Splunk Search

Splunk Search
Community Activity
wingfieldj
index=endpoint_ms_winevents sourcetype=XmlWinEventLog user=TESTER EventID=4624 OR EventID=4634| stats earliest_time(_...
by wingfieldj Explorer in Splunk Search 12-12-2025
0 6
0
6
Kimiko
Hi Splunk Community,I have created the following SPL for scheduled alerts. Some parts are masked for confidentiality,...
by Kimiko New Member in Splunk Search 12-10-2025
0 4
0
4
RobK700000
I am attempting to rex out some fields from a source log and then if FIELD1 changes in a 24 hour period when the othe...
by RobK700000 Engager in Splunk Search 12-10-2025
0 1
0
1
Sailesh6891
Is it possible to get list of all indexes with creation time and who created the index?
by Sailesh6891 Engager in Splunk Search 12-09-2025
0 3
0
3
msquicc
How can I reliably classify IPv4 and IPv6 addresses as internal vs external?  Requirements:Handle both IPv4 and IPv6V...
by msquicc Path Finder in Splunk Search 12-09-2025
0 1
0
1
mfleitma
Hello,I want to run a datamodel tstats search, excluding some events with a lookup for src_ip's. In case I fill the l...
by mfleitma Explorer in Splunk Search 12-09-2025
0 5
0
5
DaveBunn
I'm trying to set up a regular search to check all our GitHub packages against the latest Shai Hulud npm packages.wit...
by DaveBunn Path Finder in Splunk Search 12-07-2025
0 3
0
3
ashishmgupta
In the below dataset, there are two different ISPs for the user from their usual ones.NordVPN for John and Quadranet ...
by ashishmgupta Explorer in Splunk Search 12-06-2025
0 2
0
2
becksyboy
Hi all,I have a search with a Join. For the event I am Joining the Master search may not always have corresponding ev...
by becksyboy Contributor in Splunk Search 12-04-2025
0 2
0
2
aoliullah
what exactly is a tsidx file? Can someone explain please? I don't quite understand the definition: "A tsidx file as...
by aoliullah Path Finder in Splunk Search 12-02-2025
4 5
4
5
NullZero
Background:I have a client with a large clustered environment, I have recently upgraded it to 9.4.6 and fixed wiredTi...
by NullZero Path Finder in Splunk Search 12-02-2025
0 10
0
10
DashZentin
Hi all,I have setup an LDAP connection to my AD server. But when I click on LDAP Groups, not all groups are displayed...
by DashZentin Explorer in Splunk Search 12-02-2025
0 3
0
3
zakaria1996-cyb
Hi everyone,I'm working with the botsv1 attack-only dataset and I need some guidance on how to approach a few SPL tas...
by zakaria1996-cyb New Member in Splunk Search 11-29-2025
0 1
0
1
karthi2809
Hi All,Thanks in AdvanceI have a requirement we are onboarding CSV files that contain events. I am writing query to d...
by karthi2809 Builder in Splunk Search 11-28-2025
0 4
0
4
dtaylor
I have an alert which filters process creation Windows logs. I'm attempting to add the grandparent process and comman...
by dtaylor Path Finder in Splunk Search 11-27-2025
0 18
0
18
kuul13
I want o create a dashboard for my API response times and TPS for comparison between multiple timeframes. When ever s...
by kuul13 Explorer in Splunk Search 11-26-2025
0 8
0
8
SN1
Hi , I want to make an alert of all the indexes that are receiving 0 events in last 24 hr. Thanks
by SN1 Path Finder in Splunk Search 11-25-2025
0 1
0
1
NAGA4
I have below requirement. I am working on two types of events. Source 1 - From here I wanted to take employee email a...
by NAGA4 Engager in Splunk Search 11-25-2025
0 2
0
2
yuanliu
This happens in one of newly installed 10.0.1 instances.  The only data ingested is tutorialdata.zip from Splunk Tuto...
by SplunkTrust SplunkTrust in Splunk Search 11-25-2025
0 3
0
3
samaG02
Hi all,I’m working with the BOTSv1 dataset in Splunk and I’m trying to solve three tasks.I would appreciate some guid...
by samaG02 Engager in Splunk Search 11-25-2025
0 2
0
2
john789789
Hello, I am running into the "common" issue of duplicated JSON fields. I use Splunk Enterprise 9.2, with an Universal...
by john789789 Observer in Splunk Search 11-22-2025
0 4
0
4
PoojaDevi
I ve came across a post where im trying to fetch the HEC Token via the REST API.When I tried that locally Im getting ...
by PoojaDevi Loves-to-Learn Lots in Splunk Search 11-21-2025
0 4
0
4
Joe_Hartzel
I’ve been working with Splunk recently to improve the way we collect and analyze machine-generated data coming from v...
by Joe_Hartzel Explorer in Splunk Search 11-21-2025
0 0
0
0
esalesapns2
I need to provide feedback on ways logging formats could be improved.To that end, I'm trying to create a search that ...
by esalesapns2 Communicator in Splunk Search 11-21-2025
0 3
0
3
ginagodwin
Can i get help with how i can download the older version of splunk forwader. The 9.0.5 specifically. It's not amongst...
by ginagodwin New Member in Splunk Search 11-20-2025
0 3
0
3
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors