Splunk Search

Splunk Search
Community Activity
samaG02
Hi all,I’m working with the BOTSv1 dataset in Splunk and I’m trying to solve three tasks.I would appreciate some guid...
by samaG02 Engager in Splunk Search 11-25-2025
0 2
0
2
john789789
Hello, I am running into the "common" issue of duplicated JSON fields. I use Splunk Enterprise 9.2, with an Universal...
by john789789 Observer in Splunk Search 11-22-2025
0 4
0
4
PoojaDevi
I ve came across a post where im trying to fetch the HEC Token via the REST API.When I tried that locally Im getting ...
by PoojaDevi Loves-to-Learn Lots in Splunk Search 11-21-2025
0 4
0
4
Joe_Hartzel
I’ve been working with Splunk recently to improve the way we collect and analyze machine-generated data coming from v...
by Joe_Hartzel Explorer in Splunk Search 11-21-2025
0 0
0
0
esalesapns2
I need to provide feedback on ways logging formats could be improved.To that end, I'm trying to create a search that ...
by esalesapns2 Communicator in Splunk Search 11-21-2025
0 3
0
3
ginagodwin
Can i get help with how i can download the older version of splunk forwader. The 9.0.5 specifically. It's not amongst...
by ginagodwin New Member in Splunk Search 11-20-2025
0 3
0
3
AleCanzo
Hi guys, is there a limit of the number's events returned  in splunk? I'm trying to run a query with inputlookup, but...
by AleCanzo Path Finder in Splunk Search 11-20-2025
0 5
0
5
jwalzerpitt
We are using SCCM to install Splunk Universal Forwarder in our organization and via our Deployment server, I can keep...
by jwalzerpitt Influencer in Splunk Search 11-20-2025
3 2
3
2
danielbb
I sometimes lose the source code of a dashboard, and therefore, I wonder if I can automatically take a backup of my d...
by danielbb Motivator in Splunk Search 11-19-2025
0 2
0
2
ethompso
Every 10 min DMP files and the text document are being created on my drive: C__Program Files_Splunk_bin_splunkd_exe_...
by ethompso Explorer in Splunk Search 11-19-2025
1 6
1
6
Nithiya1
I have file name and file size.I would like to find largest file name.My query:<search>| stats max(File_Size_MB) AS L...
by Nithiya1 Explorer in Splunk Search 11-19-2025
0 3
0
3
DarthHerm
Hopefully this makes some sense.  I am working on a dashboard that pulls up activity when someone clicks on the detai...
by DarthHerm Explorer in Splunk Search 11-17-2025
0 2
0
2
zapping575
I sometimes need to make some changes to my eventtype definitions.However, I do not actually want to edit the query i...
by zapping575 Communicator in Splunk Search 11-17-2025
0 12
0
12
brandonmurphy
I am attempting to identify external IPs that are accessing our servers more than a given number of times each day in...
by brandonmurphy New Member in Splunk Search 11-17-2025
0 8
0
8
snakhuda
Hi there, I have a use case to query internal and external ip addresses of the host which has UF installed. I am usin...
by snakhuda Engager in Splunk Search 11-17-2025
0 13
0
13
athoma31
The ability for many things in Splunk is controlled by capabilities applied to roles/users. In order for a user to ut...
by athoma31 Explorer in Splunk Search 11-17-2025
0 3
0
3
Anders333
Hello, I came across some unexpected search behaviour today.When using the outputlookup command followed by a stats c...
by Anders333 Explorer in Splunk Search 11-16-2025
0 2
0
2
quangtran
I have a Splunk server (Splunk A) with indexes named var_log_***, which contain logs from both UAT and Prod hosts. I’...
by quangtran Explorer in Splunk Search 11-16-2025
0 3
0
3
Gregski11
I must admit what is happening makes no sense. Take this error for example:[OurIndexer01,OurIndexer02,OurIndexer03] C...
by Gregski11 Contributor in Splunk Search 11-13-2025
0 2
0
2
wu_weidong
Hi, I am trying to ingest long JSON files into my Splunk index, where a record could contain more than 10000 characte...
by wu_weidong Path Finder in Splunk Search 11-12-2025
0 9
0
9
lady_bl00dst0n3
some datasets are large and when configuring an spl and changing the time range picker, it triggers the search to run...
by lady_bl00dst0n3 New Member in Splunk Search 11-11-2025
0 3
0
3
dtaylor
Unfortunately, I've hit the limit of my Splunk knowledge again, and I need some help. I'm attempting to write a searc...
by dtaylor Path Finder in Splunk Search 11-09-2025
0 1
0
1
chimuru84
Hello. I have an index="index", and if I add a field to the search, such as index="index" errorCode, I retrieve logs ...
by chimuru84 Path Finder in Splunk Search 11-05-2025
0 10
0
10
hank72
Hi community,When using datamodels, is it possible to remove/exclude the portion of the autoextractSearch: | search (...
by hank72 Path Finder in Splunk Search 11-04-2025
0 6
0
6
hl
index=web host!="*TEST*" | rare limit=10 http_user_agent,c_ip,src,X_Forwarded_For,host ```|lookup static_assets ip as...
by hl Path Finder in Splunk Search 11-03-2025
0 3
0
3
Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...
Top Solution Authors