Splunk Search

Splunk Search
Community Activity
rdhdr
Hello experts, I have a dashboard in simple xml that shows single number charts which reflect, by host and applicatio...
by rdhdr Explorer in Splunk Search 09-13-2025
0 1
0
1
JHFRDANALYSIS
Error in my results query:  Unable to distribute to peer named 10.245.11.153 at uri=10.245.11.153:8089 using the uri-...
by JHFRDANALYSIS Engager in Splunk Search 09-12-2025
0 1
0
1
sselias
I need to get historical logs from splunk between a time interval more specifically between two dates. When I do not ...
by sselias Engager in Splunk Search 09-12-2025
0 4
0
4
vikashumble
Hello All, I have a multivalue field which contains domain names (for this case, say it is in field named emailDomain...
by vikashumble Explorer in Splunk Search 09-11-2025
0 3
0
3
pt
I am building a correlation search in Splunk ES Cloud 8 using multiple detections combined with append. Each subsearc...
by pt Engager in Splunk Search 09-11-2025
0 2
0
2
asees
I am building a custom Technology Add-on (TA) where I need to silently drop specific events using nullQueue but also ...
by asees Explorer in Splunk Search 09-09-2025
0 5
0
5
Wooly
Using Splunk Enterprise 9.4I have created a data source name TimeRange with the SPL Query:| makeresults | addinfo | e...
by Wooly Explorer in Splunk Search 09-08-2025
0 1
0
1
msunilreddy
Hi Team,   We are seeing  error like"user could not act as admin in splunk" for the Rest API call "/servicesNS/admin/...
by msunilreddy New Member in Splunk Search 09-05-2025
0 3
0
3
spisiakmi
Hi, any help, please?Here is the code| makeresults | eval tmp_1=1| eval tmp_2=""| eval tmp_3=3| eval tmp=""| foreach ...
by spisiakmi Builder in Splunk Search 09-05-2025
0 4
0
4
rafalpachulski
Hey All,Recently, while browsing through Splunk’s official research site, I came across a SPL (Search Processing Lang...
by rafalpachulski Engager in Splunk Search 09-04-2025
0 4
0
4
JossPRG
Hello. I've been trying for days now and can't make the following work. Let me show you what I have.My search looks l...
by JossPRG Engager in Splunk Search 09-01-2025
0 5
0
5
thisemailwillbe
Hi all,Here is my current search:source=health.log REGION=region1 STATE=down TYPE=type1What I want to do: I want the ...
by thisemailwillbe Explorer in Splunk Search 08-29-2025
0 2
0
2
trazomtg
hi,how to correlate event with event correlation rule ? so, how can i write a correlation rule ?Thanks a lot
by trazomtg New Member in Splunk Search 08-29-2025
0 5
0
5
Joey3848
Is there a commonly accepted most efficient method of deleting logs? Occasionally I'll have a use case for deleting l...
by Joey3848 Loves-to-Learn in Splunk Search 08-28-2025
0 12
0
12
spm807
Is there an alternative to IF(<condition>, <true>, <false>) ? I ask because I've got a couple dozen conditions to get...
by spm807 Explorer in Splunk Search 08-27-2025
0 2
0
2
Raj_Splunk_Ing
Hi, I think i am in the right way to use the union concept in splunk search query but wanted to confirm I have 6 diff...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-27-2025
0 14
0
14
koyachi
We are seeing a large discrepancy in field extraction counts between our Prod and Dev environments for sourcetype=xxx...
by koyachi Explorer in Splunk Search 08-27-2025
0 1
0
1
TheJagoff
Hello,The table below are the results from a REST query that shows the installed Apps/TA's from various servers (4 in...
by TheJagoff Communicator in Splunk Search 08-27-2025
0 6
0
6
RobK700000
I am trying to run a daily report that tells me all the indexes that have had 0 events in the past 24 hours. From oth...
by RobK700000 Engager in Splunk Search 08-27-2025
0 3
0
3
sarge338
Good day!I am currently working on a search which provides data from two different event types (connection informatio...
by sarge338 Path Finder in Splunk Search 08-26-2025
0 5
0
5
laytonj76
I have a lookup file in a particular app that I use to enrich data from a particular index. This file, lookup_file.cs...
by laytonj76 Explorer in Splunk Search 08-26-2025
0 9
0
9
Raj_Splunk_Ing
Hi, it might be very simple but i am missing somethingwhen i look at the _time value along with other fields in the s...
by Raj_Splunk_Ing Path Finder in Splunk Search 08-25-2025
0 2
0
2
lucas4394
I wonder how the throttling works if the last pipeline of the search is to redirect the results to different tools/so...
by lucas4394 Path Finder in Splunk Search 08-25-2025
0 2
0
2
dtaylor
Good day, I've been tasked with gathering a list of all users who've accessed an internal site over a couple months. ...
by dtaylor Path Finder in Splunk Search 08-24-2025
0 3
0
3
dtaylor
I'm building out a search to look through email logs. The main search is fine, but I'd like to add fields showing whe...
by dtaylor Path Finder in Splunk Search 08-23-2025
0 3
0
3
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Solution Authors