Using Splunk

Using Splunk
Category Activity
tscroggins
Hi Splunkers!In the current json_extend documentation <https://help.splunk.com/en/splunk-enterprise/spl-search-refere...
by tscroggins Influencer in Splunk Search 8 hours ago
0 5
0
5
zeshan66
Hi everyone!I recently installed splunk and ingested botsv3 dataset through mentioned /etc/apps and gui too. The bots...
by zeshan66 New Member in Splunk Search 11 hours ago
0 1
0
1
samp
I'm trying to create SPL so I can enter multiple values on a Domain text filter. For example, I'd like to enter somet...
by samp Engager in Dashboards & Visualizations Friday
0 1
0
1
agneticdk
Hi guys   I have an installation on Splunk 8.1.2 where we have XmlWinEventLog data ingested. When we run this search:...
by agneticdk Path Finder in Splunk Search Friday
1 4
1
4
ajmach343
Hello!SOC analyst here. I am looking to build a dashboard that gives data and statistics when an alert in Incident re...
by ajmach343 Explorer in Splunk Search Friday
0 2
0
2
Souradip11
Hello Splunkers,Is it possible to group events based on a sequence. Event 1 - request , request_id 123Event 2 - respo...
by Souradip11 Explorer in Dashboards & Visualizations Friday
0 7
0
7
wingfieldj
index=endpoint_ms_winevents sourcetype=XmlWinEventLog user=TESTER EventID=4624 OR EventID=4634| stats earliest_time(_...
by wingfieldj Explorer in Splunk Search Friday
0 6
0
6
nelakolundzija
Since Microsoft Teams is deprecated 0365 connectors standard incoming webhooks and usage of MessageType cards for sen...
by nelakolundzija Engager in Alerting Thursday
6 2
6
2
Kimiko
Hi Splunk Community,I have created the following SPL for scheduled alerts. Some parts are masked for confidentiality,...
by Kimiko New Member in Splunk Search Wednesday
0 4
0
4
chrishartsock
Hello all, Certain users in our environment seem to be able to run searches utilizing the "sendemail" command while ...
by chrishartsock Path Finder in Reporting Wednesday
0 5
0
5
bjhenrick
I am new to using Splunk and I am running a report to list all Teams meetings that were recorded over the past 6 mont...
by bjhenrick Engager in Dashboards & Visualizations Wednesday
0 3
0
3
muzicman0
I have created a basic dashboard (I am just learning how all this works) and I am mostly happy with it.  The one issu...
by muzicman0 Loves-to-Learn in Dashboards & Visualizations Wednesday
0 5
0
5
RobK700000
I am attempting to rex out some fields from a source log and then if FIELD1 changes in a 24 hour period when the othe...
by RobK700000 Engager in Splunk Search Wednesday
0 1
0
1
Sailesh6891
Is it possible to get list of all indexes with creation time and who created the index?
by Sailesh6891 Engager in Splunk Search Tuesday
0 3
0
3
msquicc
How can I reliably classify IPv4 and IPv6 addresses as internal vs external?  Requirements:Handle both IPv4 and IPv6V...
by msquicc Path Finder in Splunk Search Tuesday
0 1
0
1
mfleitma
Hello,I want to run a datamodel tstats search, excluding some events with a lookup for src_ip's. In case I fill the l...
by mfleitma Explorer in Splunk Search Tuesday
0 5
0
5
DaveBunn
I'm trying to set up a regular search to check all our GitHub packages against the latest Shai Hulud npm packages.wit...
by DaveBunn Path Finder in Splunk Search a week ago
0 3
0
3
_olivier_
Hi splunkers,I need to decode base64 fields before indexing them.I found a very old post with no good proposal for th...
by _olivier_ Path Finder in Splunk Search a week ago
0 2
0
2
ashishmgupta
In the below dataset, there are two different ISPs for the user from their usual ones.NordVPN for John and Quadranet ...
by ashishmgupta Explorer in Splunk Search a week ago
0 2
0
2
tobelesp
After we upgraded to v9.0.1 we get a warning when following dashboard-generated links pointing "outside" splunk: Re...
by tobelesp Engager in Dashboards & Visualizations a week ago
3 40
3
40
wp-uk-36
Hi,I've got a number of dashboards created with Dashboard studio that need to use the same inputs. As an example, one...
by wp-uk-36 Engager in Dashboards & Visualizations a week ago
0 3
0
3
splunkbeast
Hello Splunk Champs I am trying to do something in studio and stuck with something  If you see the picture, is it pos...
by splunkbeast New Member in Dashboards & Visualizations a week ago
0 1
0
1
becksyboy
Hi all,I have a search with a Join. For the event I am Joining the Master search may not always have corresponding ev...
by becksyboy Contributor in Splunk Search a week ago
0 2
0
2
rororspec
Good Afternoon, This is gonna be fun trying to explain. In essence I have a current report we use to review data tran...
by rororspec Explorer in Alerting 2 weeks ago
0 3
0
3
aoliullah
what exactly is a tsidx file? Can someone explain please? I don't quite understand the definition: "A tsidx file as...
by aoliullah Path Finder in Splunk Search 2 weeks ago
4 5
4
5
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...
Top Karma Authors