Splunk Search

Splunk Search
Community Activity
Wooly
Using Splunk Enterprise 9.4I have created a data source name TimeRange with the SPL Query:| makeresults | addinfo | e...
by Wooly Explorer in Splunk Search 09-08-2025
0 1
0
1
msunilreddy
Hi Team,   We are seeing  error like"user could not act as admin in splunk" for the Rest API call "/servicesNS/admin/...
by msunilreddy New Member in Splunk Search 09-05-2025
0 3
0
3
spisiakmi
Hi, any help, please?Here is the code| makeresults | eval tmp_1=1| eval tmp_2=""| eval tmp_3=3| eval tmp=""| foreach ...
by spisiakmi Contributor in Splunk Search 09-05-2025
0 4
0
4
rafalpachulski
Hey All,Recently, while browsing through Splunk’s official research site, I came across a SPL (Search Processing Lang...
by rafalpachulski Engager in Splunk Search 09-04-2025
0 4
0
4
JossPRG
Hello. I've been trying for days now and can't make the following work. Let me show you what I have.My search looks l...
by JossPRG Engager in Splunk Search 09-01-2025
0 5
0
5
thisemailwillbe
Hi all,Here is my current search:source=health.log REGION=region1 STATE=down TYPE=type1What I want to do: I want the ...
by thisemailwillbe Explorer in Splunk Search 08-29-2025
0 2
0
2
trazomtg
hi,how to correlate event with event correlation rule ? so, how can i write a correlation rule ?Thanks a lot
by trazomtg New Member in Splunk Search 08-29-2025
0 5
0
5
Joey3848
Is there a commonly accepted most efficient method of deleting logs? Occasionally I'll have a use case for deleting l...
by Joey3848 Loves-to-Learn in Splunk Search 08-28-2025
0 12
0
12
spm807
Is there an alternative to IF(<condition>, <true>, <false>) ? I ask because I've got a couple dozen conditions to get...
by spm807 Explorer in Splunk Search 08-27-2025
0 2
0
2
Raj_Splunk_Ing
Hi, I think i am in the right way to use the union concept in splunk search query but wanted to confirm I have 6 diff...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-27-2025
0 14
0
14
koyachi
We are seeing a large discrepancy in field extraction counts between our Prod and Dev environments for sourcetype=xxx...
by koyachi Explorer in Splunk Search 08-27-2025
0 1
0
1
TheJagoff
Hello,The table below are the results from a REST query that shows the installed Apps/TA's from various servers (4 in...
by TheJagoff Communicator in Splunk Search 08-27-2025
0 6
0
6
RobK700000
I am trying to run a daily report that tells me all the indexes that have had 0 events in the past 24 hours. From oth...
by RobK700000 Engager in Splunk Search 08-27-2025
0 3
0
3
sarge338
Good day!I am currently working on a search which provides data from two different event types (connection informatio...
by sarge338 Path Finder in Splunk Search 08-26-2025
0 5
0
5
laytonj76
I have a lookup file in a particular app that I use to enrich data from a particular index. This file, lookup_file.cs...
by laytonj76 Explorer in Splunk Search 08-26-2025
0 9
0
9
Raj_Splunk_Ing
Hi, it might be very simple but i am missing somethingwhen i look at the _time value along with other fields in the s...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-25-2025
0 2
0
2
lucas4394
I wonder how the throttling works if the last pipeline of the search is to redirect the results to different tools/so...
by lucas4394 Path Finder in Splunk Search 08-25-2025
0 2
0
2
dtaylor
Good day, I've been tasked with gathering a list of all users who've accessed an internal site over a couple months. ...
by dtaylor Path Finder in Splunk Search 08-24-2025
0 3
0
3
dtaylor
I'm building out a search to look through email logs. The main search is fine, but I'd like to add fields showing whe...
by dtaylor Path Finder in Splunk Search 08-23-2025
0 3
0
3
RookieSplunker
Hi everyone,I'm looking for some help with a Splunk issue I recently encountered. A user's search job consumed a larg...
by RookieSplunker Engager in Splunk Search 08-22-2025
0 4
0
4
rsruthi48
I'm trying to learn Splunk and i installed the Splunk Free trial version 9.1.2I've been using this free version for o...
by rsruthi48 Observer in Splunk Search 08-22-2025
0 3
0
3
hl
Hello looking for way to create an alert based off the difference between times and only execute if the time is great...
by hl Path Finder in Splunk Search 08-20-2025
0 3
0
3
karol
I got a stream of events in a following format:[ { "name": "event 1" "attributes": ["a", "b"], }, { ...
by karol Engager in Splunk Search 08-19-2025
0 2
0
2
michaelsplunk1
Is there a limit to the number of conditions we can use in a case() statement?I've reached a point where my ORs and A...
by michaelsplunk1 Path Finder in Splunk Search 08-19-2025
1 4
1
4
sabbas
Hi folks,We use Splunk Cloud Platform for our logging needs.We would like to know the following all for the last 9 mo...
by sabbas Explorer in Splunk Search 08-18-2025
0 2
0
2
Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

[Puzzles] Solve, Learn, Repeat: Family Trees

This puzzle (first published here is based on finding grandparents and grandchildren (inspired by a question ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...