Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

123K Members 3,163 Online 158K Posts

Join us for a 4-part series on Full-Stack Observability: For the AI Era consisting of a Webinar, Tech Talk, interactive Lab, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
youngso
We needed to ingest Trellix/McAfee ePO audit logs (dbo.OrionAuditLog) into Splunk using DB Connect while establishing...
by SplunkTrust SplunkTrust in All Apps and Add-ons 31m ago
0 1
0
1
torustad
Good afternoon,I am trying to generate an alert email with a clickable link included. What is the correct way to do a...
by torustad Path Finder in Splunk Enterprise 4 hours ago
0 1
0
1
jdmeek
We have all of our Windows workstations sending PowerShell transcripts to a central drop share for ingest.  This work...
by jdmeek Explorer in Getting Data In 4 hours ago
0 1
0
1
andrew_f_trobec
There are conflicting statements in Splunk ITSI 4.21 documentation about being able to use adaptive thresholding on p...
by andrew_f_trobec Explorer in Splunk Enterprise 4 hours ago
0 1
0
1
TheExpert
Hi all,after upgrading Splunk Enterprise from 10.4.3 to 10.6.0.5 there are some issues:Management of apps isn't worki...
by TheExpert Path Finder in Splunk Enterprise 6 hours ago
0 1
0
1
kaurinko
Hi,I seem to receive warnings like the one below:LineBreakingProcessor [1616 structuredparsing] - Truncating line bec...
by kaurinko Communicator in Splunk Enterprise 6 hours ago
0 3
0
3
kh_test
weed,
by kh_test New Member in Feedback 8 hours ago
0 0
0
0
Anam
Full-Stack Observability Office Hours: Ask the ExpertsOctober 22nd 2026 | 11:00am – 12:00pm PT   As AI reshapes appli...
by Community Manager Community Manager in Community Office Hours 8 hours ago
0 0
0
0
KayeChapman
Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use ca...
by KayeChapman Splunk Employee Splunk Employee in Community Blog 10 hours ago
0 0
0
0
LesediK
The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming the enter...
by LesediK Splunk Employee Splunk Employee in Webinars 12 hours ago
0 0
0
0
Jasem
Hello If I has several network zones and a HF in each zone forwarding logs to indexer cluster, what would be the best...
by Jasem New Member in Getting Data In 18 hours ago
0 0
0
0
Prudhvi_k
In our environment the Splunkd.log are registering in Russian and English language.Kindly refer to the attached scree...
by Prudhvi_k Loves-to-Learn Lots in Splunk Cloud Platform yesterday
0 0
0
0
ddrillic
We have roughly 10k-15k UFs in the company and we wonder in which route to go for ongoing maintenance of the UFs, whe...
by ddrillic Ultra Champion in Deployment Architecture Saturday
0 5
0
5
vanvan
Hi, We have high-volume syslog input configured on a HF with Splunk v.7.2.5 and we started noticing TailReader-0 pip...
by vanvan Path Finder in Monitoring Splunk Saturday
0 4
0
4
Matt_Splunk
Hello all, I am very new to Splunk so apologies if this is an easy one. We want to set up an alert to come out of Spl...
by Matt_Splunk Observer in Splunk Search Saturday
0 5
0
5
BradOH
Hey there, in the new modern UI, is there any way to use custom icons in the navigation bar?  That is, other than the...
by BradOH Path Finder in Splunk Enterprise Friday
0 0
0
0
eucrates
I'm trying to access the Splunk hosted instance of the BOTS v1.0 dataset and the link"Splunk Security Dataset Project...
0 0
0
0
MichelleCorpora
    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of momentum to da...
by MichelleCorpora Splunk Employee Splunk Employee in Product News & Announcements Friday
0 0
0
0
kwheeler
As organizations modernize their cloud environments, AWS workloads generate more security, operational, and applicati...
by kwheeler Splunk Employee Splunk Employee in Product News & Announcements Friday
0 0
0
0
prajapatidaksh
Guys please help me on how integrate Microsoft Intune to Splunk cloud via graph Api.anyone having SOP please share no...
by prajapatidaksh New Member in Splunk Cloud Platform Friday
0 1
0
1
lary925
Hi everyone,I'm troubleshooting a Splunk Add-on for AWS CloudWatch Logs input that collects Amazon RDS Oracle audit l...
by lary925 Observer in All Apps and Add-ons Friday
0 0
0
0
Beginner2
Some Search Heads show "Up" status but other search heads are always show "Pending". I want to know that how to solve...
by Beginner2 Observer in Deployment Architecture Thursday
0 1
0
1
Anam
“AI + Observability Office Hours: Ask the Experts”October 6, 2026 | 11:00am – 12:00pm PT AI is transforming the appli...
by Community Manager Community Manager in Community Office Hours Thursday
0 0
0
0
PreranaD
We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and on-prem...
by PreranaD Splunk Employee Splunk Employee in Product News & Announcements Thursday
0 16
0
16
ddrillic
I encountered an interesting case involving a hierarchical set of monitor stanzas within the complex waslogs configur...
by ddrillic Ultra Champion in Getting Data In Thursday
0 4
0
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
OpenTelemetry Weekly Drop-In US Oct 05, 2026 @ 08:30 AM 6 attending
Splunk Twin Cities User Group - Q4 2026 Meeting: .conf 2026 Highlights / C... Minneapolis, MN (US) Oct 06, 2026 @ 14:00 PM 21 attending
Splunk ITSI EMEA User Group: Unleashing Potential Copenhagen (DK) Oct 07, 2026 @ 13:00 PM 22 attending
Inside Splunk ES: Feature highlight: ES 8.7 update session Amsterdam (NL) Oct 08, 2026 @ 10:00 AM 20 attending
OpenTelemetry Weekly Drop-In US Oct 05, 2026 @ 08:30 AM 6 attending
View More

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for Security, Observability, Industries, AI, and Cisco. We also host valuable ...
on Community Blog 10 hours ago
0 Karma
1 Replies
37 Views

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming the enterprise, but its success hinges on one critical factor: trust. Without robust ...
on Webinars 12 hours ago
0 Karma
1 Replies
33 Views

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of momentum to data management. Edge Processor Hybrid gives teams a way to modernize ingestion ...
0 Karma
1 Replies
142 Views

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and application telemetry than ever before. That data is valuable—but it does not always need to ...
0 Karma
1 Replies
119 Views

Additional Help & Resources