Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

122K Members 1,862 Online 157K Posts

Join us for a 4-part series on Splunk Agent Observability consisting of Webinar, Tech Talk, Workshop, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
BenjaminFinck
Environment:- Splunk Enterprise 10.2.7, incrementally upgraded from an older 10.x line- RHEL 8 & Windows Server 2022 ...
by BenjaminFinck Explorer in Splunk Enterprise 3 hours ago
0 1
0
1
NullZero
Some feedback on this TA, I believe that the documentation listed on Splunkbase is inadequate and it should list at t...
by NullZero Communicator in All Apps and Add-ons yesterday
0 2
0
2
briancronrath
We are seeing a large discrepancy when filtering on a JSON-extracted field in Splunk EnterpriseEnvironmentSplunk Ente...
by briancronrath Contributor in Splunk Enterprise yesterday
0 1
0
1
LESMeeks
I added the Splunk Cisco ISE addon but when i open the app it stays blank. 
by LESMeeks New Member in All Apps and Add-ons yesterday
0 2
0
2
Lachnite
Regarding the Cisco Support cutover from AppDynamics Support: I have been an AppDynamics Admin for over 6+ years, and...
by Lachnite New Member in Splunk AppDynamics yesterday
0 0
0
0
strehb18
Hello, What is the current best practice for repeated charts where only one variable changes. The suggestions I see a...
by strehb18 Path Finder in Dashboards & Visualizations yesterday
0 1
0
1
FuzzySteve
Hello Community!We have a particular set of searches that rely on a lookup against a managed lookup (adhock).  The lo...
by FuzzySteve Loves-to-Learn in Splunk Dev yesterday
0 5
0
5
hilal
The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no ...
by hilal Observer in Community Blog yesterday
3 1
3
1
kwagner001
Splunkbase doesn't have a link to the documentation for the newly update Cisco Enterprise Networking add-on and app. ...
by kwagner001 Loves-to-Learn in All Apps and Add-ons Thursday
0 2
0
2
derekmkll
I have two pipelines that reduce the log size of pan:traffic:cloud and pan:threat:cloud by removing fields that do no...
by derekmkll Path Finder in Splunk Cloud Platform Thursday
0 14
0
14
iamryan
Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with lear...
by Community Manager Community Manager in Community Blog Thursday
0 0
0
0
dkmcclory
We're using Rapid7's InsightVM TA to pull asset vulnerability events into Splunk.  Generally, it works well, but we'v...
by dkmcclory Path Finder in All Apps and Add-ons Thursday
2 0
2
0
pruthviraj_k_m
Hi All,I am trying to build a playbook that reduces the risk of an entity in any of the splunk notable only when the ...
by pruthviraj_k_m Explorer in Splunk SOAR Thursday
0 4
0
4
USA69
Can someone help me optimize this search so the results on the search and dashboard panel should be the same. The sea...
by USA69 Explorer in Splunk Search Thursday
0 6
0
6
sirpatrick
I see some very specific requirements for the latest major version of this TA for Splunk Cloud and Splunk Enterprise....
by sirpatrick Explorer in Getting Data In Thursday
0 2
0
2
romux72
Hi,I find a problem with App's Number Display (https://splunkbase.splunk.com/app/4537) on dashboard Studio when Dashb...
by romux72 Explorer in All Apps and Add-ons Thursday
0 0
0
0
Seenu_K
Many enterprise applications rely on Windows-based Single Sign-On (SSO) technologies such as Kerberos, NTLM, and Inte...
by Seenu_K Engager in Splunk AppDynamics Thursday
1 0
1
0
ChrisHms
Hello,In a splunk search, the first transforming command is processed on the indexers and processed data is transfere...
by ChrisHms Observer in Deployment Architecture Wednesday
0 3
0
3
kbroeker
Hi, in our deployment pipeline we want to check the config of an app. At the moment I try to parse the default.meta ...
by kbroeker New Member in Deployment Architecture Wednesday
0 2
0
2
rederada
Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent Launch...
by rederada Splunk Employee Splunk Employee in Community Blog Wednesday
0 0
0
0
ricarsot
Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in Splunk Clo...
by ricarsot Splunk Employee Splunk Employee in Splunk Tech Talks Wednesday
0 0
0
0
LizAndy123
We currently have a DB Connection and a Query which brings in Project Details with the username Entitlements. The Que...
by LizAndy123 Path Finder in Splunk Search Wednesday
0 7
0
7
hrawat
Why Universal Forwarders Should Not Be Used as Intermediate Forwarders A practical Splunk forwarding topology guide f...
by hrawat Splunk Employee Splunk Employee in Community Blog Wednesday
0 1
0
1
jjkel
Successful when using finding:consolidated_findings.example.0 or finding:consolidated_findings.example.1 but not when...
by jjkel Explorer in Splunk SOAR Wednesday
1 5
1
5
mcqueen9
Hello,I'm trying to configure the PureStorage Unified addon, and keep getting the Something went wrong errorAddon:htt...
by mcqueen9 Engager in Installation Tuesday
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
Inside Splunk ES: Feature highlight: ES 8.6 update session Amsterdam (NL) Sep 10, 2026 @ 10:00 AM 32 attending
Explorando o M.O.A.T.: Arquitetura de Dados com Splunk Sao Paulo (BR) Sep 10, 2026 @ 19:00 PM 7 attending
Unlock the Power of the Splunk AI Toolkit: Live Walkthrough Frisco, TX (US) Sep 10, 2026 @ 17:30 PM 8 attending

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no strangers to alert fatigue. A high-severity notable fires, and an analyst ...
on Community Blog yesterday
3 Karma
2 Replies
1021 Views

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed with learning. But when the breakout rooms clear, it’s time to step away, grab a drink, and ...
on Community Blog Thursday
0 Karma
1 Replies
51 Views

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent Launchpad to build an AI-powered workflow addressing a real-world Splunk challenge. And ...
on Community Blog Wednesday
0 Karma
1 Replies
114 Views

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in Splunk Cloud Platform becomes complex quickly, as an average stack of about 50 applications ...
on Splunk Tech Talks Wednesday
0 Karma
1 Replies
120 Views

Additional Help & Resources