Splunk Search

Splunk Search
Community Activity
MakszimM
Hello Splunkers!We are at the end of migrating an old deployment, to a new one(C1).So far everything checks out, exce...
by MakszimM Engager in Splunk Search 03-24-2026
0 0
0
0
cipher
Hi,I’ve set up an alert in Splunk that triggers whenever there are log gaps (missing logs) from hosts, based on the R...
by cipher Explorer in Splunk Search 03-23-2026
0 1
0
1
MJ_27
I'm trying to figure out when some of my correlation searches was created ?i tried it with rest, but only getting upd...
by MJ_27 New Member in Splunk Search 03-23-2026
0 3
0
3
imsidrai
i need help in setting up federated search , the requirement is that i want to run some splunk search from dbconnect ...
by imsidrai Explorer in Splunk Search 03-22-2026
0 3
0
3
mcaulsc
I'm trying to create an alert based on a field as shown below, I want to search for the EDC5133I text. However the TE...
by mcaulsc Path Finder in Splunk Search 03-18-2026
0 6
0
6
ManjunathNargun
Team , how to get an extract of threshold values set in Splunk ITSI. Kindly suggest.
by ManjunathNargun New Member in Splunk Search 03-18-2026
0 0
0
0
tpchi
Hi team, There is following errors with my Splunk healtch check. "The number of extremely lagged searches (1) over th...
by tpchi New Member in Splunk Search 03-16-2026
0 7
0
7
dtaylor
If I look at this long enough, I'm sure I'll eventually figure it out, but that could be a whole month at my current ...
by dtaylor Path Finder in Splunk Search 03-14-2026
0 3
0
3
beetlegeuse
I have a dropdown input type in a dashboard that has a token aligned with it (we'll call it $dropdown_value$); the va...
by beetlegeuse Path Finder in Splunk Search 03-11-2026
0 2
0
2
RSS_STT
"resource_id": "/subscriptions/850686fe-9b2b-48ab-81a6-80600a0ca5z1/resourceGroups/vg-weu-ltaprod-rg/providers/Micros...
by RSS_STT Explorer in Splunk Search 03-11-2026
0 5
0
5
mwdbhyat
Hi, How does one upload files larger than 500mb? I get an error "File too large. The file selected is 996Mb. Maximum...
by mwdbhyat Builder in Splunk Search 03-08-2026
0 17
0
17
rob_gibson
I have a LogStash feed coming in, with events containing a string following this example;"message":"Transfer end logg...
by rob_gibson Path Finder in Splunk Search 03-08-2026
0 8
0
8
wp-uk-36
Hi,I've gone through Splunk documentation but still struggle to find an official answer to my question.Given an accel...
by wp-uk-36 Explorer in Splunk Search 03-08-2026
0 2
0
2
Jayhawker1610
I am trying to sign up for the Splunk Core User cert. Where do I find my Splunk ID
by Jayhawker1610 New Member in Splunk Search 03-05-2026
0 1
0
1
Kopcisko
Hello everyone, I would like to ask you for an assistance if possible. Is there a way how to rename an attachment whe...
by Kopcisko Engager in Splunk Search 03-04-2026
0 1
0
1
Siddharthnegi
I have a simple question how can I check that in which of the apps a particular index has been used.
by Siddharthnegi Contributor in Splunk Search 03-03-2026
0 6
0
6
Iris_Pi
Hello Guys,When I click the edit button for the alerts, the "search" input box is grey as showed below, I cannot modi...
by Iris_Pi Path Finder in Splunk Search 03-02-2026
0 2
0
2
JohnsonMarcus
Hi Team,Can someone Kindly help with a rex pattern for the below splunk log.Attached a sample splunk log and rx patte...
by JohnsonMarcus Engager in Splunk Search 02-24-2026
0 1
0
1
markdflip
I saw a feature in Splunk 6.5.0 where you can press a single button in the search bar and it will autoformat the quer...
by markdflip Path Finder in Splunk Search 02-24-2026
7 19
7
19
verbal_666
Hello.I found out that running a search to find events from 00:00:00 to 23:59:59, when i want H24 all events, using l...
by verbal_666 Builder in Splunk Search 02-22-2026
0 6
0
6
bekirk
index=myindex "event=login" OR "event=logout" | transaction username startswith="event=login" endswith="event=logout...
by bekirk Explorer in Splunk Search 02-21-2026
0 5
0
5
acs12
Hello,How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?My d...
by acs12 Engager in Splunk Search 02-20-2026
0 5
0
5
yuanliu
I'm really confused about performance related to use of foreach + rename. I have a macro that renames potential name ...
by SplunkTrust SplunkTrust in Splunk Search 02-19-2026
0 2
0
2
corti77
Hi, I am trying to search exact matches inside a multivalue field using the mvfind command. Unfortunately, it uses re...
by corti77 Contributor in Splunk Search 02-18-2026
0 4
0
4
BuzzLights10
Hey Splunkers,I wanted to get a list of all the lookup files on my SH and their file sizes along with other data. I c...
by BuzzLights10 Explorer in Splunk Search 02-18-2026
1 11
1
11
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...