Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

123K Members 1,616 Online 158K Posts

Join us for a 4-part series on Full-Stack Observability: For the AI Era consisting of a Webinar, Tech Talk, interactive Lab, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
CaitlinHalla
Instrumentation is usually the last step or even an afterthought when building out a project. The feature ships, the ...
by CaitlinHalla Splunk Employee Splunk Employee in Community Blog 2 hours ago
1 0
1
0
NithinKR
Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the Splunk Clo...
by NithinKR Splunk Employee Splunk Employee in Product News & Announcements 2 hours ago
0 0
0
0
torustad
Good morning all,I run this search| makeresults count=4 | eval a="splunk_server" | map search="search index=esak-qa s...
by torustad Path Finder in Splunk Search 3 hours ago
0 19
0
19
ebaileytu
We have a use case where index time extractions for XML data makes a lot of sense yet I do not see an easy way go mak...
by ebaileytu Communicator in Splunk Search 3 hours ago
0 6
0
6
LesediK
Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how Splunk ...
by LesediK Splunk Employee Splunk Employee in Splunk Tech Talks 4 hours ago
0 0
0
0
maheshnc
Hi Everyone, we are using Splunk DB Connect 4.3.0 along with splunk 10.4.1 version, we had existing connections using...
by maheshnc Path Finder in Getting Data In 8 hours ago
0 1
0
1
saised
The latest Splunk Enterprise version that is Splunk 10.6.0.5 do not have the App "TA Zeek JSON Parsing". How can we r...
by saised New Member in Splunk Enterprise 8 hours ago
0 1
0
1
iamvikasjha
Splunk version 10.4 Victoria:I'm experiencing inconsistent filtering behavior in a Dashboard Studio table that uses a...
by iamvikasjha New Member in Splunk Cloud Platform 10 hours ago
0 0
0
0
TheEggi98
Hi fellow splunkers,i developed a monorepo app with a basic page as view and want to make the view globally available...
by TheEggi98 Path Finder in Splunk Enterprise 10 hours ago
0 0
0
0
kaurinko
Hi,I seem to receive warnings like the one below:LineBreakingProcessor [1616 structuredparsing] - Truncating line bec...
by kaurinko Communicator in Splunk Enterprise 11 hours ago
0 6
0
6
TheExpert
Hi all,after upgrading Splunk Enterprise from 10.4.3 to 10.6.0.5 there are some issues:Management of apps isn't worki...
by TheExpert Path Finder in Splunk Enterprise yesterday
0 5
0
5
hrawat
Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone of mod...
by hrawat Splunk Employee Splunk Employee in Community Blog yesterday
0 0
0
0
BJ17
Unable to update and save detections after upgrading to Splunk ES version 8.1.0. It says Detection ID is missing.  
by BJ17 Explorer in Splunk Enterprise Security yesterday
0 5
0
5
LesediK
Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. Between ...
by LesediK Splunk Employee Splunk Employee in Splunk Tech Talks yesterday
0 0
0
0
Jakob45a
Hello all, I'm trying to get data from  _configtracker in Splunk Cloud, as I cannot seem to find saved search changes...
by Jakob45a New Member in Monitoring Splunk yesterday
0 1
0
1
Omar_Khaled
Hi , did anyone faced this issue before ? how I can solve that BTW the unhealthy instances are indexers    
by Omar_Khaled Observer in Splunk Enterprise yesterday
0 9
0
9
Jasem
Hello If I has several network zones and a HF in each zone forwarding logs to indexer cluster, what would be the best...
by Jasem New Member in Getting Data In Tuesday
0 3
0
3
Prudhvi_k
In our environment the Splunkd.log are registering in Russian and English language.Kindly refer to the attached scree...
by Prudhvi_k Loves-to-Learn Lots in Splunk Cloud Platform Tuesday
0 2
0
2
andrew_f_trobec
There are conflicting statements in Splunk ITSI 4.21 documentation about being able to use adaptive thresholding on p...
by andrew_f_trobec Explorer in Splunk Enterprise Tuesday
0 2
0
2
damucka
Hello, I have a parts of the search, which I would like to execute conditionally. In the below example I am trying t...
by damucka Builder in Splunk Search Tuesday
0 18
0
18
torustad
Good afternoon,I am trying to generate an alert email with a clickable link included. What is the correct way to do a...
by torustad Path Finder in Splunk Enterprise Monday
0 2
0
2
jdmeek
We have all of our Windows workstations sending PowerShell transcripts to a central drop share for ingest.  This work...
by jdmeek Explorer in Getting Data In Monday
0 2
0
2
youngso
We needed to ingest Trellix/McAfee ePO audit logs (dbo.OrionAuditLog) into Splunk using DB Connect while establishing...
by SplunkTrust SplunkTrust in All Apps and Add-ons Monday
0 1
0
1
Anam
Full-Stack Observability Office Hours: Ask the ExpertsOctober 22nd 2026 | 11:00am – 12:00pm PT   As AI reshapes appli...
by Community Manager Community Manager in Community Office Hours Monday
0 0
0
0
KayeChapman
Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use ca...
by KayeChapman Splunk Employee Splunk Employee in Community Blog Monday
0 0
0
0
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
Splunk ITSI EMEA User Group: Unleashing Potential Copenhagen (DK) Oct 07, 2026 @ 13:00 PM 22 attending
Inside Splunk ES: Feature highlight: ES 8.7 update session Amsterdam (NL) Oct 08, 2026 @ 10:00 AM 27 attending
OpenTelemetry Weekly Drop-In US Oct 12, 2026 @ 08:30 AM 6 attending
HYBRID: DASUG 2nd-Tue Sep 13 DINNER presents: Best of .conf26 free-for-all! Dallas, TX (US) Oct 13, 2026 @ 17:00 PM 0 attending
Splunk ITSI EMEA User Group: Unleashing Potential Copenhagen (DK) Oct 07, 2026 @ 13:00 PM 22 attending
View More

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Latest Blog Activity

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without Leaving Your IDE

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ships, the sprint closes, and the OpenTelemetry work lands in the backlog until something ...
on Community Blog 2 hours ago
1 Karma
1 Replies
20 Views

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk Cloud Platform

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the Splunk Cloud Platform v10.6.x release. This release brings historical firewall telemetry into ...
0 Karma
1 Replies
70 Views

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how Splunk supports this spectrum of agentic experiences. Start with AI Assistant in agentic ...
on Splunk Tech Talks 4 hours ago
0 Karma
1 Replies
24 Views

Supercharging Windows Security Detection Performance: Introducing Hybrid Field Extractions

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone of modern Security Operations Centers (SOCs). However, in high-throughput environments, ...
on Community Blog yesterday
0 Karma
1 Replies
67 Views

Additional Help & Resources