Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

123K Members 1,002 Online 158K Posts

Join us for a 4-part series on Full-Stack Observability: For the AI Era consisting of a Webinar, Tech Talk, interactive Lab, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
Amohlmann
I want to group users by their age which range from roughly 5 years to 90. The dateofbirth field is formatted like th...
by Amohlmann Communicator in Splunk Search 5 hours ago
0 13
0
13
rederada
If you stopped by the Builder Bar at .conf26, thank you! This year, we brought together Splunk app developers, app ow...
by rederada Splunk Employee Splunk Employee in Community Blog 7 hours ago
0 0
0
0
splunkreal
Hello, we have "opencti_create_incident_modalert.log" file generated in splunk/var/log/splunk on search heads (SHC) h...
by splunkreal Influencer in All Apps and Add-ons 9 hours ago
0 8
0
8
Matt_Splunk
Hello all, I am very new to Splunk so apologies if this is an easy one. We want to set up an alert to come out of Spl...
by Matt_Splunk New Member in Splunk Search 10 hours ago
0 3
0
3
kaurinko
Hi,I tried to create a summary-event index using collect. The aim was to be able to define some things that the stand...
by kaurinko Communicator in Splunk Enterprise 13 hours ago
0 7
0
7
ServiceNow_SecO
We recently rolled out a new version of our Splunk Add-on. When the customers upgraded to this new version (this cont...
by ServiceNow_SecO Loves-to-Learn in All Apps and Add-ons 15 hours ago
0 1
0
1
senmng
I would like to use AI tool to automate the Splunk search capability. For instance, instead of using Splunk search us...
by senmng New Member in Dashboards & Visualizations 15 hours ago
0 2
0
2
hotrodbass
This query works.  I get a triggered alert if the cpu is running high over 90% for 5 consecutive minutes. But when th...
by hotrodbass Explorer in Alerting 16 hours ago
0 3
0
3
LuisLandero
Hi team, I'm training self on splunk but i forget the pass.¿How I can reset it?
by LuisLandero New Member in Splunk Enterprise 16 hours ago
0 1
0
1
luispulido
Hello Splunk Community,I have a Splunk Enterprise environment where the Search Head has restricted Internet access. A...
by luispulido Explorer in Splunk Enterprise 16 hours ago
0 2
0
2
cskokos_splunk
Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University classrooms...
by cskokos_splunk Splunk Employee Splunk Employee in Training & Certification Blog yesterday
1 0
1
0
hrawat
When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with before a...
by hrawat Splunk Employee Splunk Employee in Community Blog yesterday
5 6
5
6
hrawat
Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully utilize...
by hrawat Splunk Employee Splunk Employee in Community Blog yesterday
0 2
0
2
kaurinko
Hi,We upgraded our Splunk from 9.4.3 to 10.4.3 and it seems like something changed. The following used to work withou...
by kaurinko Communicator in Splunk Enterprise yesterday
0 2
0
2
unluakin
AI Toolkit cannot make a connection to local OLLAMA server. It gives an error saying that litellm is missing and is n...
by unluakin Loves-to-Learn Lots in All Apps and Add-ons yesterday
0 5
0
5
peining
I am trying to calculate birth year and age, based on birthdate. The following works, but only for dates within the l...
by peining Observer in Other Usage yesterday
0 5
0
5
lumpymilk
Is there a plan to support Splunk Enterprise 10.2 and 10.4 with the TA-proofpoint-isolation add-on? If not, what are ...
by lumpymilk Explorer in All Apps and Add-ons Friday
1 1
1
1
ddrillic
I encountered an interesting case involving a hierarchical set of monitor stanzas within the complex waslogs configur...
by ddrillic Ultra Champion in Getting Data In Friday
0 1
0
1
dbcase
Hi, Is there a way to create a Dashboard/form/something that will group dashboards together? Example, I have dashbo...
by dbcase Motivator in Dashboards & Visualizations Friday
1 12
1
12
Jijish
Dear All, The even though the vulnerability is appearing a Mitigated in the Tenable SC . Still the Tenable Add on in ...
by Jijish New Member in All Apps and Add-ons Friday
0 0
0
0
madhav_dholakia
Hello,What are the best methods to ingest Datadog Log and Metrics Data into Splunk Cloud/HF? We have a requirement to...
by madhav_dholakia Contributor in Other Usage Friday
0 5
0
5
schose
Hi all,when upgrading to Splunk Enterprise 9.4.15, 10.0.10, 10.2.7 or 10.4.3 with the .rpm or .deb package, the upgra...
by schose Builder in Splunk Enterprise Friday
1 1
1
1
balu25
For security reasons, your account has been locked out. Please try again later or contact your system administrator.
by balu25 New Member in Training + Certification Discussions Thursday
0 1
0
1
Wohamed_wakkad
I configured a multi-layer Deployment Server (DS) setup with the following architecture:Main DS Management: The main ...
by Wohamed_wakkad Path Finder in Deployment Architecture Thursday
0 2
0
2
Anam
As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of monitoring are ...
by Community Manager Community Manager in Community Blog Thursday
0 0
0
0
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
.conf26 recap; Introducing Machine Data Lake for cost-effective storage: Se... San Francisco, CA (US) Sep 29, 2026 @ 18:00 PM 17 attending
Finding silent detection failures with Warren James Canberra, Australian Capital Territory (AU) Oct 01, 2026 @ 16:00 PM 7 attending

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought together Splunk app developers, app owners and curious newcomers for a hands-on experience focused on one ...
on Community Blog 7 hours ago
0 Karma
1 Replies
32 Views

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University classrooms to certification milestones and hundreds of challenges completed in the ...
1 Karma
1 Replies
52 Views

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with before automatic scaling takes over. It is not a memory guard rail and it is not the final ...
on Community Blog yesterday
5 Karma
7 Replies
1939 Views

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully utilized. In practice, that often leads to a familiar pattern: blocked queues appear, ...
on Community Blog yesterday
0 Karma
3 Replies
520 Views

Additional Help & Resources