Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

122K Members 2,389 Online 157K Posts

Join us for a 4-part series on Splunk Agent Observability consisting of Webinar, Tech Talk, Workshop, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
709_miner
I have inherited Splunk and I've been in the process of cleaning up 2 of the heavy forwarder and 2 syslog uni forward...
by 709_miner Loves-to-Learn Everything in Splunk Enterprise 45m ago
0 1
0
1
sheryaramalik
My splunk.com account is registered to an email address that no longer exists, so I can't receive mail at it. There's...
by sheryaramalik New Member in Splunk Enterprise 51m ago
0 1
0
1
ravidaj
I looked in the SPLUNK_HOME/etc/log.cfg and local-log.cfg and can't find any stanzas to change it. I ask because it i...
by ravidaj Engager in Splunk Enterprise 7 hours ago
2 2
2
2
Arun2
Hi Team, I am exploring the splunk Observability CLoud with MS SQL Server Monitor. Collector has been deployed with r...
by Arun2 New Member in Splunk Observability Cloud 8 hours ago
0 0
0
0
evelenke
Hi Splunkers, we have DB with events in UTC which differs from local timezone. Setting up TZ (timezone) in props.con...
by evelenke Contributor in All Apps and Add-ons yesterday
2 13
2
13
Alan_Chan
“After upgrading Splunk to 10.2, the apps are no longer usable. May I know if there are any methods to collect PRTG l...
by Alan_Chan Explorer in Monitoring Splunk yesterday
0 1
0
1
bmeister
You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at .conf26 on We...
by bmeister Splunk Employee Splunk Employee in Community Blog yesterday
0 0
0
0
hilal
The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no ...
by hilal Observer in Community Blog yesterday
1 0
1
0
mohsplunking
Hello Splunkers,I have a question around integration of Salesforce with Splunk , I see there are two Add-on available...
by mohsplunking Path Finder in Splunk Enterprise Security yesterday
0 0
0
0
desaye
Hi Everyone,I have an existing F5 integration using Splunk Add-on for F5 BIG-IP configured to send Syslog and ASM log...
by desaye Engager in Knowledge Management yesterday
0 2
0
2
prad87
I am trying to setup a new cluster with smartstore to an S3 compliant DELL storage and failing. The configuration is ...
by prad87 Explorer in Getting Data In yesterday
0 2
0
2
szutsmarcell
I am currently unable to log into the Splunk Support Portal. The system continuously attempts to redirect me to the P...
0 0
0
0
ak_sky
Could someone confirm the expected outcome for the following settings: outputs.conf [tcpout:group1] server = 192.168...
by ak_sky Engager in Getting Data In Wednesday
1 7
1
7
seaswallowmex
How to export Checkpoint harmony log (cloud) to our Splunk (on-prem) ?
by seaswallowmex New Member in Splunk Enterprise Wednesday
0 0
0
0
LesediK
Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel like you’...
by LesediK Splunk Employee Splunk Employee in Splunk Tech Talks Wednesday
0 1
0
1
LesediK
Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling alerts, ru...
by LesediK Splunk Employee Splunk Employee in Splunk Tech Talks Wednesday
0 1
0
1
Joshu
Aside form the intro to splunk and the field search one, each time i try to do a new course i just get hit with this....
by Joshu New Member in Training + Certification Discussions Wednesday
0 0
0
0
cskokos_splunk
IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally C...
by cskokos_splunk Splunk Employee Splunk Employee in Training & Certification Blog Wednesday
0 0
0
0
ArifV
conf26   With nearly 70 breakout sessions on the docket, the .conf26 Observability track is designed to help teams cu...
by ArifV Splunk Employee Splunk Employee in Community Blog Wednesday
0 0
0
0
jjkel
Successful when using finding:consolidated_findings.example.0 or finding:consolidated_findings.example.1 but not when...
by jjkel Observer in Splunk SOAR Wednesday
0 3
0
3
BRFZ
Hello,I recently upgraded my Splunk instances to version 10.4.x and started seeing integrity check warnings affecting...
by BRFZ Communicator in Splunk Enterprise Wednesday
0 1
0
1
gleffler
Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to change all ...
by gleffler Splunk Employee Splunk Employee in Community Blog Tuesday
0 0
0
0
Latefa
Hi,Does Splunk Enterprise Security 8.x support JSON feeds directly as a URL-based threat intelligence source?If yes, ...
by Latefa New Member in Splunk Enterprise Security Tuesday
0 0
0
0
Scriabin
We upgraded an on-premises Splunk Enterprise Security search-head cluster from ES 8.2.x to ES 8.5.1.Before the upgrad...
by Scriabin New Member in Splunk SOAR Tuesday
0 1
0
1
spisiakmi
Hi, here is the description.In a dashboard there is time range picker with its token time_tkn and 2 dropdowns.The fir...
by spisiakmi Builder in Dashboards & Visualizations Monday
1 11
1
11
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
OpenTelemetry Weekly Drop-In US Aug 31, 2026 @ 08:30 AM 10 attending
Unlock the Power of the Splunk AI Toolkit: Live Walkthrough Frisco, TX (US) Sep 04, 2026 @ 17:30 PM 0 attending
Inside Splunk ES: Feature highlight: ES 8.6 update session Amsterdam (NL) Sep 10, 2026 @ 10:00 AM 18 attending
Explorando o M.O.A.T.: Arquitetura de Dados com Splunk Sao Paulo (BR) Sep 10, 2026 @ 19:00 PM 7 attending
OpenTelemetry Weekly Drop-In US Aug 31, 2026 @ 08:30 AM 10 attending
View More

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at .conf26 on Wednesday  Looking to dive into Splunk? Join one of our Product Focus Sessions on ...
on Community Blog yesterday
0 Karma
1 Replies
42 Views

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security are no strangers to alert fatigue. A high-severity notable fires, and an analyst ...
on Community Blog yesterday
1 Karma
1 Replies
362 Views

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel like you’re trying to solve a puzzle where the pieces are scattered across five different ...
on Splunk Tech Talks Wednesday
0 Karma
2 Replies
620 Views

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling alerts, runbooks, and endless manual searches. What if you could turn that operational ...
on Splunk Tech Talks Wednesday
0 Karma
2 Replies
447 Views

Additional Help & Resources