Splunk Search

Splunk Search
Community Activity
Darthsplunker
Simple one for you all!I have a query that shows files(cs_uri_stem) on a webserver accessed and the http status codes...
by Darthsplunker Path Finder in Splunk Search 04-07-2026
0 12
0
12
Darkvader
When mapping fields to the CIM in an indexer cluster can I use search time field extractions like IFX, tags and field...
by Darkvader Explorer in Splunk Search 04-07-2026
0 6
0
6
LexSplunker
I know this has always been kind of a sore subject due to the use of the userAccountControl property flags being in s...
by LexSplunker Engager in Splunk Search 04-07-2026
0 2
0
2
manas
Capture in a field from log message and it is in below format : [{"request":"ID1","statusCode":"200"},{"request":"ID2...
by manas Explorer in Splunk Search 04-07-2026
0 4
0
4
cipher
Hi,I’ve set up an alert in Splunk that triggers whenever there are log gaps (missing logs) from hosts, based on the R...
by cipher Explorer in Splunk Search 03-23-2026
0 1
0
1
MJ_27
I'm trying to figure out when some of my correlation searches was created ?i tried it with rest, but only getting upd...
by MJ_27 New Member in Splunk Search 03-23-2026
0 3
0
3
mcaulsc
I'm trying to create an alert based on a field as shown below, I want to search for the EDC5133I text. However the TE...
by mcaulsc Path Finder in Splunk Search 03-18-2026
0 6
0
6
ManjunathNargun
Team , how to get an extract of threshold values set in Splunk ITSI. Kindly suggest.
by ManjunathNargun New Member in Splunk Search 03-18-2026
0 0
0
0
tpchi
Hi team, There is following errors with my Splunk healtch check. "The number of extremely lagged searches (1) over th...
by tpchi New Member in Splunk Search 03-16-2026
0 7
0
7
dtaylor
If I look at this long enough, I'm sure I'll eventually figure it out, but that could be a whole month at my current ...
by dtaylor Path Finder in Splunk Search 03-14-2026
0 3
0
3
beetlegeuse
I have a dropdown input type in a dashboard that has a token aligned with it (we'll call it $dropdown_value$); the va...
by beetlegeuse Path Finder in Splunk Search 03-11-2026
0 2
0
2
RSS_STT
"resource_id": "/subscriptions/850686fe-9b2b-48ab-81a6-80600a0ca5z1/resourceGroups/vg-weu-ltaprod-rg/providers/Micros...
by RSS_STT Explorer in Splunk Search 03-11-2026
0 5
0
5
mwdbhyat
Hi, How does one upload files larger than 500mb? I get an error "File too large. The file selected is 996Mb. Maximum...
by mwdbhyat Builder in Splunk Search 03-08-2026
0 17
0
17
rob_gibson
I have a LogStash feed coming in, with events containing a string following this example;"message":"Transfer end logg...
by rob_gibson Path Finder in Splunk Search 03-08-2026
0 8
0
8
wp-uk-36
Hi,I've gone through Splunk documentation but still struggle to find an official answer to my question.Given an accel...
by wp-uk-36 Explorer in Splunk Search 03-08-2026
0 2
0
2
Jayhawker1610
I am trying to sign up for the Splunk Core User cert. Where do I find my Splunk ID
by Jayhawker1610 New Member in Splunk Search 03-05-2026
0 1
0
1
Kopcisko
Hello everyone, I would like to ask you for an assistance if possible. Is there a way how to rename an attachment whe...
by Kopcisko Engager in Splunk Search 03-04-2026
0 1
0
1
Siddharthnegi
I have a simple question how can I check that in which of the apps a particular index has been used.
by Siddharthnegi Contributor in Splunk Search 03-03-2026
0 6
0
6
Iris_Pi
Hello Guys,When I click the edit button for the alerts, the "search" input box is grey as showed below, I cannot modi...
by Iris_Pi Path Finder in Splunk Search 03-02-2026
0 2
0
2
JohnsonMarcus
Hi Team,Can someone Kindly help with a rex pattern for the below splunk log.Attached a sample splunk log and rx patte...
by JohnsonMarcus Engager in Splunk Search 02-24-2026
0 1
0
1
markdflip
I saw a feature in Splunk 6.5.0 where you can press a single button in the search bar and it will autoformat the quer...
by markdflip Path Finder in Splunk Search 02-24-2026
7 19
7
19
verbal_666
Hello.I found out that running a search to find events from 00:00:00 to 23:59:59, when i want H24 all events, using l...
by verbal_666 Builder in Splunk Search 02-22-2026
0 6
0
6
bekirk
index=myindex "event=login" OR "event=logout" | transaction username startswith="event=login" endswith="event=logout...
by bekirk Explorer in Splunk Search 02-21-2026
0 5
0
5
acs12
Hello,How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?My d...
by acs12 Engager in Splunk Search 02-20-2026
0 5
0
5
yuanliu
I'm really confused about performance related to use of foreach + rename. I have a macro that renames potential name ...
by SplunkTrust SplunkTrust in Splunk Search 02-19-2026
0 2
0
2
Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...