Splunk Search

Splunk Search
Community Activity
tdavison76
Hello,I have a Search that is taking 5 min to complete when looking at only the last 24 hrs.  If possible, could some...
by tdavison76 Path Finder in Splunk Search 05-20-2025
0 5
0
5
sarvesh_11
Hello ,My splunk query is simple: index=abc,source=xxx.trc| transaction host source max events=100000| table _time ho...
by sarvesh_11 Communicator in Splunk Search 05-20-2025
0 14
0
14
mpk_24
Hello @Splunkers,Can someone please help me on this ? Trying to use "lookup/ inputlookup" command in search.Use case:...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 6
0
6
mpk_24
Hey @Splunkers,Looking for valuable insights for this use case. I wanted to extract the numbers at the end of the log...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 2
0
2
te25
Hello. I am working on creating an alert in Splunk for detecting when a firewall stops sending logs. We have all logs...
by te25 Engager in Splunk Search 05-19-2025
0 3
0
3
m_zandinia
Hi Splunkers,I’m running a Splunk Search Head Cluster (SHC) with 3 search heads, authenticated via Active Directory (...
by m_zandinia Path Finder in Splunk Search 05-18-2025
0 16
0
16
tiimo
If you use timewrap without previously using the timechart command, you get a warning "The timewrap command is design...
by tiimo Engager in Splunk Search 05-16-2025
0 4
0
4
Harikiranjammul
Have events like below1) date-TimestampServer - hostnameStatus - host is downThreshold - unable to ping 2) Date-Times...
by Harikiranjammul Explorer in Splunk Search 05-16-2025
0 5
0
5
amit2312
Hi All,I am very new to splunk and faced a issue while extracting a value which is having alphanumeric value, with no...
by amit2312 Explorer in Splunk Search 05-16-2025
0 3
0
3
LearningGuy
Hello,When I clicked open in search, I got the following message:Request-URI Too LongThe requested URL's length excee...
by LearningGuy Motivator in Splunk Search 05-15-2025
0 9
0
9
chinmayc469
Hello, I am getting "Request URI too long error, status 404" because of large splunk query. How to avoid this issue f...
by chinmayc469 Explorer in Splunk Search 05-15-2025
0 4
0
4
srikanth1213
Hello Guys, Can someone help me with a search to list the roles and their capabilities in a Splunk environment?
by srikanth1213 Path Finder in Splunk Search 05-15-2025
0 5
0
5
amit2312
Hi All,I have the log file like below :[Request BEGIN] Session ID - 1234gcy6789rtcd, Request ID - 2605, Source IP - 1...
by amit2312 Explorer in Splunk Search 05-14-2025
0 6
0
6
Iris_Pi
Hello Everyone,I want to check if a field called "from_header_displayname" contains any Unicode.Below is the event so...
by Iris_Pi Path Finder in Splunk Search 05-14-2025
0 4
0
4
Pujarani
Why i am getting error for one of the indexer from indexer cluster while running a report from particular app. Error ...
by Pujarani New Member in Splunk Search 05-13-2025
0 4
0
4
BorrajaX
Hello everyone! In my company, we have Splunk (version 6.0) recording log information about data sent by remote devi...
by BorrajaX Explorer in Splunk Search 05-12-2025
1 6
1
6
jessieb_83
I've never worked with splunk regex before so I'm probably just missing something. I've been up and down  the  https:...
by jessieb_83 Path Finder in Splunk Search 05-12-2025
0 11
0
11
bmer
Hi Team,I have 2 splunks as below(index=xxxx) orgName=xxx sourcetype=CASE(SourceA) earliest=-15d uniqueIdentifier="Cl...
by bmer Explorer in Splunk Search 05-12-2025
0 5
0
5
dtsao
I'm trying to do a transaction using an array.  I need to define the transaction by a value in an array.  However, th...
by dtsao Loves-to-Learn in Splunk Search 05-10-2025
0 3
0
3
k1green97
I am not sure where to start on this. I have 2 fields. Field1 only has a few values while Field2 has many. How can I ...
by k1green97 Engager in Splunk Search 05-10-2025
0 3
0
3
bill
Hello,I am looking to add a particular value to an existing search of Okta data. The problem is I don't know how to e...
by bill Engager in Splunk Search 05-09-2025
0 4
0
4
shawngsharp
I am trying to do a query that will search for arbitrary strings, but will ignore if the string is/isn't in a specifi...
by shawngsharp New Member in Splunk Search 05-09-2025
0 6
0
6
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-09-2025
0 5
0
5
dflynn235
I'm attempting to suppress an alert if a follow up event (condition) is received within 60 seconds of the initial eve...
by dflynn235 Loves-to-Learn in Splunk Search 05-08-2025
0 7
0
7
msarkaus
Hello,I have this Splunk log that contains tons of quotes, commas, and other special characters. I’m trying to only p...
by msarkaus Path Finder in Splunk Search 05-08-2025
0 17
0
17
Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...