Splunk Search

Splunk Search
Community Activity
SN1
hello i have this search| inputlookup lkp-all-findings| lookup lkp-findings-blacklist.csv blfinding as finding OUTPUT...
by SN1 Path Finder in Splunk Search 03-27-2025
0 8
0
8
feichinger
I do have a solution for this, but I just wonder if there is a more straight forward approach to get a better underst...
by feichinger Path Finder in Splunk Search 03-27-2025
0 1
0
1
doniaelansasy
I’ve encountered an issue while working on a configuration for a Splunk deployment. I was creating a stanza in the in...
by doniaelansasy Loves-to-Learn Lots in Splunk Search 03-26-2025
0 11
0
11
DATT
I have a field that I need to search on that is a long string of comma-separated values.  It comes from our vulnerabi...
by DATT Path Finder in Splunk Search 03-26-2025
0 5
0
5
rvsroe
In the fundamentals 1 course lab 8 tells us to: "As a best practice and for best performance, place dedup as early in...
by rvsroe Explorer in Splunk Search 03-26-2025
0 6
0
6
HX
I would like to get the number of hosts per index in the last 7 days, the query as below gave me the format but not t...
by HX Engager in Splunk Search 03-26-2025
0 3
0
3
ayomotukoya
I have the below search and I want to modify it to get the bandwidth utilization percentage. Whats the best way to go...
by ayomotukoya Explorer in Splunk Search 03-26-2025
0 10
0
10
ramuzzini
Need help cleaning up my rex command line with data delineated by (,) then extracting the value after the (=) charact...
by ramuzzini Path Finder in Splunk Search 03-25-2025
0 3
0
3
b17gunnr
 Hello folks,I have a series of event results which take the format as shown below: appDisplayName: foo appId: f...
by b17gunnr Path Finder in Splunk Search 03-25-2025
0 3
0
3
reswob4
I have a problem where I cannot remotely access the web interface (not via HTTPS or HTTP on either 8000 or 8089) of o...
by reswob4 Builder in Splunk Search 03-25-2025
0 3
0
3
SN1
Hello I am running searchindex=_introspectiondedup host table hostin result i am not able to see one indexer and one ...
by SN1 Path Finder in Splunk Search 03-25-2025
0 6
0
6
secure
Hi everyonei have a dataset| makeresults| eval APP1="appdelta", hostname1= mvappend("syzhost.domain1","abchost.domain...
by secure Path Finder in Splunk Search 03-24-2025
0 2
0
2
gcoles
This might be a silly question, but has anyone figured out how to add line breaks to text that has been evaluated wit...
by gcoles Communicator in Splunk Search 03-24-2025
11 16
11
16
shimada-k
Hi Experts,I have the following data. {<!-- -->"TIMESTAMP": 1742677200,"SYSINFO": "{\"number_of_notconnect_interfaces\":0,\"h...
by shimada-k Explorer in Splunk Search 03-24-2025
0 6
0
6
kiwiglen
I have an index with a list of transactions, the transactions in the system start as 1 process with a transaction num...
by kiwiglen Observer in Splunk Search 03-23-2025
0 11
0
11
nithys
Hi I have dashboard with Data Entity drop down ,i want to add a drop drown "ALL" ,if i select ALL and hit submit butt...
by nithys Communicator in Splunk Search 03-23-2025
0 3
0
3
molla
Hi Splunkers, I would like to display a count divided by several locations on a map. On the map, I would like only th...
by molla Explorer in Splunk Search 03-23-2025
0 2
0
2
b17gunnr
Hello folks,I trying to use a base search within a dashboard but it consistently returns no results. However, when I ...
by b17gunnr Path Finder in Splunk Search 03-21-2025
0 6
0
6
Ombessam
Hello guys,I have a dashboard  with two tabs. I've added a dropdown input and I'm going to add more inputs. But I wan...
by Ombessam Path Finder in Splunk Search 03-21-2025
0 3
0
3
stefanlasiewski
I am using the Interactive field extractor to try and extract certain fields. However, regular expressions are tricky...
by stefanlasiewski Contributor in Splunk Search 03-20-2025
1 7
1
7
secure
i have a list of hostnames being generated from left join for different application in multivalue table columnAPP1hos...
by secure Path Finder in Splunk Search 03-20-2025
0 7
0
7
parumugam
I am using Splunk Observability Cloud for Kubernetes monitoring and trying to retrieve data for container CPU limits ...
by parumugam Observer in Splunk Search 03-20-2025
0 1
0
1
majlo333
Hi,I have a query that goes something like this:index&#61;myindex | eval urgency&#61;"medium", account_name&#61;'awsMetadata.acco...
by majlo333 Observer in Splunk Search 03-20-2025
0 1
0
1
Braagi
So, have a timechart with multiple streams.Call them X, Y, and Z.Run the panel for a 4h timeframe.I want to click a p...
by Braagi Explorer in Splunk Search 03-20-2025
0 2
0
2
mrdeterville
Hi SMEs;I'd like to convert the following date format into epoch:  yyyymmdd. E.g 20220508.Any assistance would be app...
by mrdeterville Explorer in Splunk Search 03-19-2025
0 1
0
1
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...