Splunk Search

Splunk Search
Community Activity
SN1
| makeresults| eval sourcetype=split("BBCN-Kunshan,BSCN-Suzhou,BBSP-Malasiya,BTCN-Tianjin,BXCN-Xian,BCCN-Suzhouheadqu...
by SN1 Path Finder in Splunk Search 01-12-2026
0 2
0
2
_olivier_
Hi splunkers,I need to decode base64 fields before indexing them.I found a very old post with no good proposal for th...
by _olivier_ Path Finder in Splunk Search 01-09-2026
0 3
0
3
coo
| chart sparkline count by a,bI would like to have sparkline table like...a | b | count | sparklinething1 | fo...
by coo Explorer in Splunk Search 01-08-2026
0 4
0
4
AbuNAM8
I am facin big issue while creating use case on splunk and adding the drill down on the content management. I went to...
by AbuNAM8 New Member in Splunk Search 01-07-2026
0 0
0
0
charliesfx
My splunk server is receiving metrics from collectd. I want to build a table showing the metrics, dimensions, and ...
by charliesfx Explorer in Splunk Search 01-06-2026
5 9
5
9
dinesh001kumar
I need to display the Success percentage for each service day wise.I am doing stats and then table getting output as ...
by dinesh001kumar Explorer in Splunk Search 01-05-2026
0 4
0
4
yuanliu
Riding the coattail of Re: Why is the null value in a JSON event not being parsed properly as NULL?, I constructed tw...
by SplunkTrust SplunkTrust in Splunk Search 01-04-2026
1 4
1
4
Didalready
When I use the search below, the event is 25 days ago, set search to last 30 takes 10 seconds, set to 90 days takes 2...
by Didalready Explorer in Splunk Search 12-29-2025
0 1
0
1
ThuLe
Hello everyone,I am trying to create a custom report that lists Investigations alongside the Notable Events (Findings...
by ThuLe Explorer in Splunk Search 12-29-2025
0 5
0
5
satyaallaparthi
Hi everyone,I need some help with a SPL query.I am trying to create an inventory of all queries running in my dashboa...
by satyaallaparthi Communicator in Splunk Search 12-27-2025
0 9
0
9
dtaylor
I'm working with a search that starts by filtering for all process events in Windows and then sending them to a looku...
by dtaylor Path Finder in Splunk Search 12-26-2025
0 2
0
2
bmer
Hi,Iam using below splunk to help identify least common values of runTime field in myEventRecType file . i get the re...
by bmer Explorer in Splunk Search 12-22-2025
0 4
0
4
andrewpense825
Good day, I often run up against the issue of wanting to drag the text of a field name from the browser into a separa...
by andrewpense825 Explorer in Splunk Search 12-18-2025
1 4
1
4
JohnEGones
Hi Team,I have been trying to work on a query I found on a blog that was trying to calculate and tag a week over week...
by JohnEGones Communicator in Splunk Search 12-17-2025
0 4
0
4
nawazns5038
how can we get the oldest index time of an index ? Does retention policy depend on indextime or _time ?
by nawazns5038 Builder in Splunk Search 12-17-2025
1 20
1
20
bpenny
Executive overview: We're using Splunk Cloud (Victoria Experience), and we're in the process of spinning up a new ins...
by bpenny Explorer in Splunk Search 12-15-2025
0 1
0
1
tscroggins
Hi Splunkers!In the current json_extend documentation <https://help.splunk.com/en/splunk-enterprise/spl-search-refere...
by tscroggins Champion in Splunk Search 12-14-2025
0 5
0
5
zeshan66
Hi everyone!I recently installed splunk and ingested botsv3 dataset through mentioned /etc/apps and gui too. The bots...
by zeshan66 New Member in Splunk Search 12-14-2025
0 1
0
1
agneticdk
Hi guys   I have an installation on Splunk 8.1.2 where we have XmlWinEventLog data ingested. When we run this search:...
by agneticdk Path Finder in Splunk Search 12-12-2025
1 4
1
4
ajmach343
Hello!SOC analyst here. I am looking to build a dashboard that gives data and statistics when an alert in Incident re...
by ajmach343 Explorer in Splunk Search 12-12-2025
0 2
0
2
wingfieldj
index=endpoint_ms_winevents sourcetype=XmlWinEventLog user=TESTER EventID=4624 OR EventID=4634| stats earliest_time(_...
by wingfieldj Explorer in Splunk Search 12-12-2025
0 6
0
6
Kimiko
Hi Splunk Community,I have created the following SPL for scheduled alerts. Some parts are masked for confidentiality,...
by Kimiko New Member in Splunk Search 12-10-2025
0 4
0
4
RobK700000
I am attempting to rex out some fields from a source log and then if FIELD1 changes in a 24 hour period when the othe...
by RobK700000 Engager in Splunk Search 12-10-2025
0 1
0
1
Sailesh6891
Is it possible to get list of all indexes with creation time and who created the index?
by Sailesh6891 Engager in Splunk Search 12-09-2025
0 3
0
3
msquicc
How can I reliably classify IPv4 and IPv6 addresses as internal vs external?  Requirements:Handle both IPv4 and IPv6V...
by msquicc Path Finder in Splunk Search 12-09-2025
0 1
0
1
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...