Splunk Search

Splunk Search
Community Activity
verbal_666
Hello.I found out that running a search to find events from 00:00:00 to 23:59:59, when i want H24 all events, using l...
by verbal_666 Builder in Splunk Search 02-22-2026
0 6
0
6
bekirk
index=myindex "event=login" OR "event=logout" | transaction username startswith="event=login" endswith="event=logout...
by bekirk Explorer in Splunk Search 02-21-2026
0 5
0
5
acs12
Hello,How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?My d...
by acs12 Engager in Splunk Search 02-20-2026
0 5
0
5
yuanliu
I'm really confused about performance related to use of foreach + rename. I have a macro that renames potential name ...
by SplunkTrust SplunkTrust in Splunk Search 02-19-2026
0 2
0
2
corti77
Hi, I am trying to search exact matches inside a multivalue field using the mvfind command. Unfortunately, it uses re...
by corti77 Contributor in Splunk Search 02-18-2026
0 4
0
4
BuzzLights10
Hey Splunkers,I wanted to get a list of all the lookup files on my SH and their file sizes along with other data. I c...
by BuzzLights10 Explorer in Splunk Search 02-18-2026
1 11
1
11
ilhwan
I'm using this command to search dhcp logs and find devices that are new in the last 30 days other than a list of exp...
by ilhwan Path Finder in Splunk Search 02-17-2026
0 4
0
4
wp-uk-36
Hi, Is it possible to hide sort indicators in the headers of a table in Dashboard studio?Thank you
by wp-uk-36 Explorer in Splunk Search 02-16-2026
0 2
0
2
karn
Hello, I created a dashboard with a table and multiple charts. After the table query is finished, I create a token ($...
by karn Path Finder in Splunk Search 02-13-2026
0 1
0
1
fkabell
While tuning a Web Application Firewall (WAF), I'm attempting to filter out all the hostile IP addresses attacking th...
by fkabell New Member in Splunk Search 02-11-2026
0 3
0
3
balcv
I'm trying to work out how I execute a saved search / report using the REST API.  I have created the token and have a...
by balcv Contributor in Splunk Search 02-11-2026
0 2
0
2
rmoon91
Hello Splunk community, I'm ata delimma, Our organiztion is transitioning to an OCI cloud environment so the way we u...
by rmoon91 New Member in Splunk Search 02-11-2026
0 0
0
0
ramuzzini
I have a system user lookup where all users are at least assigned to the GU group but can also be assigned to other g...
by ramuzzini Path Finder in Splunk Search 02-10-2026
0 5
0
5
spisiakmi
Hi, here is the description of the status quo. There is multiselect element defined by a token tkn1. Output variable ...
by spisiakmi Contributor in Splunk Search 02-08-2026
0 3
0
3
surekhasplunk
Hi, Am using case statement to sort the fields according to user requirement and not alphabetically. eval sort_fie...
by surekhasplunk Communicator in Splunk Search 02-07-2026
2 5
2
5
kchaitanya
We are trying to create a new Enterprise Security Search head cluster (with latest ES version ), Whats the best way t...
by kchaitanya Explorer in Splunk Search 02-06-2026
1 1
1
1
im_bharath
Is Splunk Universal Forwader 9.2.5 supports to Windows Server 2025 ? Pls confirm. am seeing below in search community...
by im_bharath Path Finder in Splunk Search 02-04-2026
0 1
0
1
NanSplk01
I have a search started, but it's failing to run.  What I want is to eliminate some ID's and only bring back ID's tha...
by NanSplk01 Communicator in Splunk Search 02-03-2026
0 11
0
11
splunknoob4
I have two different searches which each get _time and username.I am trying to append these two searches, and compare...
by splunknoob4 Engager in Splunk Search 02-03-2026
0 12
0
12
karthi2809
Thank in Advance I have three source type Micro, application, CsID and i want to fetch details from these three sourc...
by karthi2809 Builder in Splunk Search 02-02-2026
0 2
0
2
BG_Splunk
Nightly, my organization puts a bunch of pieces of equipment into "maintenance mode" to do repairs and such on them. ...
by BG_Splunk Explorer in Splunk Search 01-28-2026
0 7
0
7
munang
A) index=main 192.168.172.10B) index=main src_ip=192.168.172.10 I thought B) was faster.Because the index is the same...
by munang Path Finder in Splunk Search 01-24-2026
0 2
0
2
JohnsonMarcus
Hi Team,Can someone help me with the Splunk query to input a lookupfile only when there is "no result & "no event"I t...
by JohnsonMarcus Engager in Splunk Search 01-23-2026
0 5
0
5
danielbb
Is there a way to pass a parameter to a report when calling it via -    curl -u user:password -k https://<api_server>...
by danielbb Motivator in Splunk Search 01-22-2026
0 3
0
3
PickleRick
Hello there.I was wondering... is there any way to generate _events_ in search?I mean, I know of the makeresults comm...
by SplunkTrust SplunkTrust in Splunk Search 01-22-2026
0 7
0
7
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Solution Authors