Splunk Search

Splunk Search
Community Activity
amit2312
Hi All,I have the log file like below :[Request BEGIN] Session ID - 1234gcy6789rtcd, Request ID - 2605, Source IP - 1...
by amit2312 Explorer in Splunk Search 05-14-2025
0 6
0
6
Iris_Pi
Hello Everyone,I want to check if a field called "from_header_displayname" contains any Unicode.Below is the event so...
by Iris_Pi Path Finder in Splunk Search 05-14-2025
0 4
0
4
Pujarani
Why i am getting error for one of the indexer from indexer cluster while running a report from particular app. Error ...
by Pujarani New Member in Splunk Search 05-13-2025
0 4
0
4
BorrajaX
Hello everyone! In my company, we have Splunk (version 6.0) recording log information about data sent by remote devi...
by BorrajaX Explorer in Splunk Search 05-12-2025
1 6
1
6
jessieb_83
I've never worked with splunk regex before so I'm probably just missing something. I've been up and down  the  https:...
by jessieb_83 Path Finder in Splunk Search 05-12-2025
0 11
0
11
bmer
Hi Team,I have 2 splunks as below(index=xxxx) orgName=xxx sourcetype=CASE(SourceA) earliest=-15d uniqueIdentifier="Cl...
by bmer Explorer in Splunk Search 05-12-2025
0 5
0
5
dtsao
I'm trying to do a transaction using an array.  I need to define the transaction by a value in an array.  However, th...
by dtsao Loves-to-Learn in Splunk Search 05-10-2025
0 3
0
3
k1green97
I am not sure where to start on this. I have 2 fields. Field1 only has a few values while Field2 has many. How can I ...
by k1green97 Engager in Splunk Search 05-10-2025
0 3
0
3
bill
Hello,I am looking to add a particular value to an existing search of Okta data. The problem is I don't know how to e...
by bill Engager in Splunk Search 05-09-2025
0 4
0
4
shawngsharp
I am trying to do a query that will search for arbitrary strings, but will ignore if the string is/isn't in a specifi...
by shawngsharp New Member in Splunk Search 05-09-2025
0 6
0
6
mint_choco
Hi, I try to display the number of events per day from multiple indexes.I wrote the below SPL, but when all index val...
by mint_choco Explorer in Splunk Search 05-09-2025
0 5
0
5
dflynn235
I'm attempting to suppress an alert if a follow up event (condition) is received within 60 seconds of the initial eve...
by dflynn235 Loves-to-Learn in Splunk Search 05-08-2025
0 7
0
7
msarkaus
Hello,I have this Splunk log that contains tons of quotes, commas, and other special characters. I’m trying to only p...
by msarkaus Path Finder in Splunk Search 05-08-2025
0 17
0
17
u_m1580
Hi there,I would like to create a search to alert us based on an index not ingesting any event data by basing it off ...
by u_m1580 New Member in Splunk Search 05-08-2025
0 2
0
2
LIS
Hi Splunkers :-),We have nice feature it dashboard studio - "Select all matches" in multiselect filter.But, unfortuna...
by LIS Path Finder in Splunk Search 05-07-2025
0 20
0
20
sdanayak
I want to have result in table with 2 or 3 log events combined based on unique key in all events and return 1 single ...
by sdanayak Loves-to-Learn in Splunk Search 05-07-2025
0 9
0
9
Crabbok
I'm trying to track the duration of user sessions to a server.   I want to know WHICH users are connecting, and for h...
by Crabbok Engager in Splunk Search 05-07-2025
0 3
0
3
jialiu907
I am looking for a range of number within my results of my search query but I am getting no results back after adding...
by jialiu907 Path Finder in Splunk Search 05-07-2025
0 12
0
12
Casial06
I'm creating Mutiple Locked account search query while checking the account first if it has 4767 (unlocked) it should...
by Casial06 Explorer in Splunk Search 05-07-2025
0 4
0
4
Alan_Chan
We found that the search job size becomes extremely large during searches. My Splunk instance is a newly installed te...
by Alan_Chan Explorer in Splunk Search 05-07-2025
0 1
0
1
Harikiranjammul
I am running tstats command with span of 2hrs for index and source.It returns the data for every 2hrs.But I want to i...
by Harikiranjammul Explorer in Splunk Search 05-06-2025
0 4
0
4
irfanarif
Hi, I completed a course titled “Intro to Superman Mission Control” earlier, but it no longer appears in the free cou...
by irfanarif Engager in Splunk Search 05-06-2025
0 2
0
2
jat75
I have a search where I am doing 2 inputlookups for 2 different lookups and appending them. Then I search them. Can I...
by jat75 Explorer in Splunk Search 05-06-2025
0 1
0
1
timgren
Id like to create table of results, and convert each row into an unordered bullet list using html. Such as: | table r...
by timgren Path Finder in Splunk Search 05-06-2025
0 1
0
1
Jessydan
Hello,I'm working on a Splunk query to track REST calls in our logs. Specifically, I’m trying to use the transaction ...
by Jessydan Explorer in Splunk Search 05-05-2025
0 10
0
10
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...