Splunk Search

Splunk Search
Community Activity
ganesanvc
Hi all,I'm trying to dynamically replace single backslashes with double backslashes in a search string and use the re...
by ganesanvc Engager in Splunk Search 04-25-2025
0 12
0
12
chartastic
We use a custom app in our Splunk Cloud instance to segregate dashboards and searches from other teams. With the rece...
by chartastic Explorer in Splunk Search 04-25-2025
0 17
0
17
CMAzurdia
Good afternoon Splunk Team,I have my search query: index=example_mine  host=x.x.x.x  [ | inputlookup  myfiile.csv | r...
by CMAzurdia Engager in Splunk Search 04-24-2025
0 5
0
5
mbasharat
Hi all,I have a situation. Below is my search. Search needs to produce past 6 months of report. The goal is to produc...
by mbasharat Builder in Splunk Search 04-24-2025
0 4
0
4
SN1
So  i have a dashboard and in drilldown i am showing severity in the servers now i want whenever the severity is solv...
by SN1 Path Finder in Splunk Search 04-24-2025
0 6
0
6
CMAzurdia
Hello Splunk team,I need a search query that can pull data back of successful and unsuccessful login attempts of user...
by CMAzurdia Engager in Splunk Search 04-23-2025
0 4
0
4
sverdhan
Hello guys, I need a splunk query that list out all the alerts that have index=* in their query. Unfortunately, I can...
by sverdhan Loves-to-Learn Lots in Splunk Search 04-23-2025
0 4
0
4
Zoe_
anybody have experience for building an automation to import CSV from  github location into Splunk lookup file, CSV f...
by Zoe_ Observer in Splunk Search 04-23-2025
0 2
0
2
amitrinx
I am currently working with data from SendGrid Event API that is being ingested into Splunk. The data includes multip...
by amitrinx Explorer in Splunk Search 04-23-2025
0 3
0
3
rob_gibson
I'm running a very simple search to draw a table. One of the values returned is appearing twice in the table, but on...
by rob_gibson Path Finder in Splunk Search 04-22-2025
0 9
0
9
lguinn2
The manual entry for the metadata command says "...in environments with large numbers of values per category, the da...
by Legend in Splunk Search 04-22-2025
2 27
2
27
Zhangyy
Use iplocation or geostats to display within a range of 100 kilometers (with longitude of 0.89 degrees and latitude o...
by Zhangyy New Member in Splunk Search 04-22-2025
0 6
0
6
LearningGuy
Hello,How to display JSON tree structure in a summary index without output_mode=hec?I am not a Splunk admin. So, the ...
by LearningGuy Motivator in Splunk Search 04-22-2025
0 1
0
1
bilalzaib
Hi, We are using the event field message in our alert, but in some cases, the field is not being parsed correctly. Fo...
by bilalzaib Engager in Splunk Search 04-21-2025
0 3
0
3
ravi_lookout
I have a few records in the splunk like this{"timeStamp":"2025-04-21T08:21:40.000Z","eventId":"test_eventId_1","orign...
by ravi_lookout Explorer in Splunk Search 04-21-2025
0 2
0
2
MrGlass
I am trying to locate some data between two indexes, the common items are the src_interface and the network device na...
by MrGlass Explorer in Splunk Search 04-19-2025
0 7
0
7
Das
I need to calculate time difference between start and end times. But I get the difference value as null. Not sure wha...
by Das Engager in Splunk Search 04-18-2025
0 2
0
2
LearningGuy
Hello,How to create sample JSON data and display it in tree structure?I used makeresults to create sample JSON data b...
by LearningGuy Motivator in Splunk Search 04-18-2025
0 7
0
7
ranandeshi
Hello,I would like some help to convert the TAI64N format to "%m/%d/%Y %H:%M:%S", I tried to use following query:| ma...
by ranandeshi New Member in Splunk Search 04-18-2025
0 4
0
4
marksheinbaum
I have events like the following. The filed jobName contains "(W6) Power Quality Read - MT - IR Meters Pascal" delimi...
by marksheinbaum Explorer in Splunk Search 04-17-2025
0 3
0
3
RSS_STT
I want to transpose the below row to column.Hostdrive_Nameutilization aaaD20 bbbD30 aaaE60  want to covert above tabl...
by RSS_STT Explorer in Splunk Search 04-17-2025
0 2
0
2
Abass42
I have some Netskope data. Searching it goes something like this:index=testing sourcetype="netskope:application" dlp_...
by Abass42 Communicator in Splunk Search 04-16-2025
0 2
0
2
Flynt
From my search flashtimeline I can tell my search head in a distributed environment to only use the local lookup file...
by Flynt Splunk Employee Splunk Employee in Splunk Search 04-15-2025
6 5
6
5
robertlynch2020
How do I split the below data into 2 lines? I need to run stats on the tables, but when they are together the answers...
by robertlynch2020 Influencer in Splunk Search 04-15-2025
0 8
0
8
JNgoho
How can we Stop Docker from sending these logs?We recently disable the ingestion from Docker to Splunk on the Splunk ...
by JNgoho Engager in Splunk Search 04-15-2025
0 3
0
3
Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...
Top Solution Authors