Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

123K Members 2,294 Online 158K Posts

Join us for a 4-part series on Full-Stack Observability: For the AI Era consisting of a Webinar, Tech Talk, interactive Lab, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
ddrillic
We have roughly 10k-15k UFs in the company and we wonder in which route to go for ongoing maintenance of the UFs, whe...
by ddrillic Ultra Champion in Deployment Architecture yesterday
0 5
0
5
vanvan
Hi, We have high-volume syslog input configured on a HF with Splunk v.7.2.5 and we started noticing TailReader-0 pip...
by vanvan Path Finder in Monitoring Splunk yesterday
0 4
0
4
Matt_Splunk
Hello all, I am very new to Splunk so apologies if this is an easy one. We want to set up an alert to come out of Spl...
by Matt_Splunk Observer in Splunk Search yesterday
0 5
0
5
BradOH
Hey there, in the new modern UI, is there any way to use custom icons in the navigation bar?  That is, other than the...
by BradOH Path Finder in Splunk Enterprise Friday
0 0
0
0
eucrates
I'm trying to access the Splunk hosted instance of the BOTS v1.0 dataset and the link"Splunk Security Dataset Project...
0 0
0
0
MichelleCorpora
    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of momentum to da...
by MichelleCorpora Splunk Employee Splunk Employee in Product News & Announcements Friday
0 0
0
0
kwheeler
As organizations modernize their cloud environments, AWS workloads generate more security, operational, and applicati...
by kwheeler Splunk Employee Splunk Employee in Product News & Announcements Friday
0 0
0
0
prajapatidaksh
Guys please help me on how integrate Microsoft Intune to Splunk cloud via graph Api.anyone having SOP please share no...
by prajapatidaksh New Member in Splunk Cloud Platform Friday
0 1
0
1
lary925
Hi everyone,I'm troubleshooting a Splunk Add-on for AWS CloudWatch Logs input that collects Amazon RDS Oracle audit l...
by lary925 Observer in All Apps and Add-ons Friday
0 0
0
0
Beginner2
Some Search Heads show "Up" status but other search heads are always show "Pending". I want to know that how to solve...
by Beginner2 Observer in Deployment Architecture Thursday
0 1
0
1
Anam
“AI + Observability Office Hours: Ask the Experts”October 6, 2026 | 11:00am – 12:00pm PT AI is transforming the appli...
by Community Manager Community Manager in Community Office Hours Thursday
0 0
0
0
PreranaD
We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and on-prem...
by PreranaD Splunk Employee Splunk Employee in Product News & Announcements Thursday
0 16
0
16
ddrillic
I encountered an interesting case involving a hierarchical set of monitor stanzas within the complex waslogs configur...
by ddrillic Ultra Champion in Getting Data In Thursday
0 4
0
4
SplunkCommunity
Splunk HQ Community Welcome Event SWEEPSTAKES Official Rules NO PURCHASE NECESSARY TO ENTER OR WIN.   A PURCHASE WILL...
by Community Manager Community Manager in Welcome Center Thursday
0 0
0
0
elizabethl_splu
In Splunk Cloud Platform and Splunk Enterprise 10.6, Analytics Workspace is removed from product and no longer suppor...
by elizabethl_splu Splunk Employee Splunk Employee in Product News & Announcements Thursday
0 0
0
0
gcusello
Hi at all, I need to send logs from many Universal Forwarders to an Indexer Cluster using an Intermediate Forwarder. ...
by SplunkTrust SplunkTrust in Splunk Search Thursday
0 5
0
5
schose
Hi all,when upgrading to Splunk Enterprise 9.4.15, 10.0.10, 10.2.7 or 10.4.3 with the .rpm or .deb package, the upgra...
by schose Builder in Splunk Enterprise Thursday
2 4
2
4
splunkreal
Hello, since upgrade 9.4.11 from 9.3.0 getting error 500 on splunkweb using local user (works with admin account). Th...
by splunkreal Influencer in Splunk Enterprise Thursday
0 1
0
1
Jasem
I'm using Splunk enterprise 10.4.0 with es 8.6 installed. But this dashboard is searching threat_intelligence index w...
by Jasem New Member in Splunk Enterprise Security Thursday
0 2
0
2
Tushar_ph
Title: Seeking a supported or community Wiz connector for Splunk SOAR CloudHi all,We use Wiz for cloud security postu...
by Tushar_ph New Member in Splunk SOAR Thursday
0 2
0
2
Seawheels51
Splunk Assist generating DNS queries to beam.scs.splunk.com every 15 secondsEnvironment: Splunk Enterprise 10.2.3Comp...
by Seawheels51 Path Finder in Splunk Enterprise Wednesday
0 0
0
0
zdunlap
I am looking for a version of the Nozomi Networks Universal Add-on that is supported on Splunk Enterprise 9.0.10 and ...
by zdunlap Engager in All Apps and Add-ons Wednesday
0 1
0
1
josep
Hello,I'm new to Splunk Enterprise Security and I'm building a flow where a finding triggers a playbook that simply s...
by josep New Member in Splunk Enterprise Security Wednesday
0 0
0
0
PaulaCom
Morning All  I need some help with an spl i am using to define actions requried this is my curretn spl which is worki...
by PaulaCom Path Finder in Splunk Search Wednesday
0 5
0
5
Raffaele53
Hello,I’m using Cribl Cloud to pull JSON events from an Azure Event Hub and forward them to Splunk via HEC.Each incom...
by Raffaele53 Loves-to-Learn in Getting Data In Wednesday
0 7
0
7
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
OpenTelemetry Weekly Drop-In US Oct 05, 2026 @ 08:30 AM 5 attending
Splunk Twin Cities User Group - Q4 2026 Meeting: .conf 2026 Highlights / C... Minneapolis, MN (US) Oct 06, 2026 @ 14:00 PM 19 attending
Splunk ITSI EMEA User Group: Unleashing Potential Copenhagen (DK) Oct 07, 2026 @ 13:00 PM 21 attending
Inside Splunk ES: Feature highlight: ES 8.7 update session Amsterdam (NL) Oct 08, 2026 @ 10:00 AM 15 attending
OpenTelemetry Weekly Drop-In US Oct 05, 2026 @ 08:30 AM 5 attending
View More

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Latest Blog Activity

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of momentum to data management. Edge Processor Hybrid gives teams a way to modernize ingestion ...
0 Karma
1 Replies
70 Views

Federated Search for CloudWatch Unified Data Store Is Generally Available

As organizations modernize their cloud environments, AWS workloads generate more security, operational, and application telemetry than ever before. That data is valuable—but it does not always need to ...
0 Karma
1 Replies
59 Views

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and on-premises customers who have upgraded to version 10.4. This transformative update shifts ...
0 Karma
17 Replies
5431 Views

Analytics Workspace removal in Splunk 10.6

In Splunk Cloud Platform and Splunk Enterprise 10.6, Analytics Workspace is removed from product and no longer supported. To learn more about the removal, visit this Lantern article FAQ. 
0 Karma
1 Replies
103 Views

Additional Help & Resources