
kn450
opt/caspida/bin/Caspida setuphadoop ...............................Failed to run sudo -u hdfs hdfs namenode -format >...
by kn450 Explorer in Splunk Search 06-05-2025
0 1
0
1
anlePRH
I currently have this to group IPs into subnets and list the counts, I want it to also show the IP it has listed aswe...
by anlePRH Observer in Splunk Search 06-05-2025
0 3
0
3
mchoudhary
Hi everyone!I am working on building a dashboard which captures all the firewall, Web proxy, EDR, WAF, Email, DLP blo...
by mchoudhary Explorer in Splunk Search 06-05-2025
0 6
0
6
tomapatan
I'm working with a CSV lookup  that contains multiple fields which may include wildcard (*) values.The lookup is stru...
by tomapatan Contributor in Splunk Search 06-05-2025
0 1
0
1
sabbas
Hello folks,We use Splunk cloud platform (managed by Splunk) for our logging system. We want to implement role based ...
by sabbas Explorer in Splunk Search 06-04-2025
0 1
0
1
sdubey_splunk
Symptoms: It usually happen in the next couple of hours after we manually deleted the stuck search jobs It only happ...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk Search 06-04-2025
0 3
0
3
yeahnah
The xpath command does not work if the XML event contains valid prolog header lines (https://www.w3schools.com/xml/xm...
by yeahnah Motivator in Splunk Search 06-03-2025
0 2
0
2
Raj_Splunk_Ing
Hi,I have this very simple splunk search query and i was able to run in splunk search portal or UI and I am using the...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 10
0
10
Raj_Splunk_Ing
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in itafter ...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 7
0
7
Karthikeya
We are getting this particular error Waiting for queued jobs to start for most of our customers. When they click on m...
by Karthikeya Communicator in Splunk Search 06-03-2025
0 2
0
2
sabbas
Hello folks,We use Splunk cloud platform for our logging system. I was trying to use the Search Filter under the Rest...
by sabbas Explorer in Splunk Search 06-03-2025
0 1
0
1
a212830
Why is | tstats count where index=* by sourcetype so much faster than index=* | stats count by sourcetype ?
by a212830 Champion in Splunk Search 06-01-2025
20 8
20
8
asif_khan1
I am trying to get a list of all services that are in APM. The APM usage report does not provide the name and only pr...
by asif_khan1 New Member in Splunk Search 05-30-2025
0 0
0
0
harshal_chakran
Hi, I am working to list all the index with underlying sourcetypes and sources in it. For which I am currently usin...
by harshal_chakran Builder in Splunk Search 05-30-2025
0 7
0
7
smanojkumar
index=*sap sourcetype=FSC*| fields _time index Eventts ID FIELD_02 FIELD_01 CODE ID FIELD* source| rex field=index "^...
by smanojkumar Contributor in Splunk Search 05-30-2025
0 12
0
12
Pooja1
Hi Team,On May 20th, we successfully migrated from Splunk On-Prem to Splunk Cloud. We have a scheduled search that ru...
by Pooja1 Loves-to-Learn Everything in Splunk Search 05-29-2025
0 2
0
2
mchoudhary
Hi Everyone!I wrote a search query to get the blocked count of emails for last 6months and below is my query-| tstats...
by mchoudhary Explorer in Splunk Search 05-29-2025
0 9
0
9
Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...