Splunk Search

Splunk Search
Community Activity
BlueHelix
I have a search with a chart that works well but when attempting to save I get the following error message: "Value of...
by BlueHelix New Member in Splunk Search 09-23-2025
0 1
0
1
akarivaratharaj
I am trying to fetch top 10 max Requests count of events with their corresponding response time. So using the below q...
by akarivaratharaj Communicator in Splunk Search 09-23-2025
0 5
0
5
nabeel652
Hello wonderful SplunkersI know we can have a WILDCARD match in a lookup where we can match a key to a wildcard in th...
by nabeel652 Builder in Splunk Search 09-23-2025
0 6
0
6
imst27
Hi,I’m building a search on the Network_Traffic datamodel to detect high outbound flows (>1 GB).I need to exclude a l...
by imst27 Loves-to-Learn in Splunk Search 09-22-2025
0 1
0
1
Ombessam
Here is what I haveNow I want to add a new column like this eval nullPercent = round((nullCount/total)*100, 2) where ...
by Ombessam Path Finder in Splunk Search 09-22-2025
0 4
0
4
whitecat001
Am having issue with a Splunk alert triggering for daily snapshot of aws account ids. The alert is suppose to trigger...
by whitecat001 Explorer in Splunk Search 09-19-2025
0 2
0
2
caschmid
I’m trying to find logs where requestId value is equal to requestId value in another logTrying to find logs like this...
by caschmid Observer in Splunk Search 09-18-2025
0 4
0
4
Walter_Oesch
HelloI have a two multivalue fields: poiMv (point of interest) and timeMv as a result of a transaction command. Both ...
by Walter_Oesch Observer in Splunk Search 09-15-2025
0 2
0
2
Ste
Dear ExpertsMy search: index="pm-azlm_internal_prod_events" sourcetype="azlmj" [| inputlookup pm-azlm-reg-ocp-tea...
by Ste Path Finder in Splunk Search 09-15-2025
0 2
0
2
rdhdr
Hello experts, I have a dashboard in simple xml that shows single number charts which reflect, by host and applicatio...
by rdhdr Explorer in Splunk Search 09-13-2025
0 1
0
1
JHFRDANALYSIS
Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-...
by JHFRDANALYSIS Engager in Splunk Search 09-12-2025
0 1
0
1
sselias
I need to get historical logs from splunk between a time interval more specifically between two dates. When I do not ...
by sselias Engager in Splunk Search 09-12-2025
0 4
0
4
vikashumble
Hello All, I have a multivalue field which contains domain names (for this case, say it is in field named emailDomain...
by vikashumble Explorer in Splunk Search 09-11-2025
0 3
0
3
pt
I am building a correlation search in Splunk ES Cloud 8 using multiple detections combined with append. Each subsearc...
by pt Engager in Splunk Search 09-11-2025
0 2
0
2
asees
I am building a custom Technology Add-on (TA) where I need to silently drop specific events using nullQueue but also ...
by asees Explorer in Splunk Search 09-09-2025
0 5
0
5
Wooly
Using Splunk Enterprise 9.4I have created a data source name TimeRange with the SPL Query:| makeresults | addinfo | e...
by Wooly Explorer in Splunk Search 09-08-2025
0 1
0
1
msunilreddy
Hi Team,   We are seeing  error like"user could not act as admin in splunk" for the Rest API call "/servicesNS/admin/...
by msunilreddy New Member in Splunk Search 09-05-2025
0 3
0
3
spisiakmi
Hi, any help, please?Here is the code| makeresults | eval tmp_1=1| eval tmp_2=""| eval tmp_3=3| eval tmp=""| foreach ...
by spisiakmi Contributor in Splunk Search 09-05-2025
0 4
0
4
rafalpachulski
Hey All,Recently, while browsing through Splunk’s official research site, I came across a SPL (Search Processing Lang...
by rafalpachulski Engager in Splunk Search 09-04-2025
0 4
0
4
JossPRG
Hello. I've been trying for days now and can't make the following work. Let me show you what I have.My search looks l...
by JossPRG Engager in Splunk Search 09-01-2025
0 5
0
5
thisemailwillbe
Hi all,Here is my current search:source=health.log REGION=region1 STATE=down TYPE=type1What I want to do: I want the ...
by thisemailwillbe Explorer in Splunk Search 08-29-2025
0 2
0
2
trazomtg
hi,how to correlate event with event correlation rule ? so, how can i write a correlation rule ?Thanks a lot
by trazomtg New Member in Splunk Search 08-29-2025
0 5
0
5
Joey3848
Is there a commonly accepted most efficient method of deleting logs? Occasionally I'll have a use case for deleting l...
by Joey3848 Loves-to-Learn in Splunk Search 08-28-2025
0 12
0
12
spm807
Is there an alternative to IF(<condition>, <true>, <false>) ? I ask because I've got a couple dozen conditions to get...
by spm807 Explorer in Splunk Search 08-27-2025
0 2
0
2
Raj_Splunk_Ing
Hi, I think i am in the right way to use the union concept in splunk search query but wanted to confirm I have 6 diff...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-27-2025
0 14
0
14
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...