Splunk Search

Splunk Search
Community Activity
Soonerseast
Hi my data is comma delimited   , there  are 2 rows with a header. I'fd like the columns to be split by the comma int...
by Soonerseast Loves-to-Learn in Splunk Search 06-13-2025
0 3
0
3
rishabhpatel20
Hello, I have lookup file uploaded and now I want to see the data, I am not able to see it on map , I can see the det...
by rishabhpatel20 Explorer in Splunk Search 06-13-2025
0 2
0
2
AleCanzo
Hi, i'm searching for a way to modify my app/dashboard to be able to modify the entries of a table (such as delete/du...
by AleCanzo Explorer in Splunk Search 06-13-2025
0 2
0
2
cdevoe57
I have a query that detects missing systems.  the lookup table has fields System, Location, responsible.I am trying t...
by cdevoe57 Path Finder in Splunk Search 06-12-2025
0 8
0
8
ripvw32
I have the below query I've written - I am used to SQL, SPL is still new to me. I feel like there has to be some way ...
by ripvw32 Explorer in Splunk Search 06-12-2025
0 5
0
5
Cybers1
Hi Splunk Community,We’re currently trying to drop specific logs using props.conf and transforms.conf, but our config...
by Cybers1 Engager in Splunk Search 06-11-2025
0 5
0
5
Kemark
Does splunk support fill-forward or "last observation carried forward".I want to create a daily based monitoring.One ...
by Kemark Explorer in Splunk Search 06-11-2025
0 10
0
10
AleCanzo
Hi, this is my first interaction with Splunk Community so be patient please  I'm trying to output some fields from a...
by AleCanzo Explorer in Splunk Search 06-11-2025
0 3
0
3
caschmid
I need a query that will tell me the count of a substring within a string like this ..."This is my [string]" and I ne...
by caschmid Observer in Splunk Search 06-10-2025
0 5
0
5
cfernaca
Good afternoon,I have a monitoring architecture with three nodes with the Splunk Enterprise product. One node acts as...
by cfernaca Explorer in Splunk Search 06-10-2025
0 4
0
4
super_edition
Hello Everyone,Below is my splunk query:index="my_index" uri="*/experience/*" | stats count as hits by uri | sort -h...
by super_edition Path Finder in Splunk Search 06-09-2025
0 7
0
7
dashe
Hi,I'm trying to clean up an old splunk cloud instance. one thought that occurred to me is find scheduled searches th...
by dashe Engager in Splunk Search 06-09-2025
0 3
0
3
mchoudhary
Hi Team,I have been observing 1 skipped search error indicating on my CMC. Error is -"The maximum number of concurren...
by mchoudhary Explorer in Splunk Search 06-09-2025
0 2
0
2
jcm
0
2
N3gativeSpace
Here is my code:index=example sourcetype=wineventlog computer_name="example"| transaction computer_name startswith="e...
by N3gativeSpace Engager in Splunk Search 06-05-2025
0 3
0
3
orpiczy
Hi Fellow Splunkers,How can I add multi-value field (array) directly to the index through `/var/spool/splunk`.I tried...
by orpiczy Splunk Employee Splunk Employee in Splunk Search 06-05-2025
0 1
0
1
kn450
opt/caspida/bin/Caspida setuphadoop ...............................Failed to run sudo -u hdfs hdfs namenode -format >...
by kn450 Explorer in Splunk Search 06-05-2025
0 1
0
1
anlePRH
I currently have this to group IPs into subnets and list the counts, I want it to also show the IP it has listed aswe...
by anlePRH Observer in Splunk Search 06-05-2025
0 3
0
3
mchoudhary
Hi everyone!I am working on building a dashboard which captures all the firewall, Web proxy, EDR, WAF, Email, DLP blo...
by mchoudhary Explorer in Splunk Search 06-05-2025
0 6
0
6
tomapatan
I'm working with a CSV lookup  that contains multiple fields which may include wildcard (*) values.The lookup is stru...
by tomapatan Contributor in Splunk Search 06-05-2025
0 1
0
1
sabbas
Hello folks,We use Splunk cloud platform (managed by Splunk) for our logging system. We want to implement role based ...
by sabbas Explorer in Splunk Search 06-04-2025
0 1
0
1
sdubey_splunk
Symptoms: It usually happen in the next couple of hours after we manually deleted the stuck search jobs It only happ...
by sdubey_splunk Splunk Employee Splunk Employee in Splunk Search 06-04-2025
0 3
0
3
yeahnah
The xpath command does not work if the XML event contains valid prolog header lines (https://www.w3schools.com/xml/xm...
by yeahnah Motivator in Splunk Search 06-03-2025
0 2
0
2
Raj_Splunk_Ing
Hi,I have this very simple splunk search query and i was able to run in splunk search portal or UI and I am using the...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 10
0
10
Raj_Splunk_Ing
Hi, I have this field in this format and i am using eval to convert but sometimes there is an extra space in itafter ...
by Raj_Splunk_Ing Path Finder in Splunk Search 06-03-2025
0 7
0
7
Claim a $25 Cisco Store Gift Card
Help us improve the Splunk Community and complete our survey today!
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...