Splunk Search

Splunk Search
Community Activity
dmoberg
I have a drop-down in my Classic Dashboard that is populating from an inputlookup.Looks like this:<input type="dropdo...
by dmoberg Path Finder in Splunk Search 09-29-2025
0 3
0
3
JHFRDANALYSIS
I'm a novice working in fraud prevention; appreciate your help.  When running the following, I'm getting a failure er...
by JHFRDANALYSIS Engager in Splunk Search 09-27-2025
0 7
0
7
sarge338
Good afternoon.I have been working on this issue for a couple of days, and I just cannot seem to get this SPL correct...
by sarge338 Path Finder in Splunk Search 09-26-2025
0 3
0
3
dmoberg
We have a need to setup Synthetic Browser Tests against many endpoints. The main purpose for the Browser tests is to ...
by dmoberg Path Finder in Splunk Search 09-26-2025
0 1
0
1
HeinzWaescher
Hi, Let's say we have 2 multivalue fields Field1={a,b,c,d} Field2={a,b,c,d,e} Is it possible to evaluate the diff...
by HeinzWaescher Motivator in Splunk Search 09-25-2025
0 9
0
9
hawkeyesc72
I've got a list of over 100 account names and I'd like to search Splunk to find out the most recent activity (if any)...
by hawkeyesc72 Engager in Splunk Search 09-25-2025
0 5
0
5
BacPhan-2005
According to https://community.splunk.com/t5/Splunk-Search/Is-there-a-way-to-instruct-Splunk-to-not-add-quotes-when-p...
by BacPhan-2005 Loves-to-Learn in Splunk Search 09-25-2025
0 1
0
1
cyberpop
I use fieldformat "Date Time"=strftime('Date Time',"%F %T %:z %Z","Asia/Hong Kong"). but it said the syntax is wrong....
by cyberpop Observer in Splunk Search 09-25-2025
0 7
0
7
luffy
I have a regex to extract filename from object field. This works completely fine in Search.index="test" | rex field=o...
by luffy Engager in Splunk Search 09-24-2025
0 1
0
1
weidertc
I have a json from Grafana.| makeresults count=1 | eval json = "{ \"datasources\": { \"ds_a\": {}, \"ds_b\"...
by weidertc Contributor in Splunk Search 09-24-2025
0 5
0
5
BlueHelix
I have a search with a chart that works well but when attempting to save I get the following error message: "Value of...
by BlueHelix New Member in Splunk Search 09-23-2025
0 1
0
1
akarivaratharaj
I am trying to fetch top 10 max Requests count of events with their corresponding response time. So using the below q...
by akarivaratharaj Communicator in Splunk Search 09-23-2025
0 5
0
5
nabeel652
Hello wonderful SplunkersI know we can have a WILDCARD match in a lookup where we can match a key to a wildcard in th...
by nabeel652 Builder in Splunk Search 09-23-2025
0 6
0
6
imst27
Hi,I’m building a search on the Network_Traffic datamodel to detect high outbound flows (>1 GB).I need to exclude a l...
by imst27 Loves-to-Learn Lots in Splunk Search 09-22-2025
0 1
0
1
Ombessam
Here is what I haveNow I want to add a new column like this eval nullPercent = round((nullCount/total)*100, 2) where ...
by Ombessam Path Finder in Splunk Search 09-22-2025
0 4
0
4
whitecat001
Am having issue with a Splunk alert triggering for daily snapshot of aws account ids. The alert is suppose to trigger...
by whitecat001 Explorer in Splunk Search 09-19-2025
0 2
0
2
caschmid
I’m trying to find logs where requestId value is equal to requestId value in another logTrying to find logs like this...
by caschmid Observer in Splunk Search 09-18-2025
0 4
0
4
Walter_Oesch
HelloI have a two multivalue fields: poiMv (point of interest) and timeMv as a result of a transaction command. Both ...
by Walter_Oesch Observer in Splunk Search 09-15-2025
0 2
0
2
Ste
Dear ExpertsMy search: index="pm-azlm_internal_prod_events" sourcetype="azlmj" [| inputlookup pm-azlm-reg-ocp-tea...
by Ste Path Finder in Splunk Search 09-15-2025
0 2
0
2
rdhdr
Hello experts, I have a dashboard in simple xml that shows single number charts which reflect, by host and applicatio...
by rdhdr Explorer in Splunk Search 09-13-2025
0 1
0
1
JHFRDANALYSIS
Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-...
by JHFRDANALYSIS Engager in Splunk Search 09-12-2025
0 1
0
1
sselias
I need to get historical logs from splunk between a time interval more specifically between two dates. When I do not ...
by sselias Engager in Splunk Search 09-12-2025
0 4
0
4
vikashumble
Hello All, I have a multivalue field which contains domain names (for this case, say it is in field named emailDomain...
by vikashumble Explorer in Splunk Search 09-11-2025
0 3
0
3
pt
I am building a correlation search in Splunk ES Cloud 8 using multiple detections combined with append. Each subsearc...
by pt Engager in Splunk Search 09-11-2025
0 2
0
2
asees
I am building a custom Technology Add-on (TA) where I need to silently drop specific events using nullQueue but also ...
by asees Explorer in Splunk Search 09-09-2025
0 5
0
5
Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...