Splunk Search

Splunk Search
Community Activity
zakaria1996-cyb
Hi everyone,I'm working with the botsv1 attack-only dataset and I need some guidance on how to approach a few SPL tas...
by zakaria1996-cyb New Member in Splunk Search 11-29-2025
0 1
0
1
karthi2809
Hi All,Thanks in AdvanceI have a requirement we are onboarding CSV files that contain events. I am writing query to d...
by karthi2809 Builder in Splunk Search 11-28-2025
0 4
0
4
dtaylor
I have an alert which filters process creation Windows logs. I'm attempting to add the grandparent process and comman...
by dtaylor Path Finder in Splunk Search 11-27-2025
0 18
0
18
kuul13
I want o create a dashboard for my API response times and TPS for comparison between multiple timeframes. When ever s...
by kuul13 Explorer in Splunk Search 11-26-2025
0 8
0
8
SN1
Hi , I want to make an alert of all the indexes that are receiving 0 events in last 24 hr. Thanks
by SN1 Path Finder in Splunk Search 11-25-2025
0 1
0
1
NAGA4
I have below requirement. I am working on two types of events. Source 1 - From here I wanted to take employee email a...
by NAGA4 Engager in Splunk Search 11-25-2025
0 2
0
2
yuanliu
This happens in one of newly installed 10.0.1 instances.  The only data ingested is tutorialdata.zip from Splunk Tuto...
by SplunkTrust SplunkTrust in Splunk Search 11-25-2025
0 3
0
3
samaG02
Hi all,I’m working with the BOTSv1 dataset in Splunk and I’m trying to solve three tasks.I would appreciate some guid...
by samaG02 Engager in Splunk Search 11-25-2025
0 2
0
2
john789789
Hello, I am running into the "common" issue of duplicated JSON fields. I use Splunk Enterprise 9.2, with an Universal...
by john789789 Observer in Splunk Search 11-22-2025
0 4
0
4
PoojaDevi
I ve came across a post where im trying to fetch the HEC Token via the REST API.When I tried that locally Im getting ...
by PoojaDevi Loves-to-Learn Lots in Splunk Search 11-21-2025
0 4
0
4
Joe_Hartzel
I’ve been working with Splunk recently to improve the way we collect and analyze machine-generated data coming from v...
by Joe_Hartzel Explorer in Splunk Search 11-21-2025
0 0
0
0
esalesapns2
I need to provide feedback on ways logging formats could be improved.To that end, I'm trying to create a search that ...
by esalesapns2 Communicator in Splunk Search 11-21-2025
0 3
0
3
ginagodwin
Can i get help with how i can download the older version of splunk forwader. The 9.0.5 specifically. It's not amongst...
by ginagodwin New Member in Splunk Search 11-20-2025
0 3
0
3
AleCanzo
Hi guys, is there a limit of the number's events returned  in splunk? I'm trying to run a query with inputlookup, but...
by AleCanzo Path Finder in Splunk Search 11-20-2025
0 5
0
5
jwalzerpitt
We are using SCCM to install Splunk Universal Forwarder in our organization and via our Deployment server, I can keep...
by jwalzerpitt Influencer in Splunk Search 11-20-2025
3 2
3
2
danielbb
I sometimes lose the source code of a dashboard, and therefore, I wonder if I can automatically take a backup of my d...
by danielbb Motivator in Splunk Search 11-19-2025
0 2
0
2
ethompso
Every 10 min DMP files and the text document are being created on my drive: C__Program Files_Splunk_bin_splunkd_exe_...
by ethompso Explorer in Splunk Search 11-19-2025
1 6
1
6
Nithiya1
I have file name and file size.I would like to find largest file name.My query:<search>| stats max(File_Size_MB) AS L...
by Nithiya1 Explorer in Splunk Search 11-19-2025
0 3
0
3
DarthHerm
Hopefully this makes some sense.  I am working on a dashboard that pulls up activity when someone clicks on the detai...
by DarthHerm Explorer in Splunk Search 11-17-2025
0 2
0
2
zapping575
I sometimes need to make some changes to my eventtype definitions.However, I do not actually want to edit the query i...
by zapping575 Communicator in Splunk Search 11-17-2025
0 12
0
12
brandonmurphy
I am attempting to identify external IPs that are accessing our servers more than a given number of times each day in...
by brandonmurphy New Member in Splunk Search 11-17-2025
0 8
0
8
snakhuda
Hi there, I have a use case to query internal and external ip addresses of the host which has UF installed. I am usin...
by snakhuda Engager in Splunk Search 11-17-2025
0 13
0
13
athoma31
The ability for many things in Splunk is controlled by capabilities applied to roles/users. In order for a user to ut...
by athoma31 Explorer in Splunk Search 11-17-2025
0 3
0
3
Anders333
Hello, I came across some unexpected search behaviour today.When using the outputlookup command followed by a stats c...
by Anders333 Explorer in Splunk Search 11-16-2025
0 2
0
2
quangtran
I have a Splunk server (Splunk A) with indexes named var_log_***, which contain logs from both UAT and Prod hosts. I’...
by quangtran Explorer in Splunk Search 11-16-2025
0 3
0
3
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Solution Authors