Splunk Search

Splunk Search
Community Activity
artkhod
Hi,I haven't seen the acceleration mentioned anywhere in regards to SPL2.I have saved a sample search as a report for...
by artkhod New Member in Splunk Search 05-07-2026
0 1
0
1
zapping575
My goal is to solve the following:I have what I consider "starting" events. They contain the string "to FAIL".I have ...
by zapping575 Communicator in Splunk Search 05-05-2026
0 6
0
6
wp-uk-36
Hi,From time to time I make typos in field names in my Splunk SPL searches and very rightly Splunk returns nothing in...
by wp-uk-36 Explorer in Splunk Search 04-25-2026
1 6
1
6
kjain041523
Hi, I need a splunk query to find the license utilization per host per day in last 4 months, to know which host/serve...
by kjain041523 Observer in Splunk Search 04-21-2026
0 3
0
3
SN1
I have admin role in splunk , I was able to edit alert searches before but now i am not able to do so. 
by SN1 Path Finder in Splunk Search 04-20-2026
0 4
0
4
sdk32
hi Every one i am new to splunk , but here my query goes:Sample Data and json : {id: 1 , executor: "executor1" , time...
by sdk32 Engager in Splunk Search 04-19-2026
1 4
1
4
Kobi998
Hi,I’d appreciate your help extracting attachments/notes that users add to Findings (Mission Control) for reporting p...
by Kobi998 New Member in Splunk Search 04-18-2026
0 1
0
1
BradOH
Hey community, another weird question.  We have scheduled reports which use dbxlookups to enrich the data for analysi...
by BradOH Path Finder in Splunk Search 04-17-2026
0 3
0
3
koyachi
Hi All,We have been experiencing intermittent indexing delays on our Splunk environment, which consists of three stan...
by koyachi Explorer in Splunk Search 04-15-2026
0 3
0
3
manchou0709
Hi everyone, I am trying to find out index name , sourcetype for 100+  (128) hosts. Since I am working in a multisite...
by manchou0709 Explorer in Splunk Search 04-14-2026
0 2
0
2
Poojary
I am using n8n automation to fetch information from a Splunk search. However, when I use the n8n node, I get an authe...
by Poojary New Member in Splunk Search 04-12-2026
0 3
0
3
splunkreal
Hello,when using index=si_cisco we get results however if we add index=si_cisco sourcetype="cisco:ise:syslog" then no...
by splunkreal Influencer in Splunk Search 04-08-2026
0 8
0
8
Darthsplunker
Simple one for you all!I have a query that shows files(cs_uri_stem) on a webserver accessed and the http status codes...
by Darthsplunker Path Finder in Splunk Search 04-07-2026
0 12
0
12
Darkvader
When mapping fields to the CIM in an indexer cluster can I use search time field extractions like IFX, tags and field...
by Darkvader Explorer in Splunk Search 04-07-2026
0 6
0
6
LexSplunker
I know this has always been kind of a sore subject due to the use of the userAccountControl property flags being in s...
by LexSplunker Engager in Splunk Search 04-07-2026
0 2
0
2
manas
Capture in a field from log message and it is in below format : [{"request":"ID1","statusCode":"200"},{"request":"ID2...
by manas Explorer in Splunk Search 04-07-2026
0 4
0
4
cipher
Hi,I’ve set up an alert in Splunk that triggers whenever there are log gaps (missing logs) from hosts, based on the R...
by cipher Explorer in Splunk Search 03-23-2026
0 1
0
1
MJ_27
I'm trying to figure out when some of my correlation searches was created ?i tried it with rest, but only getting upd...
by MJ_27 New Member in Splunk Search 03-23-2026
0 3
0
3
mcaulsc
I'm trying to create an alert based on a field as shown below, I want to search for the EDC5133I text. However the TE...
by mcaulsc Path Finder in Splunk Search 03-18-2026
0 6
0
6
ManjunathNargun
Team , how to get an extract of threshold values set in Splunk ITSI. Kindly suggest.
by ManjunathNargun New Member in Splunk Search 03-18-2026
0 0
0
0
tpchi
Hi team, There is following errors with my Splunk healtch check. "The number of extremely lagged searches (1) over th...
by tpchi New Member in Splunk Search 03-16-2026
0 7
0
7
dtaylor
If I look at this long enough, I'm sure I'll eventually figure it out, but that could be a whole month at my current ...
by dtaylor Path Finder in Splunk Search 03-14-2026
0 3
0
3
beetlegeuse
I have a dropdown input type in a dashboard that has a token aligned with it (we'll call it $dropdown_value$); the va...
by beetlegeuse Path Finder in Splunk Search 03-11-2026
0 2
0
2
RSS_STT
"resource_id": "/subscriptions/850686fe-9b2b-48ab-81a6-80600a0ca5z1/resourceGroups/vg-weu-ltaprod-rg/providers/Micros...
by RSS_STT Explorer in Splunk Search 03-11-2026
0 5
0
5
mwdbhyat
Hi, How does one upload files larger than 500mb? I get an error "File too large. The file selected is 996Mb. Maximum...
by mwdbhyat Builder in Splunk Search 03-08-2026
0 17
0
17
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...