Admin Other

Admin Other
Category Activity
dwfarris
Ok, I am working to trim back some of our indexed data. I initially tried to drill down using a basic sum(len(_raw) f...
by dwfarris Explorer in Installation 02-16-2021
1 2
1
2
dflodstrom
How do I push my self-signed certs to universal forwarders using the deployment server. The docs say: Define the fol...
by dflodstrom Builder in Security 02-16-2021
0 7
0
7
adamhopkinson
Hi I'm running a trial of Splunk 4.2.4 on our webserver - just one installation, with no forwarders and not pulling ...
by adamhopkinson Explorer in Installation 02-16-2021
0 6
0
6
Parameshwara
When a query with 'return' command is run by a non admin user, it throws the error Unknown search command 'return' ...
by Parameshwara Path Finder in Security 02-12-2021
1 3
1
3
pettuv01
Hi, Is it possible to export/archive data during license violation causing search function lockdown?In our case we ha...
by pettuv01 Engager in Installation 02-10-2021
0 2
0
2
splunkreal
Hello guys,Just noticed on preproduction environment local sslPassword on cluster member has not been updated when pu...
by splunkreal Influencer in Security 02-10-2021
0 0
0
0
jbender72
Hello,I am getting this new warning on my dashboards and searches of a Security Essentials Lookup.  I have done btool...
by jbender72 Path Finder in Security 02-10-2021
0 0
0
0
rajkskumar
I need to extract two characters to a new field. The query I have written is able to remove the first 6 characters an...
by rajkskumar Explorer in Installation 02-10-2021
0 1
0
1
chillsgrove
We have almost 500 Splunk users in our organization (a mix of local and LDAP). About 200+ of our Splunk users are no ...
by chillsgrove Explorer in Security 02-09-2021
2 5
2
5
srhuston
I've been running Splunk for some time, and with a recent update - though I can't say I recall which one - I noticed ...
by srhuston New Member in Installation 02-08-2021
0 0
0
0
rayar
We have the following architecture1 SearchHead1 Cluster Master8 Indexers 1 deployment server  I am now added 2 new in...
by rayar Contributor in Installation 02-07-2021
0 12
0
12
DDAVIDDD
How do I know my server OS can be installed with the SplunkDELL PowerEdge R740 ServerOS version: Redhat linux | Redha...
by DDAVIDDD New Member in Installation 02-06-2021
0 1
0
1
sasankganta
Index=X sourcetype=Y cribl_pipe=Z when I ran for 1week and 24hrs it showed index , sourcetype field with 100% Index=X...
by sasankganta Path Finder in Knowledge Management 02-05-2021
0 13
0
13
RookieNr1
Hello all,I have a problem with which I am currently stuck.Here is a short explanation.For the automated installation...
by RookieNr1 Observer in Installation 02-05-2021
0 0
0
0
chrisitanmoleck
Hello,we are using Splunk v8.1.1I have one user with multiple roles, so he can access multiple indexes and hosts.The ...
by chrisitanmoleck Path Finder in Security 02-04-2021
0 1
0
1
splkadmin
Hello ,we have an application to be monitor through an APM of Splunk, I heard there is a product  of SignalFxwhere to...
by splkadmin Explorer in Installation 02-03-2021
0 0
0
0
dataIngester
I know it is possible to have multiple instances of splunk running on the same machine/server.My question is if there...
by dataIngester Explorer in Installation 02-02-2021
0 1
0
1
splunkreal
Hello guys,tried to update server.conf but Splunk crashed with handshake failure accessing https://localhost:8089[ssl...
by splunkreal Influencer in Security 02-02-2021
0 2
0
2
dlc
I am just getting started with splunk.I want to get the splunk docker container and run splunk under the free license...
by dlc Loves-to-Learn Lots in Installation 02-01-2021
0 1
0
1
MAMAOUI
Hello All,I have Two  errors on the search cluster for ANY search in Splunk. Two errors per indexer:ERROR - Could not...
by MAMAOUI Explorer in Installation 02-01-2021
0 1
0
1
emallinger
Hello everyone, I've got a local universal forwarder on an internal network. (all in linux env)My intermediate forwar...
by emallinger Communicator in Security 02-01-2021
0 5
0
5
saeed
Hi,I would like to increase the cold retention period for index [pa] to 180 days, but when i  get into indexes.conf i...
by saeed Explorer in Knowledge Management 02-01-2021
0 5
0
5
yeahnah
Hi Splunk AdminsJust looking for some advice around setting the data segment size (ulimit -d) in Splunk, on a Linux  ...
by yeahnah Motivator in Installation 01-31-2021
0 1
0
1
karakutu
Hi all, I just want to ask if it makes sense to backup the indexed data before the upgrade of peer nodes (indexer nod...
by karakutu Path Finder in Installation 01-31-2021
0 1
0
1
hadinh
Should we run Splunk as root or non-root user? Which way is better? Thanks -Ha
by hadinh Explorer in Security 01-30-2021
7 9
7
9
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors