Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

122K Members 2,282 Online 157K Posts

Join us for a 4-part series on Splunk Agent Observability consisting of Webinar, Tech Talk, Workshop, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
masakazu
I attempted to install SOAR 8.5 on an offline RHEL 9.4 environment, but the installation failed with error messages s...
by masakazu Explorer in Splunk SOAR yesterday
0 2
0
2
romux72
Hi,I find a problem with App's Number Display (https://splunkbase.splunk.com/app/4537) on dashboard Studio when Dashb...
by romux72 Explorer in All Apps and Add-ons yesterday
0 6
0
6
wdeherre1
This app requires three configuration items (XSOAR URL , XSOAR API Key, and Splunk Token).I'm not sure where to obtai...
by wdeherre1 New Member in All Apps and Add-ons yesterday
0 0
0
0
USA69
 Please I need help fixing this search below. Will appreciate the help. When I run the search I don't see the results...
by USA69 Path Finder in Splunk Enterprise yesterday
0 9
0
9
vvalverde
From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a passion f...
by vvalverde Splunk Employee Splunk Employee in Community Blog yesterday
0 0
0
0
KayeChapman
Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use ca...
by KayeChapman Splunk Employee Splunk Employee in Community Blog yesterday
0 0
0
0
i0ntempest
I just upgraded Splunk to 10.4 (10.2.2 x86_64 to 10.4 arm64) on macOS, and the previously working KVStore now does no...
by i0ntempest Loves-to-Learn Lots in Deployment Architecture Monday
0 9
0
9
neerajs_81
Hello, Like any other ES user, we have threat intel feeds configured that came along with box.  How can i view the ac...
by neerajs_81 Builder in Splunk Enterprise Security Monday
0 2
0
2
USA69
Can someone help me optimize this search so the results on the search and dashboard panel should be the same. The sea...
by USA69 Path Finder in Splunk Search Monday
0 7
0
7
natebolt01
I recently passed the tests for the Splunk Power User and Splunk Admin certifications. I got emails from Splunk sayi...
3 10
3
10
NullZero
Some feedback on this TA, I believe that the documentation listed on Splunkbase is inadequate and it should list at t...
by NullZero Communicator in All Apps and Add-ons Monday
0 3
0
3
ravidaj
I looked in the SPLUNK_HOME/etc/log.cfg and local-log.cfg and can't find any stanzas to change it. I ask because it i...
by ravidaj Engager in Splunk Enterprise Monday
2 3
2
3
Matzi
Hi all!Maybe I have found a small bug in the Python for Scientific Computing for Linux 64-bit app.The problem I see i...
by Matzi Engager in All Apps and Add-ons Sunday
0 1
0
1
ahartge
I have noticed something odd in a SHC deployment. Im consistently seeing "SHCMasterArtifactHandler - failed on handle...
by ahartge Path Finder in Deployment Architecture Sunday
2 4
2
4
BenjaminFinck
Environment:- Splunk Enterprise 10.2.7, incrementally upgraded from an older 10.x line- RHEL 8 & Windows Server 2022 ...
by BenjaminFinck Explorer in Splunk Enterprise Saturday
0 1
0
1
briancronrath
We are seeing a large discrepancy when filtering on a JSON-extracted field in Splunk EnterpriseEnvironmentSplunk Ente...
by briancronrath Contributor in Splunk Enterprise Friday
0 1
0
1
LESMeeks
I added the Splunk Cisco ISE addon but when i open the app it stays blank. 
by LESMeeks New Member in All Apps and Add-ons Friday
0 2
0
2
Lachnite
Regarding the Cisco Support cutover from AppDynamics Support: I have been an AppDynamics Admin for over 6+ years, and...
by Lachnite New Member in Splunk AppDynamics Friday
0 0
0
0
strehb18
Hello, What is the current best practice for repeated charts where only one variable changes. The suggestions I see a...
by strehb18 Path Finder in Dashboards & Visualizations Friday
0 1
0
1
FuzzySteve
Hello Community!We have a particular set of searches that rely on a lookup against a managed lookup (adhock).  The lo...
by FuzzySteve Loves-to-Learn in Splunk Dev Friday
0 5
0
5
hilal
The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no ...
by hilal Loves-to-Learn in Community Blog Friday
3 1
3
1
kwagner001
Splunkbase doesn't have a link to the documentation for the newly update Cisco Enterprise Networking add-on and app. ...
by kwagner001 Loves-to-Learn in All Apps and Add-ons Thursday
0 2
0
2
derekmkll
I have two pipelines that reduce the log size of pan:traffic:cloud and pan:threat:cloud by removing fields that do no...
by derekmkll Path Finder in Splunk Cloud Platform Thursday
0 14
0
14
iamryan
Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with lear...
by Community Manager Community Manager in Community Blog Thursday
0 0
0
0
dkmcclory
We're using Rapid7's InsightVM TA to pull asset vulnerability events into Splunk.  Generally, it works well, but we'v...
by dkmcclory Path Finder in All Apps and Add-ons Thursday
2 0
2
0
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
Inside Splunk ES: Feature highlight: ES 8.6 update session Amsterdam (NL) Sep 10, 2026 @ 10:00 AM 48 attending
Explorando o M.O.A.T.: Arquitetura de Dados com Splunk Sao Paulo (BR) Sep 10, 2026 @ 19:00 PM 7 attending
Unlock the Power of the Splunk AI Toolkit: Live Walkthrough Frisco, TX (US) Sep 10, 2026 @ 17:30 PM 9 attending

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a passion for Kubernetes and containers into a solution to real-world customer challenges? For ...
on Community Blog yesterday
0 Karma
1 Replies
29 Views

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for Security, Observability, Industries, AI, and Cisco. We also host valuable ...
on Community Blog yesterday
0 Karma
1 Replies
51 Views

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no strangers to alert fatigue. A high-severity notable fires, and an analyst ...
on Community Blog Friday
3 Karma
2 Replies
1186 Views

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with learning. But when the breakout rooms clear, it’s time to step away, grab a drink, and ...
on Community Blog Thursday
0 Karma
1 Replies
100 Views

Additional Help & Resources