Find Answers

Find Answers
Ask questions. Get answers. Find technical product solutions from passionate members of the Splunk community.
Category Activity
cipher
Hi,I’ve set up an alert in Splunk that triggers whenever there are log gaps (missing logs) from hosts, based on the R...
by cipher Explorer in Splunk Search 03-23-2026
0 1
0
1
Alberto_Astolf1
Dear all,could you please tell me how often the Universal Forwarder checks for and downloads the configuration file f...
by Alberto_Astolf1 Explorer in Monitoring Splunk 03-23-2026
0 21
0
21
spl_aficionado
This subject keeps baffling us - Can I configure restartSplunkd to true for all applications? One thing we saw is tha...
by spl_aficionado Path Finder in Getting Data In 03-23-2026
0 3
0
3
KevHaze
When trying to download this app into my splunk cloud10.2 environment, I get the error message:Invalid app contents: ...
by KevHaze Explorer in Splunk Cloud Platform 03-23-2026
0 5
0
5
MJ_27
I'm trying to figure out when some of my correlation searches was created ?i tried it with rest, but only getting upd...
by MJ_27 New Member in Splunk Search 03-23-2026
0 3
0
3
ra_52194724
I'm trying to extract fields using regex based on the condition.Below are the raw payload. {"group_id": "aa2211-3b22-...
by ra_52194724 Explorer in Splunk Enterprise 03-23-2026
0 9
0
9
imsidrai
i need help in setting up federated search , the requirement is that i want to run some splunk search from dbconnect ...
by imsidrai Explorer in Splunk Search 03-22-2026
0 3
0
3
detrue
I have a distributed deployment with a SHC and a IC.  I have added the index to the manager and pushed the new index ...
by detrue New Member in Deployment Architecture 03-22-2026
0 2
0
2
Narendra_Rao
Does AppDynamics Python Agent 25.10.0.8329 support AI auto-instrumentation only for official OpenAI/Bedrock/LangChain...
by Narendra_Rao Loves-to-Learn Lots in Splunk AppDynamics 03-22-2026
0 0
0
0
ra_52194724
i want to extract last word in resource_id field from below events.      
by ra_52194724 Explorer in Splunk Enterprise 03-21-2026
0 2
0
2
fedayn05
Hello Team,I hope you are doing well. Recently i am going through a critical issue on my splunk entreprise. I used to...
by fedayn05 Path Finder in Getting Data In 03-21-2026
0 4
0
4
JordanPeterson
I have a fresh install of 7.0.x in our QA environment to test with. I have an indexer/search head/deployment server r...
by JordanPeterson Path Finder in Getting Data In 03-21-2026
0 7
0
7
LovingSplunk
We are at 10 indexers ingesting around 400 GBs/day. A homogeneous environment with 1 millisecond wait time (I/O Write...
by LovingSplunk Path Finder in Deployment Architecture 03-20-2026
0 12
0
12
manchou0709
Hi All,I am bit new to Splunk. In my current project,  there are around 69,000+ universal forwarders. I need to perfo...
by manchou0709 Explorer in Splunk Enterprise 03-20-2026
0 12
0
12
icarvaja
Hi,I am trying to validate connectivity to the official Splunk MCP Server app before integrating it with an MCP clien...
by icarvaja Engager in All Apps and Add-ons 03-20-2026
1 1
1
1
splunkreal
Hello, we haveSplunk Add-on for Check Point Log Exporter ( https://splunkbase.splunk.com/app/5478 ) Built by Splunk L...
by splunkreal Influencer in Getting Data In 03-20-2026
0 3
0
3
aohls
I am working on migrating some items over to dashboard studio. I have a very simple stats command getting a few count...
by aohls Contributor in Dashboards & Visualizations 03-20-2026
0 6
0
6
splunklearner
Hello all,I have an ask to create a sample dashboard with the data present. Hence I have created following panels wit...
by splunklearner Communicator in Dashboards & Visualizations 03-19-2026
0 6
0
6
raymondteledata
Hi ,   Can i Use this  alerts@splunkcloud.com email for Splunk Enterprise on prem installed as alert sender email? 
by raymondteledata New Member in Splunk Enterprise 03-19-2026
0 4
0
4
tsa
We are observing delayed ingestion of logs from neuvector application, via syslog method 
by tsa New Member in Splunk Enterprise Security 03-19-2026
0 3
0
3
radko
Hello. I have the following issue: I can't make splunk index GPU data in a metrics index. On the GPU server I have a ...
by radko Explorer in Getting Data In 03-19-2026
0 4
0
4
eddieddieddie
Hi,I'm attempting to configure a Universal Forwarder on a Windows server behind a proxy to send data via S2S over htt...
by eddieddieddie Path Finder in Getting Data In 03-19-2026
0 9
0
9
mcaulsc
I'm trying to create an alert based on a field as shown below, I want to search for the EDC5133I text. However the TE...
by mcaulsc Path Finder in Splunk Search 03-18-2026
0 6
0
6
nckncklogrhythm
Has anyone used the TA publish to Confluence app to specifically, create and publish new pages within confluence? The...
by nckncklogrhythm Explorer in All Apps and Add-ons 03-18-2026
0 1
0
1
dwoehr
Sorry for bringing this up again, but the other questions haven't been answered yet in a way that would help us. I'm...
by dwoehr Explorer in Getting Data In 03-18-2026
1 17
1
17
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...
Top Karma Authors