Splunk Search

Splunk Search
Community Activity
SplunkWorthy
I am attempting to use the transaction field to identify when a  service fails and then the next time it runs success...
by SplunkWorthy Loves-to-Learn Lots in Splunk Search 06-16-2026
0 11
0
11
ekb
We recently moved some inputs from universal forwarders to a pair of heavy forwarders for pre-processing. Since then ...
by ekb Engager in Splunk Search 06-15-2026
0 2
0
2
gsbpp
search  | rex field=_raw "id=\"(?<id>[^\"]*)"| stats count by id | where count > 1 I just want to consider the total ...
by gsbpp Explorer in Splunk Search 06-08-2026
0 1
0
1
MakszimM
Hello Splunkers!We are at the end of migrating an old deployment, to a new one(C1).So far everything checks out, exce...
by MakszimM Engager in Splunk Search 06-01-2026
0 1
0
1
Dolly
Hello everyone, I am facing an issue related to a Splunk user role. A role was created with access to indexes 1, 2, 3...
by Dolly Explorer in Splunk Search 05-22-2026
0 5
0
5
MonkeyK
My engineers are using OpenTelemetry and somehow that results in only getting metadata from a source.  So unlike usua...
by MonkeyK Builder in Splunk Search 05-19-2026
0 4
0
4
amangeli
Hi Everyone,I need help getting past a license lock. My Enterprise trial expired and I moved it to a Free license. Th...
by amangeli New Member in Splunk Search 05-15-2026
0 3
0
3
Cheng2Ready
Hi guys just need some brain picking How can I create an alert that monitors for errors that persist for more than 2 ...
by Cheng2Ready Communicator in Splunk Search 05-15-2026
0 9
0
9
castle1126
I've read and used the REGEX commands in this URL: http://answers.splunk.com/questions/8028/extracting-domain-name-ou...
by castle1126 Communicator in Splunk Search 05-12-2026
2 5
2
5
hawkeyesc72
I want to build a small dashboard that offers a quick view into emails a user has recently received. If I use this, I...
by hawkeyesc72 Engager in Splunk Search 05-11-2026
0 9
0
9
pruthviraj_k_m
Hi,I just wanted to know, is it possible to track the status change in any of the notables? If so, which log source(i...
by pruthviraj_k_m Explorer in Splunk Search 05-11-2026
0 12
0
12
Ombessam
count retail sales events for strategy games I can't find categoryId field by default from the search tutorial data. ...
by Ombessam Path Finder in Splunk Search 05-09-2026
0 4
0
4
artkhod
Hi,I haven't seen the acceleration mentioned anywhere in regards to SPL2.I have saved a sample search as a report for...
by artkhod New Member in Splunk Search 05-07-2026
0 1
0
1
zapping575
My goal is to solve the following:I have what I consider "starting" events. They contain the string "to FAIL".I have ...
by zapping575 Communicator in Splunk Search 05-05-2026
0 6
0
6
wp-uk-36
Hi,From time to time I make typos in field names in my Splunk SPL searches and very rightly Splunk returns nothing in...
by wp-uk-36 Explorer in Splunk Search 04-25-2026
1 6
1
6
kjain041523
Hi, I need a splunk query to find the license utilization per host per day in last 4 months, to know which host/serve...
by kjain041523 Observer in Splunk Search 04-21-2026
0 3
0
3
SN1
I have admin role in splunk , I was able to edit alert searches before but now i am not able to do so. 
by SN1 Path Finder in Splunk Search 04-20-2026
0 4
0
4
sdk32
hi Every one i am new to splunk , but here my query goes:Sample Data and json : {id: 1 , executor: "executor1" , time...
by sdk32 Engager in Splunk Search 04-19-2026
1 4
1
4
Kobi998
Hi,I’d appreciate your help extracting attachments/notes that users add to Findings (Mission Control) for reporting p...
by Kobi998 New Member in Splunk Search 04-18-2026
0 1
0
1
BradOH
Hey community, another weird question.  We have scheduled reports which use dbxlookups to enrich the data for analysi...
by BradOH Path Finder in Splunk Search 04-17-2026
0 3
0
3
koyachi
Hi All,We have been experiencing intermittent indexing delays on our Splunk environment, which consists of three stan...
by koyachi Explorer in Splunk Search 04-15-2026
0 3
0
3
manchou0709
Hi everyone, I am trying to find out index name , sourcetype for 100+  (128) hosts. Since I am working in a multisite...
by manchou0709 Explorer in Splunk Search 04-14-2026
0 2
0
2
Poojary
I am using n8n automation to fetch information from a Splunk search. However, when I use the n8n node, I get an authe...
by Poojary New Member in Splunk Search 04-12-2026
0 3
0
3
splunkreal
Hello,when using index=si_cisco we get results however if we add index=si_cisco sourcetype="cisco:ise:syslog" then no...
by splunkreal Influencer in Splunk Search 04-08-2026
0 8
0
8
Darthsplunker
Simple one for you all!I have a query that shows files(cs_uri_stem) on a webserver accessed and the http status codes...
by Darthsplunker Path Finder in Splunk Search 04-07-2026
0 12
0
12
Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...