Splunk Search

Splunk Search
Community Activity
yuanliu
I'm really confused about performance related to use of foreach + rename. I have a macro that renames potential name ...
by SplunkTrust SplunkTrust in Splunk Search 02-19-2026
0 2
0
2
corti77
Hi, I am trying to search exact matches inside a multivalue field using the mvfind command. Unfortunately, it uses re...
by corti77 Contributor in Splunk Search 02-18-2026
0 4
0
4
BuzzLights10
Hey Splunkers,I wanted to get a list of all the lookup files on my SH and their file sizes along with other data. I c...
by BuzzLights10 Explorer in Splunk Search 02-18-2026
1 11
1
11
ilhwan
I'm using this command to search dhcp logs and find devices that are new in the last 30 days other than a list of exp...
by ilhwan Path Finder in Splunk Search 02-17-2026
0 4
0
4
wp-uk-36
Hi, Is it possible to hide sort indicators in the headers of a table in Dashboard studio?Thank you
by wp-uk-36 Explorer in Splunk Search 02-16-2026
0 2
0
2
karn
Hello, I created a dashboard with a table and multiple charts. After the table query is finished, I create a token ($...
by karn Path Finder in Splunk Search 02-13-2026
0 1
0
1
fkabell
While tuning a Web Application Firewall (WAF), I'm attempting to filter out all the hostile IP addresses attacking th...
by fkabell New Member in Splunk Search 02-11-2026
0 3
0
3
balcv
I'm trying to work out how I execute a saved search / report using the REST API.  I have created the token and have a...
by balcv Contributor in Splunk Search 02-11-2026
0 2
0
2
rmoon91
Hello Splunk community, I'm ata delimma, Our organiztion is transitioning to an OCI cloud environment so the way we u...
by rmoon91 New Member in Splunk Search 02-11-2026
0 0
0
0
ramuzzini
I have a system user lookup where all users are at least assigned to the GU group but can also be assigned to other g...
by ramuzzini Path Finder in Splunk Search 02-10-2026
0 5
0
5
spisiakmi
Hi, here is the description of the status quo. There is multiselect element defined by a token tkn1. Output variable ...
by spisiakmi Builder in Splunk Search 02-08-2026
0 3
0
3
surekhasplunk
Hi, Am using case statement to sort the fields according to user requirement and not alphabetically. eval sort_fie...
by surekhasplunk Communicator in Splunk Search 02-07-2026
2 5
2
5
kchaitanya
We are trying to create a new Enterprise Security Search head cluster (with latest ES version ), Whats the best way t...
by kchaitanya Explorer in Splunk Search 02-06-2026
1 1
1
1
im_bharath
Is Splunk Universal Forwader 9.2.5 supports to Windows Server 2025 ? Pls confirm. am seeing below in search community...
by im_bharath Path Finder in Splunk Search 02-04-2026
0 1
0
1
NanSplk01
I have a search started, but it's failing to run.  What I want is to eliminate some ID's and only bring back ID's tha...
by NanSplk01 Communicator in Splunk Search 02-03-2026
0 11
0
11
splunknoob4
I have two different searches which each get _time and username.I am trying to append these two searches, and compare...
by splunknoob4 Engager in Splunk Search 02-03-2026
0 12
0
12
karthi2809
Thank in Advance I have three source type Micro, application, CsID and i want to fetch details from these three sourc...
by karthi2809 Builder in Splunk Search 02-02-2026
0 2
0
2
BG_Splunk
Nightly, my organization puts a bunch of pieces of equipment into "maintenance mode" to do repairs and such on them. ...
by BG_Splunk Explorer in Splunk Search 01-28-2026
0 7
0
7
munang
A) index=main 192.168.172.10B) index=main src_ip=192.168.172.10 I thought B) was faster.Because the index is the same...
by munang Path Finder in Splunk Search 01-24-2026
0 2
0
2
JohnsonMarcus
Hi Team,Can someone help me with the Splunk query to input a lookupfile only when there is "no result & "no event"I t...
by JohnsonMarcus Engager in Splunk Search 01-23-2026
0 5
0
5
danielbb
Is there a way to pass a parameter to a report when calling it via -    curl -u user:password -k https://<api_server>...
by danielbb Motivator in Splunk Search 01-22-2026
0 3
0
3
PickleRick
Hello there.I was wondering... is there any way to generate _events_ in search?I mean, I know of the makeresults comm...
by SplunkTrust SplunkTrust in Splunk Search 01-22-2026
0 7
0
7
yuanliu
To groupby?  Or not to groupby?  That is the question. (Not really.  The question arises because trellis splitby seem...
by SplunkTrust SplunkTrust in Splunk Search 01-21-2026
0 2
0
2
SplunkDash
Hello, When I extract fields from the structured XML files using props.conf,  it is not extracted any key/value pairs...
by SplunkDash Motivator in Splunk Search 01-18-2026
0 6
0
6
donaldwayne1976
Which Splunk Technical Application for Microsoft will pull the TLS details for email/Exchange?  Need to be able to re...
by donaldwayne1976 Engager in Splunk Search 01-15-2026
0 2
0
2
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...