Splunk Community

Find answers, ask questions, and connect with our community of consumers and specialists.

123K Members 1,804 Online 158K Posts

Join us for a 4-part series on Splunk Agent Observability consisting of Webinar, Tech Talk, Workshop, and Office Hours

Additional Help & Resources

Getting Started

Learn more about the Splunk Community and how we can help

Community Blog

Community happenings, product announcements, and Splunk news

Learning Paths

Discover Community and Learning Resources for your Role

User Groups

Meet up with other Splunk practitioners, virtually or in-person

Office Hours

Webinar-style deep dives and workshops for hands-on guidance

Community Activity
jarelloy
I have a namespace, hammy, in k8s with several pods deployed. Out of all the pods, i'd only want the pods with the na...
by jarelloy Engager in Splunk Enterprise an hour ago
0 5
0
5
luispulido
Hello Splunk Community,I have a Splunk Enterprise environment where the Search Head has restricted Internet access. A...
by luispulido Explorer in Splunk Enterprise 2 hours ago
0 1
0
1
kaurinko
Hi,I tried to create a summary-event index using collect. The aim was to be able to define some things that the stand...
by kaurinko Communicator in Splunk Enterprise 2 hours ago
0 1
0
1
cskokos_splunk
Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University classrooms...
by cskokos_splunk Splunk Employee Splunk Employee in Training & Certification Blog 3 hours ago
0 0
0
0
hrawat
When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with before a...
by hrawat Splunk Employee Splunk Employee in Community Blog 6 hours ago
5 6
5
6
hrawat
Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully utilize...
by hrawat Splunk Employee Splunk Employee in Community Blog 6 hours ago
0 2
0
2
splunkreal
Hello, we have "opencti_create_incident_modalert.log" file generated in splunk/var/log/splunk on search heads (SHC) h...
by splunkreal Influencer in All Apps and Add-ons 7 hours ago
0 2
0
2
kaurinko
Hi,We upgraded our Splunk from 9.4.3 to 10.4.3 and it seems like something changed. The following used to work withou...
by kaurinko Communicator in Splunk Enterprise 8 hours ago
0 2
0
2
unluakin
AI Toolkit cannot make a connection to local OLLAMA server. It gives an error saying that litellm is missing and is n...
by unluakin Loves-to-Learn Lots in All Apps and Add-ons 9 hours ago
0 5
0
5
peining
I am trying to calculate birth year and age, based on birthdate. The following works, but only for dates within the l...
by peining Observer in Other Usage 15 hours ago
0 5
0
5
hotrodbass
This query works.  I get a triggered alert if the cpu is running high over 90% for 5 consecutive minutes. But when th...
by hotrodbass Explorer in Alerting Saturday
0 1
0
1
lumpymilk
Is there a plan to support Splunk Enterprise 10.2 and 10.4 with the TA-proofpoint-isolation add-on? If not, what are ...
by lumpymilk Explorer in All Apps and Add-ons Friday
1 1
1
1
ddrillic
I encountered an interesting case involving a hierarchical set of monitor stanzas within the complex waslogs configur...
by ddrillic Ultra Champion in Getting Data In Friday
0 1
0
1
dbcase
Hi, Is there a way to create a Dashboard/form/something that will group dashboards together? Example, I have dashbo...
by dbcase Motivator in Dashboards & Visualizations Friday
1 12
1
12
Jijish
Dear All, The even though the vulnerability is appearing a Mitigated in the Tenable SC . Still the Tenable Add on in ...
by Jijish New Member in All Apps and Add-ons Friday
0 0
0
0
madhav_dholakia
Hello,What are the best methods to ingest Datadog Log and Metrics Data into Splunk Cloud/HF? We have a requirement to...
by madhav_dholakia Contributor in Other Usage Friday
0 5
0
5
schose
Hi all,when upgrading to Splunk Enterprise 9.4.15, 10.0.10, 10.2.7 or 10.4.3 with the .rpm or .deb package, the upgra...
by schose Builder in Splunk Enterprise Friday
1 1
1
1
balu25
For security reasons, your account has been locked out. Please try again later or contact your system administrator.
by balu25 New Member in Training + Certification Discussions Thursday
0 1
0
1
Wohamed_wakkad
I configured a multi-layer Deployment Server (DS) setup with the following architecture:Main DS Management: The main ...
by Wohamed_wakkad Path Finder in Deployment Architecture Thursday
0 2
0
2
Anam
As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of monitoring are ...
by Community Manager Community Manager in Community Blog Thursday
0 0
0
0
fab1en
My goal is to run AppDynamics in the context of a PHP application using an Alpine container. I am using the official ...
by fab1en Observer in Splunk AppDynamics Wednesday
0 7
0
7
richnokes
With the "STIG Compliance App for Splunk" installed, any checklist drag and dropped or browsed-for and installed just...
by richnokes New Member in Splunk Enterprise Wednesday
0 1
0
1
BenjaminFinck
Environment:- Splunk Enterprise 10.2.7, incrementally upgraded from an older 10.x line- RHEL 8 & Windows Server 2022 ...
by BenjaminFinck Explorer in Splunk Enterprise Wednesday
0 2
0
2
rogilic
I have a search to retrieve possible dropdown results from a search. The search produces 546 results. Going through t...
by rogilic New Member in Dashboards & Visualizations Wednesday
0 1
0
1
Priyanka8440
Hello Team,I am working on a requirement to discover cryptographic objects using Splunk. I need to collect relevant l...
by Priyanka8440 New Member in Getting Data In Wednesday
0 4
0
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Top Solution Authors
Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Upcoming events
View More
OpenTelemetry Weekly Drop-In US Sep 28, 2026 @ 08:30 AM 4 attending
SAP Splunk User Group - Foundation and Future Planning - Stuttgart Sept 202... Dortmund, NRW (DE) Sep 29, 2026 @ 09:00 AM 7 attending
.conf26 recap; Introducing Machine Data Lake for cost-effective storage: Se... San Francisco, CA (US) Sep 29, 2026 @ 18:00 PM 16 attending
OpenTelemetry Weekly Drop-In US Sep 28, 2026 @ 08:30 AM 4 attending
View More

Meet the SplunkTrust

"Being a member of SplunkTrust as well as a User Group Leader enriches my knowledge of Splunk greatly. I am exposed to and learn so much about Splunk that I can be on top of any new features well ahead of the game." - Becky Burwell

The SplunkTrust is comprised of our most dedicated community members. They assist other members, participate in events, demonstrate the power of Splunk's products, and help guide future roadmaps.

Learn more
Top Solution Authors
Latest Blog Activity

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University classrooms to certification milestones and hundreds of challenges completed in the ...
0 Karma
1 Replies
17 Views

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with before automatic scaling takes over. It is not a memory guard rail and it is not the final ...
on Community Blog 6 hours ago
5 Karma
7 Replies
1909 Views

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully utilized. In practice, that often leads to a familiar pattern: blocked queues appear, ...
on Community Blog 6 hours ago
0 Karma
3 Replies
496 Views

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of monitoring are shifting. Today, the challenge isn't just knowing if a service is online, it is ...
on Community Blog Thursday
0 Karma
1 Replies
66 Views

Additional Help & Resources