Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

122K Members 2,489 Online 157K Posts

Join us for a 4-part series on Splunk Agent Observability consisting of Webinar, Tech Talk, Workshop, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
kwagner001
Splunkbase doesn't have a link to the documentation for the newly update Cisco Enterprise Networking add-on and app. ...
by kwagner001 Loves-to-Learn in All Apps and Add-ons 4 hours ago
0 2
0
2
briancronrath
We are seeing a large discrepancy when filtering on a JSON-extracted field in Splunk EnterpriseEnvironmentSplunk Ente...
by briancronrath Contributor in Splunk Enterprise 8 hours ago
0 0
0
0
derekmkll
I have two pipelines that reduce the log size of pan:traffic:cloud and pan:threat:cloud by removing fields that do no...
by derekmkll Path Finder in Splunk Cloud Platform 10 hours ago
0 14
0
14
iamryan
Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with lear...
by Community Manager Community Manager in Community Blog 13 hours ago
0 0
0
0
dkmcclory
We're using Rapid7's InsightVM TA to pull asset vulnerability events into Splunk.  Generally, it works well, but we'v...
by dkmcclory Path Finder in All Apps and Add-ons 13 hours ago
1 0
1
0
pruthviraj_k_m
Hi All,I am trying to build a playbook that reduces the risk of an entity in any of the splunk notable only when the ...
by pruthviraj_k_m Explorer in Splunk SOAR 14 hours ago
0 4
0
4
USA69
Can someone help me optimize this search so the results on the search and dashboard panel should be the same. The sea...
by USA69 Explorer in Splunk Search 14 hours ago
0 6
0
6
strehb18
Hello, What is the current best practice for repeated charts where only one variable changes. The suggestions I see a...
by strehb18 Path Finder in Dashboards & Visualizations 14 hours ago
0 0
0
0
sirpatrick
I see some very specific requirements for the latest major version of this TA for Splunk Cloud and Splunk Enterprise....
by sirpatrick Explorer in Getting Data In 18 hours ago
0 2
0
2
romux72
Hi,I find a problem with App's Number Display (https://splunkbase.splunk.com/app/4537) on dashboard Studio when Dashb...
by romux72 Explorer in All Apps and Add-ons 19 hours ago
0 0
0
0
Seenu_K
Many enterprise applications rely on Windows-based Single Sign-On (SSO) technologies such as Kerberos, NTLM, and Inte...
by Seenu_K Engager in Splunk AppDynamics 19 hours ago
1 0
1
0
ChrisHms
Hello,In a splunk search, the first transforming command is processed on the indexers and processed data is transfere...
by ChrisHms Observer in Deployment Architecture yesterday
0 3
0
3
kbroeker
Hi, in our deployment pipeline we want to check the config of an app. At the moment I try to parse the default.meta ...
by kbroeker New Member in Deployment Architecture yesterday
0 2
0
2
rederada
Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent Launch...
by rederada Splunk Employee Splunk Employee in Community Blog yesterday
0 0
0
0
ricarsot
Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in Splunk Clo...
by ricarsot Splunk Employee Splunk Employee in Splunk Tech Talks yesterday
0 0
0
0
LizAndy123
We currently have a DB Connection and a Query which brings in Project Details with the username Entitlements. The Que...
by LizAndy123 Path Finder in Splunk Search yesterday
0 7
0
7
hrawat
Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology guide f...
by hrawat Splunk Employee Splunk Employee in Community Blog yesterday
0 1
0
1
jjkel
Successful when using finding:consolidated_findings.example.0 or finding:consolidated_findings.example.1 but not when...
by jjkel Explorer in Splunk SOAR yesterday
1 5
1
5
mcqueen9
Hello,I'm trying to configure the PureStorage Unified addon, and keep getting the Something went wrong errorAddon:htt...
by mcqueen9 Engager in Installation Tuesday
0 1
0
1
rederada
NO PURCHASE OR PAYMENT OF ANY KIND IS NECESSARY TO ENTER OR WIN. A PURCHASE WILL NOT INCREASE YOUR CHANCES OF WINNING...
by rederada Splunk Employee Splunk Employee in Welcome Center Tuesday
0 0
0
0
shradha_narain
Long before a new capability reaches the keynote stage, it begins as an idea waiting to be tested. At Innovation Labs...
by shradha_narain Splunk Employee Splunk Employee in Community Blog Tuesday
1 0
1
0
poojas89
I have installed the app and would like to proceed with the app setup and data ingestion configuration. Could you ple...
by poojas89 New Member in All Apps and Add-ons Tuesday
0 2
0
2
bloodsd
Dear Community:I am looking for information on ( Zabbix add-on for Splunk ) as to the compatibility with Splunk 10.2....
by bloodsd Engager in Splunk Enterprise Tuesday
0 2
0
2
szutsmarcell
I am currently unable to log into the Splunk Support Portal. The system continuously attempts to redirect me to the P...
0 2
0
2
MichelleCorpora
Data Management Digest   Welcome to the August 2026 edition of Data Management Digest! August was a big month for Spl...
by MichelleCorpora Splunk Employee Splunk Employee in Product News & Announcements Monday
0 0
0
0
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
Inside Splunk ES: Feature highlight: ES 8.6 update session Amsterdam (NL) Sep 10, 2026 @ 10:00 AM 29 attending
Explorando o M.O.A.T.: Arquitetura de Dados com Splunk Sao Paulo (BR) Sep 10, 2026 @ 19:00 PM 7 attending
Unlock the Power of the Splunk AI Toolkit: Live Walkthrough Frisco, TX (US) Sep 10, 2026 @ 17:30 PM 6 attending

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with learning. But when the breakout rooms clear, it’s time to step away, grab a drink, and ...
on Community Blog 13 hours ago
0 Karma
1 Replies
26 Views

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent Launchpad to build an AI-powered workflow addressing a real-world Splunk challenge. And ...
on Community Blog yesterday
0 Karma
1 Replies
84 Views

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in Splunk Cloud Platform becomes complex quickly, as an average stack of about 50 applications ...
on Splunk Tech Talks yesterday
0 Karma
1 Replies
91 Views

Forwarder Topology Guidance: Intermediate HF vs Intermediate UF

Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology guide for avoiding event corruption, duplicate data, and blocked forwarding queues. If you ...
on Community Blog yesterday
0 Karma
2 Replies
87 Views

Additional Help & Resources