Splunk Search

Splunk Search
Community Activity
nabeel652
Hello wonderful SplunkersI know we can have a WILDCARD match in a lookup where we can match a key to a wildcard in th...
by nabeel652 Builder in Splunk Search 09-23-2025
0 6
0
6
imst27
Hi,I’m building a search on the Network_Traffic datamodel to detect high outbound flows (>1 GB).I need to exclude a l...
by imst27 Loves-to-Learn Lots in Splunk Search 09-22-2025
0 1
0
1
Ombessam
Here is what I haveNow I want to add a new column like this eval nullPercent = round((nullCount/total)*100, 2) where ...
by Ombessam Path Finder in Splunk Search 09-22-2025
0 4
0
4
whitecat001
Am having issue with a Splunk alert triggering for daily snapshot of aws account ids. The alert is suppose to trigger...
by whitecat001 Explorer in Splunk Search 09-19-2025
0 2
0
2
caschmid
I’m trying to find logs where requestId value is equal to requestId value in another logTrying to find logs like this...
by caschmid Observer in Splunk Search 09-18-2025
0 4
0
4
Walter_Oesch
HelloI have a two multivalue fields: poiMv (point of interest) and timeMv as a result of a transaction command. Both ...
by Walter_Oesch Observer in Splunk Search 09-15-2025
0 2
0
2
Ste
Dear ExpertsMy search: index="pm-azlm_internal_prod_events" sourcetype="azlmj" [| inputlookup pm-azlm-reg-ocp-tea...
by Ste Path Finder in Splunk Search 09-15-2025
0 2
0
2
rdhdr
Hello experts, I have a dashboard in simple xml that shows single number charts which reflect, by host and applicatio...
by rdhdr Explorer in Splunk Search 09-13-2025
0 1
0
1
JHFRDANALYSIS
Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-...
by JHFRDANALYSIS Engager in Splunk Search 09-12-2025
0 1
0
1
sselias
I need to get historical logs from splunk between a time interval more specifically between two dates. When I do not ...
by sselias Engager in Splunk Search 09-12-2025
0 4
0
4
vikashumble
Hello All, I have a multivalue field which contains domain names (for this case, say it is in field named emailDomain...
by vikashumble Explorer in Splunk Search 09-11-2025
0 3
0
3
pt
I am building a correlation search in Splunk ES Cloud 8 using multiple detections combined with append. Each subsearc...
by pt Engager in Splunk Search 09-11-2025
0 2
0
2
asees
I am building a custom Technology Add-on (TA) where I need to silently drop specific events using nullQueue but also ...
by asees Explorer in Splunk Search 09-09-2025
0 5
0
5
Wooly
Using Splunk Enterprise 9.4I have created a data source name TimeRange with the SPL Query:| makeresults | addinfo | e...
by Wooly Explorer in Splunk Search 09-08-2025
0 1
0
1
msunilreddy
Hi Team,   We are seeing  error like"user could not act as admin in splunk" for the Rest API call "/servicesNS/admin/...
by msunilreddy New Member in Splunk Search 09-05-2025
0 3
0
3
spisiakmi
Hi, any help, please?Here is the code| makeresults | eval tmp_1=1| eval tmp_2=""| eval tmp_3=3| eval tmp=""| foreach ...
by spisiakmi Contributor in Splunk Search 09-05-2025
0 4
0
4
rafalpachulski
Hey All,Recently, while browsing through Splunk’s official research site, I came across a SPL (Search Processing Lang...
by rafalpachulski Engager in Splunk Search 09-04-2025
0 4
0
4
JossPRG
Hello. I've been trying for days now and can't make the following work. Let me show you what I have.My search looks l...
by JossPRG Engager in Splunk Search 09-01-2025
0 5
0
5
thisemailwillbe
Hi all,Here is my current search:source=health.log REGION=region1 STATE=down TYPE=type1What I want to do: I want the ...
by thisemailwillbe Explorer in Splunk Search 08-29-2025
0 2
0
2
trazomtg
hi,how to correlate event with event correlation rule ? so, how can i write a correlation rule ?Thanks a lot
by trazomtg New Member in Splunk Search 08-29-2025
0 5
0
5
Joey3848
Is there a commonly accepted most efficient method of deleting logs? Occasionally I'll have a use case for deleting l...
by Joey3848 Loves-to-Learn in Splunk Search 08-28-2025
0 12
0
12
spm807
Is there an alternative to IF(<condition>, <true>, <false>) ? I ask because I've got a couple dozen conditions to get...
by spm807 Explorer in Splunk Search 08-27-2025
0 2
0
2
Raj_Splunk_Ing
Hi, I think i am in the right way to use the union concept in splunk search query but wanted to confirm I have 6 diff...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-27-2025
0 14
0
14
koyachi
We are seeing a large discrepancy in field extraction counts between our Prod and Dev environments for sourcetype=xxx...
by koyachi Explorer in Splunk Search 08-27-2025
0 1
0
1
TheJagoff
Hello,The table below are the results from a REST query that shows the installed Apps/TA's from various servers (4 in...
by TheJagoff Communicator in Splunk Search 08-27-2025
0 6
0
6
Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...