Splunk Search

Splunk Search
Community Activity
dtaylor
Hopefully I've only got a small problem this time, but I've had no luck fixing it despite hours of trying. All I'm tr...
by dtaylor Path Finder in Splunk Search 05-28-2025
0 2
0
2
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-28-2025
0 1
0
1
Raj_Splunk_Ing
Hi ,  I have this scenario where i am getting data from one of the index with 2 other specified filters likeindex=ind...
by Raj_Splunk_Ing Path Finder in Splunk Search 05-28-2025
0 5
0
5
robertlynch2020
Hi I have the following data (Below).I have a situation where I want to search for "*" on a search and have it return...
by robertlynch2020 Influencer in Splunk Search 05-28-2025
0 8
0
8
Cheng2Ready
This is what I have setupindex=xxxxxx| eval HDate=strftime(_time,"%Y-%m-%d")| search NOT [ | inputlookup Date_Test.cs...
by Cheng2Ready Communicator in Splunk Search 05-27-2025
0 13
0
13
Benny87
Hi,got some problem in my searches since a few days.I really don´t know what happend and no one changed the configura...
by Benny87 Loves-to-Learn in Splunk Search 05-27-2025
0 7
0
7
ebailey
I have a distributed Splunk instance with the search head separated from the Indexers. I want to drop a CSV file with...
by ebailey Communicator in Splunk Search 05-22-2025
2 10
2
10
SN1
hello So i want to make a search .i am using index=endpoint_defender source="AdvancedHunting-DeviceInfo" | rex field=...
by SN1 Path Finder in Splunk Search 05-22-2025
0 7
0
7
kaeleyt
Situation: I have 2 data sets:Dataset 1 is a set of logs which includes IP addresses. When aggregated, there are 200,...
by kaeleyt Path Finder in Splunk Search 05-22-2025
0 3
0
3
Harikiranjammul
Have a data that returns ip field and values as below.Ip = 0.0.0.11Ip= 0.0.0.12There is a lookup that contains field ...
by Harikiranjammul Explorer in Splunk Search 05-22-2025
0 2
0
2
kn450
Hi Splunk Community,I’m working on a use case where data is stored in Elasticsearch, and I’d like to use Splunk solel...
by kn450 Explorer in Splunk Search 05-21-2025
0 6
0
6
andrewkenth
I have 3 searches that I'm appending. Each returns a Name and Date. Then I take the maximum of each of the Dates and ...
by andrewkenth Communicator in Splunk Search 05-21-2025
0 4
0
4
bvivi57
Hi, I have to search saved as quickly as possible. I CSV indexes whose columns are sometimes empty. I have to put a ...
by bvivi57 Observer in Splunk Search 05-21-2025
0 9
0
9
Jimenez
Hi all, I have the following situation with a query returning a table of this kind:fieldAfieldBA2A2B4B4 I need to add...
by Jimenez Explorer in Splunk Search 05-21-2025
0 3
0
3
Anam
Hello Splunk Community! Welcome to another week of fun curated content as a part of our Splunk Answers Community Cont...
by Community Manager Community Manager in Splunk Search 05-20-2025
2 0
2
0
tdavison76
Hello,I have a Search that is taking 5 min to complete when looking at only the last 24 hrs.  If possible, could some...
by tdavison76 Path Finder in Splunk Search 05-20-2025
0 5
0
5
sarvesh_11
Hello ,My splunk query is simple: index=abc,source=xxx.trc| transaction host source max events=100000| table _time ho...
by sarvesh_11 Communicator in Splunk Search 05-20-2025
0 14
0
14
mpk_24
Hello @Splunkers,Can someone please help me on this ? Trying to use "lookup/ inputlookup" command in search.Use case:...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 6
0
6
mpk_24
Hey @Splunkers,Looking for valuable insights for this use case. I wanted to extract the numbers at the end of the log...
by mpk_24 Explorer in Splunk Search 05-19-2025
0 2
0
2
te25
Hello. I am working on creating an alert in Splunk for detecting when a firewall stops sending logs. We have all logs...
by te25 Engager in Splunk Search 05-19-2025
0 3
0
3
m_zandinia
Hi Splunkers,I’m running a Splunk Search Head Cluster (SHC) with 3 search heads, authenticated via Active Directory (...
by m_zandinia Path Finder in Splunk Search 05-18-2025
0 16
0
16
tiimo
If you use timewrap without previously using the timechart command, you get a warning "The timewrap command is design...
by tiimo Engager in Splunk Search 05-16-2025
0 4
0
4
Harikiranjammul
Have events like below1) date-TimestampServer - hostnameStatus - host is downThreshold - unable to ping 2) Date-Times...
by Harikiranjammul Explorer in Splunk Search 05-16-2025
0 5
0
5
amit2312
Hi All,I am very new to splunk and faced a issue while extracting a value which is having alphanumeric value, with no...
by amit2312 Explorer in Splunk Search 05-16-2025
0 3
0
3
LearningGuy
Hello,When I clicked open in search, I got the following message:Request-URI Too LongThe requested URL's length excee...
by LearningGuy Motivator in Splunk Search 05-15-2025
0 9
0
9
Get Updates on the Splunk Community!

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...