Splunk Search

Splunk Search
Community Activity
DionisMjeku
I've noticed in the last days, after the deployment process is done we are having some problems when making searches ...
by DionisMjeku Engager in Splunk Search 10-15-2025
0 3
0
3
cogh3o
Help me with splunk query to monitor CPU and Memory utilized by splunk adhoc and alert searches
by cogh3o New Member in Splunk Search 10-15-2025
0 2
0
2
chandrasekhar46
i have json event in that some fields not extracting properly when i am table i am not getting some field after messa...
by chandrasekhar46 Loves-to-Learn Everything in Splunk Search 10-15-2025
0 6
0
6
Splunked_Kid
Hi Splunk Community,I'm working on a search that analyzes an index containing records of file activity. Each event in...
by Splunked_Kid Explorer in Splunk Search 10-14-2025
0 5
0
5
jfmph_
All,Anybody got idea on the below selected fields on how convert to FQDN? Seems lookups/dnslookup are not possible be...
by jfmph_ Explorer in Splunk Search 10-14-2025
0 6
0
6
JandrevdM
Good day, It's been a while. I am trying to join two indexes together to see if a ticket has been logged based on the...
by JandrevdM Path Finder in Splunk Search 10-11-2025
0 5
0
5
mchoudhary
Hi,Can someone help me understand how to add a new column to an exisiting lookup (its a kvstore lookup) using the loo...
by mchoudhary Explorer in Splunk Search 10-09-2025
0 3
0
3
SN1
so i have a index paloalto and a lookup file both have 1 field common app , now i want app which are present in looku...
by SN1 Path Finder in Splunk Search 10-09-2025
0 3
0
3
bigchungusfan55
I've been tasked with developing my organization's asset and identity lookups for Splunk ES.I am using managed lookup...
by bigchungusfan55 Explorer in Splunk Search 10-07-2025
0 2
0
2
ww9rivers
I created a search filter that looks like this:(index=web NOT status=404) OR (index!=web)which works to limit the rol...
by ww9rivers Contributor in Splunk Search 10-06-2025
0 9
0
9
daniel333
All, Is it possble to display a list of fields for an index? Something like this? index=java | dedup fields | ta...
by daniel333 Builder in Splunk Search 10-02-2025
1 13
1
13
brent_weaver
I am reading the documentation to create a simple search script: #!/usr/bin/env python import os import sys import ...
by brent_weaver Builder in Splunk Search 10-02-2025
0 1
0
1
GattyBiggz
index="*azure*" UserId="*#EXT#*" earliest=-300d@d latest=now| eval activity_time = coalesce(strptime(CreationTime, "%...
by GattyBiggz Loves-to-Learn in Splunk Search 10-01-2025
0 12
0
12
NanSplk01
| rest splunk_server=* /services/data/indexes| fields title currentDBSizeMB lastIngestTime| eval Bytes = round(coales...
by NanSplk01 Communicator in Splunk Search 09-29-2025
0 4
0
4
dmoberg
I have a drop-down in my Classic Dashboard that is populating from an inputlookup.Looks like this:<input type="dropdo...
by dmoberg Path Finder in Splunk Search 09-29-2025
0 3
0
3
JHFRDANALYSIS
I'm a novice working in fraud prevention; appreciate your help.  When running the following, I'm getting a failure er...
by JHFRDANALYSIS Engager in Splunk Search 09-27-2025
0 7
0
7
sarge338
Good afternoon.I have been working on this issue for a couple of days, and I just cannot seem to get this SPL correct...
by sarge338 Path Finder in Splunk Search 09-26-2025
0 3
0
3
dmoberg
We have a need to setup Synthetic Browser Tests against many endpoints. The main purpose for the Browser tests is to ...
by dmoberg Path Finder in Splunk Search 09-26-2025
0 1
0
1
HeinzWaescher
Hi, Let's say we have 2 multivalue fields Field1={a,b,c,d} Field2={a,b,c,d,e} Is it possible to evaluate the diff...
by HeinzWaescher Motivator in Splunk Search 09-25-2025
0 9
0
9
hawkeyesc72
I've got a list of over 100 account names and I'd like to search Splunk to find out the most recent activity (if any)...
by hawkeyesc72 Engager in Splunk Search 09-25-2025
0 5
0
5
BacPhan-2005
According to https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-instruct-Splunk-to-not-add-quotes-when-p...
by BacPhan-2005 Loves-to-Learn in Splunk Search 09-25-2025
0 1
0
1
cyberpop
I use fieldformat "Date Time"=strftime('Date Time',"%F %T %:z %Z","Asia/Hong Kong"). but it said the syntax is wrong....
by cyberpop Observer in Splunk Search 09-25-2025
0 7
0
7
luffy
I have a regex to extract filename from object field. This works completely fine in Search.index="test" | rex field=o...
by luffy Engager in Splunk Search 09-24-2025
0 1
0
1
weidertc
I have a json from Grafana.| makeresults count=1 | eval json = "{ \"datasources\": { \"ds_a\": {}, \"ds_b\"...
by weidertc Contributor in Splunk Search 09-24-2025
0 5
0
5
BlueHelix
I have a search with a chart that works well but when attempting to save I get the following error message: "Value of...
by BlueHelix New Member in Splunk Search 09-23-2025
0 1
0
1
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...