Monitoring Splunk

Monitoring Splunk
Community Activity
Balshore
ERROR TcpOutputFd [TcpOutEloop] - Read error. An existing connection was forcibly closed by the remote host.I have th...
by Balshore Loves-to-Learn Lots in Monitoring Splunk 4 weeks ago
0 6
0
6
JohnEGones
Hi folks, Just a hopefully quick and basic question, I read the following two docs but I am still not quite clear on ...
by JohnEGones Communicator in Monitoring Splunk 06-25-2026
0 3
0
3
licadiw273
Hi everyone, I’ve been hanging around the Splunk community for a while, mostly dealing with application logs, but I’v...
by licadiw273 New Member in Monitoring Splunk 06-17-2026
0 1
0
1
Wohamed_wakkad
"I am writing this thread to summarize the Monitoring Console (MC) configuration and highlight the non-obvious nuance...
by Wohamed_wakkad Explorer in Monitoring Splunk 06-15-2026
0 2
0
2
ikulcsar
Hi there, I'm building a test Splunk deployment: 3 SH in cluster, 2x2 IX in multi-site cluster, 1 admin node(CM, Dep...
by ikulcsar Communicator in Monitoring Splunk 06-13-2026
0 9
0
9
narenrecw
How to set up the ' Personal Access Token' using the trial account 
by narenrecw New Member in Monitoring Splunk 06-07-2026
0 2
0
2
ASierra
There have been reports that the February 2026 MS update kills the RPC call to the Domain Controllers for various ver...
by ASierra Explorer in Monitoring Splunk 05-13-2026
0 1
0
1
mgaraventa_splu
In my use-case my source log (tailed by a monitor input stanza) is being archived once a day at midnight and the resu...
by mgaraventa_splu Splunk Employee Splunk Employee in Monitoring Splunk 05-05-2026
3 3
3
3
splunker_ak
On our SOC operations dashboard we can already see the overall MTTD (Mean Time to Detect) and MTTT (Mean Time to Tria...
by splunker_ak Explorer in Monitoring Splunk 04-13-2026
0 4
0
4
Darkvader
Search peer appprd09 has the following message: The current bundle directory contains a large lookup file that might ...
by Darkvader Explorer in Monitoring Splunk 04-01-2026
0 1
0
1
Chris_Urman
I'm setting up Dynatrace synthetic monitors to replicate user experience in Splunk and I am having trouble getting a ...
by Chris_Urman Engager in Monitoring Splunk 03-26-2026
0 4
0
4
cesaccenturefed
sometimes you just dont want to navigate from user menu to roles menu, then to index access listing. i'd like to just...
by cesaccenturefed Path Finder in Monitoring Splunk 03-26-2026
0 2
0
2
Alberto_Astolf1
Dear all,could you please tell me how often the Universal Forwarder checks for and downloads the configuration file f...
by Alberto_Astolf1 Explorer in Monitoring Splunk 03-23-2026
0 21
0
21
hartsoftware
I'm seeing many action=restart_splunkd messages from my "_audit" index. I can tell from my processor status that splu...
by hartsoftware Engager in Monitoring Splunk 03-17-2026
2 11
2
11
AntoineDRN
Hello Splunkers,   I'm here to ask you for a bit or your wisdom. Context : This happens since the upgrade from 8.2.x ...
by AntoineDRN Path Finder in Monitoring Splunk 03-09-2026
0 3
0
3
miguelmail1314
Hi, How to display a procedure (KB) associated with the Splunk alert, i have tu use SPL ? Do you have a client exampl...
by miguelmail1314 Explorer in Monitoring Splunk 03-05-2026
0 6
0
6
jadengoho
Hi , Why are we receiving this kind of issue on "o365:cas:api"while the others listed below are working as expected. ...
by jadengoho Builder in Monitoring Splunk 02-19-2026
0 3
0
3
splunkreal
Hello, if you have license usage error when running a query on license logs, it can be based on Splunk server.conf se...
by splunkreal Influencer in Monitoring Splunk 02-19-2026
0 1
0
1
zapping575
We have setup SAML authentication using MS Azure as IDP using the following instructions:https://help.splunk.com/en/s...
by zapping575 Communicator in Monitoring Splunk 02-19-2026
0 2
0
2
e_charles
I'm working with a Customer who has  some questions in regards how the # Active host are being counted specifically f...
by e_charles New Member in Monitoring Splunk 02-13-2026
0 0
0
0
esalesapns2
Our indexers are reporting “server-busy” errors back to the kinesis data firehoses periodically.This is an indication...
by esalesapns2 Communicator in Monitoring Splunk 02-09-2026
0 3
0
3
b17gunnr
Hello folks,I have a compliance control requirement to alert when there is a log ingestion failure to Splunk. The des...
by b17gunnr Path Finder in Monitoring Splunk 02-09-2026
0 6
0
6
marcokrueger
I give my splunk 50GB Mem with max_mem_usage_mb = 50480 in the limits.conf but splunk 5.0.3 gives me a "mvexpand out...
by marcokrueger Path Finder in Monitoring Splunk 02-02-2026
1 15
1
15
loganallen
Hi All, I have SOC metric reporting dashboards for MTTR (mean time to respond) and MTTC (mean time to close) but am s...
by loganallen Loves-to-Learn in Monitoring Splunk 01-31-2026
0 2
0
2
R15
Recently upgraded to 9.2.2 and Historic License Usage panels in the Monitoring Console are now broken. The panels in ...
by R15 Communicator in Monitoring Splunk 01-22-2026
0 4
0
4
Get Updates on the Splunk Community!

Federated Search for Snowflake Is Now Generally Available on Splunk Cloud Platform

Unlocking Data-In-Place Search Across Splunk and Snowflake  Enterprise data is increasingly distributed across ...

Help Us Build Better Splunk Regex Puzzles (And Win Prizes!)

If you’ve spent any time in the Splunk Community Slack, you’ve likely seen our resident Splunk Trust ...

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...