Splunk Search

Splunk Search
Community Activity
jwalzerpitt
We are using SCCM to install Splunk Universal Forwarder in our organization and via our Deployment server, I can keep...
by jwalzerpitt Influencer in Splunk Search 11-20-2025
3 2
3
2
danielbb
I sometimes lose the source code of a dashboard, and therefore, I wonder if I can automatically take a backup of my d...
by danielbb Motivator in Splunk Search 11-19-2025
0 2
0
2
ethompso
Every 10 min DMP files and the text document are being created on my drive: C__Program Files_Splunk_bin_splunkd_exe_...
by ethompso Explorer in Splunk Search 11-19-2025
1 6
1
6
Nithiya1
I have file name and file size.I would like to find largest file name.My query:<search>| stats max(File_Size_MB) AS L...
by Nithiya1 Explorer in Splunk Search 11-19-2025
0 3
0
3
DarthHerm
Hopefully this makes some sense.  I am working on a dashboard that pulls up activity when someone clicks on the detai...
by DarthHerm Explorer in Splunk Search 11-17-2025
0 2
0
2
zapping575
I sometimes need to make some changes to my eventtype definitions.However, I do not actually want to edit the query i...
by zapping575 Path Finder in Splunk Search 11-17-2025
0 12
0
12
brandonmurphy
I am attempting to identify external IPs that are accessing our servers more than a given number of times each day in...
by brandonmurphy New Member in Splunk Search 11-17-2025
0 8
0
8
snakhuda
Hi there, I have a use case to query internal and external ip addresses of the host which has UF installed. I am usin...
by snakhuda Engager in Splunk Search 11-17-2025
0 13
0
13
athoma31
The ability for many things in Splunk is controlled by capabilities applied to roles/users. In order for a user to ut...
by athoma31 Explorer in Splunk Search 11-17-2025
0 3
0
3
Anders333
Hello, I came across some unexpected search behaviour today.When using the outputlookup command followed by a stats c...
by Anders333 Explorer in Splunk Search 11-16-2025
0 2
0
2
quangtran
I have a Splunk server (Splunk A) with indexes named var_log_***, which contain logs from both UAT and Prod hosts. I’...
by quangtran Explorer in Splunk Search 11-16-2025
0 3
0
3
Gregski11
I must admit what is happening makes no sense. Take this error for example:[OurIndexer01,OurIndexer02,OurIndexer03] C...
by Gregski11 Contributor in Splunk Search 11-13-2025
0 2
0
2
wu_weidong
Hi, I am trying to ingest long JSON files into my Splunk index, where a record could contain more than 10000 characte...
by wu_weidong Path Finder in Splunk Search 11-12-2025
0 9
0
9
lady_bl00dst0n3
some datasets are large and when configuring an spl and changing the time range picker, it triggers the search to run...
by lady_bl00dst0n3 New Member in Splunk Search 11-11-2025
0 3
0
3
dtaylor
Unfortunately, I've hit the limit of my Splunk knowledge again, and I need some help. I'm attempting to write a searc...
by dtaylor Path Finder in Splunk Search 11-09-2025
0 1
0
1
chimuru84
Hello. I have an index="index", and if I add a field to the search, such as index="index" errorCode, I retrieve logs ...
by chimuru84 Path Finder in Splunk Search 11-05-2025
0 10
0
10
hank72
Hi community,When using datamodels, is it possible to remove/exclude the portion of the autoextractSearch: | search (...
by hank72 Path Finder in Splunk Search 11-04-2025
0 6
0
6
hl
index=web host!="*TEST*" | rare limit=10 http_user_agent,c_ip,src,X_Forwarded_For,host ```|lookup static_assets ip as...
by hl Path Finder in Splunk Search 11-03-2025
0 3
0
3
Ted-Splunk
There is an async process that logs first when something is created, then again when it is picked up by a service tha...
by Ted-Splunk Engager in Splunk Search 10-31-2025
0 2
0
2
jodros
In our environment, we have a CIFS share that is used to store all colddb. Warm is rolled to cold when the hot/warm ...
by jodros Builder in Splunk Search 10-30-2025
0 8
0
8
jariw
Hello,   i try to understand the "fast mode" compared to the "smart" and "verbose mode" in relation to field extracti...
by jariw Path Finder in Splunk Search 10-29-2025
0 11
0
11
sdk32
hi Every one i am new to splunk , but here my query goes:Sample Data and json : {id: 1 , executor: "executor1" , time...
by sdk32 Engager in Splunk Search 10-27-2025
1 3
1
3
josemanm12
I understand that it is currently possible to schedule the export of a Dashboard Studio dashboard in PDF or PNG forma...
by josemanm12 Engager in Splunk Search 10-27-2025
0 2
0
2
dm1
 10-27-2025 03:21:21.006 WARN  AuthorizationManager [28813 MainThread] - Capability 'use_file_operator' is not recogn...
by dm1 Contributor in Splunk Search 10-27-2025
0 2
0
2
JanYang
I am using the deployment server to push configurations to the search heads. All the .conf files are successfully dep...
by JanYang Loves-to-Learn Lots in Splunk Search 10-23-2025
0 12
0
12
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...
Top Solution Authors