Splunk Search

Splunk Search
Community Activity
AL3Z
Hi,Could if anyone pls share the dashboard spl for the lateral movement in this YouTube video.https://youtu.be/bCCf9q...
by AL3Z Builder in Splunk Search 03-16-2024
0 1
0
1
anoop
Dear team,  Good day! Hope you are doing well.  I need some help in understanding a correlation search. The search is...
by anoop Loves-to-Learn Lots in Splunk Search 03-15-2024
0 5
0
5
LearningGuy
Hello,How to modify _time when running summary index on a scheduled search?Please suggest. I appreciate your help. Th...
by LearningGuy Motivator in Splunk Search 03-15-2024
0 9
0
9
karthi2809
Hello to all, I have a multivalue field with a content.errormsg with values and also with a null value. If the null v...
by karthi2809 Builder in Splunk Search 03-15-2024
0 2
0
2
bigll
I want to create statistic per group of device rather than individual devices.I tried eval, but it produced no result...
by bigll Path Finder in Splunk Search 03-15-2024
0 6
0
6
dataisbeautiful
I'm trying to build a query to give real time results for a value, but the is a time delay between the data send and ...
by dataisbeautiful Communicator in Splunk Search 03-15-2024
0 5
0
5
Ginzoa
Hello! I have tried a lot of options to solve this, but nothing has worked so far. I have a single panel, with 3 el...
by Ginzoa Explorer in Splunk Search 03-15-2024
0 3
0
3
HankinAlex
Is there a way to change the _time field of imported data to be a custom extracted datetime field?Or at least some wa...
by HankinAlex Explorer in Splunk Search 03-14-2024
0 10
0
10
mahesh27
i have a dashboard, In that there is a drop down for services.we have 10 panels in a dashboard.When i select service ...
by mahesh27 Communicator in Splunk Search 03-14-2024
0 1
0
1
lembark
Q: Given a "timechart span=1m sep='-" last(foo) as foo last( bar) as bar by  hostname", how would I get a unique valu...
by lembark Loves-to-Learn in Splunk Search 03-14-2024
0 8
0
8
binay2634
Hi all I am trying to join two queries but unable to get the expected result.I am using join command to extract usern...
by binay2634 Explorer in Splunk Search 03-14-2024
0 7
0
7
anil1219
Hi,I want to extract value c611b43d-a574-4636-9116-ec45fe8090f8 from below.Could you please let me know how I can do ...
by anil1219 Engager in Splunk Search 03-14-2024
0 2
0
2
CoryC
I am trying to create a dashboard to examine group policy processing errors.  I would like to create a drop-down base...
by CoryC Engager in Splunk Search 03-14-2024
0 4
0
4
uagraw01
From last two days I am not receiving data in my Splunk internal index.  Please help me understand this issue . 
by uagraw01 Motivator in Splunk Search 03-14-2024
0 16
0
16
jeradb
<row> <panel depends="$tok_tab_1$"> <table> <title>Alerts Fired</title> <search> ...
by jeradb Explorer in Splunk Search 03-14-2024
0 1
0
1
cjharmening
Hello, Looking for some real guidance here. We just implemented Splunk with an Implementation team. We are pulling ou...
by cjharmening Loves-to-Learn Lots in Splunk Search 03-14-2024
0 1
0
1
BeautyData
Good afternoon everyone, I need your help in this way. I have a stats sum with the wild card *|appendpipe [stats sum(...
by BeautyData Explorer in Splunk Search 03-14-2024
0 7
0
7
sle
I'm trying to create a workload management rule to prevent users from searching with "All Time". After researching, i...
by sle Engager in Splunk Search 03-14-2024
0 2
0
2
abhi04
Hi All,   How can I optimize the below query? Can we convert it to tstats?   index=abc host=def* stalled | rex field=...
by abhi04 Communicator in Splunk Search 03-13-2024
0 3
0
3
splunkuser320
I am trying to use parameter into the search using IN condition.  Query is retuning results if I put data directly in...
by splunkuser320 Path Finder in Splunk Search 03-13-2024
0 8
0
8
Deprasad
I've below 3 different types of API logs where I've to treat all 3 as same and get the count of the API.There are mul...
by Deprasad Path Finder in Splunk Search 03-13-2024
0 5
0
5
ipoluda
Hello!I have a log that shows locking/unlocking PCs:1710320306,u09,unlocked1710320356,u09,locked1710320360,u10,unlock...
by ipoluda Explorer in Splunk Search 03-13-2024
0 1
0
1
Splunk-Star
We have a Splunk Dashboard for our Team in Splunk  Cluster. Almost every report item is having exclamation symbol and...
by Splunk-Star Loves-to-Learn Lots in Splunk Search 03-13-2024
0 2
0
2
Tron-spectron47
if i had to write a document for myself on basic learning of splunk: to create a dashboard i can either use inputs li...
by Tron-spectron47 Loves-to-Learn in Splunk Search 03-13-2024
0 3
0
3
Splunk-Star
On splunk user is getting the following error:Could not load lookup=LOOKUP-pp_vms  but admin is not getting any such ...
by Splunk-Star Loves-to-Learn Lots in Splunk Search 03-13-2024
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...