Splunk Administration

Splunk Administration
Category Activity
i0ntempest
I just upgraded Splunk to 10.4 (10.2.2 x86_64 to 10.4 arm64) on macOS, and the previously working KVStore now does no...
by i0ntempest Loves-to-Learn in Deployment Architecture yesterday
0 2
0
2
0xAli
Hi Everyone,Anyone integrated the Forcepoint DLP with splunk? What is the proper method? is there any Add-on FP DLP?
by 0xAli Explorer in Getting Data In Tuesday
0 3
0
3
pdominicb
I am about to have a few UFs monitoring some extremely high volume logs. These high volume logs are less critical tha...
by pdominicb Explorer in Getting Data In Sunday
0 8
0
8
spl_aficionado
We have two active-active deployment servers in place. Quite often, apps reach their destination in a week's delay. I...
by spl_aficionado Path Finder in Deployment Architecture Friday
0 9
0
9
VK18
Hi All,We have approximately 100 Splunk Universal Forwarders (UFs) installed at a remote site, and we're interested i...
by VK18 Explorer in Deployment Architecture Friday
0 9
0
9
martaBenedetti
Hi all,I need to migrate heavy forwarders, search head cluster and search head deployer,  cluster manager, license ma...
by martaBenedetti Path Finder in Deployment Architecture Friday
0 4
0
4
pdominicb
I have events with URLs, and the URLs contain parameters with KV values in them. Splunk auto extracts the KV pairs, b...
by pdominicb Explorer in Getting Data In Friday
0 10
0
10
loganallen
I am trying to implement a postfilter in Splunk Connect for Syslog to drop east-west (internal-to-internal) Fortigate...
by loganallen Loves-to-Learn in Getting Data In a week ago
0 0
0
0
Araton71
I've configured my splunk enterprise to get saml login with keycloak.[authentication]authSettings = samlauthType = SA...
by Araton71 Loves-to-Learn in Security a week ago
0 1
0
1
0xAli
Hi,We want to migrate from the ESXI VM to the Hyper-V:Our Initial approach:Fresh OS + Splunk installations on Hyper-V...
by 0xAli Explorer in Deployment Architecture a week ago
0 1
0
1
himanshu2
I have a 2 search heads in a Splunk SH cluster in the dev environment. Recently, I upgraded Splunk from 9.3.8 to 9.4....
by himanshu2 Loves-to-Learn in Deployment Architecture a week ago
0 2
0
2
Karthikeya
We have to pull logs from Tencent COS (Cloud Object Storage) to our Splunk instances which are hosted on AWS. Tencent...
by Karthikeya Communicator in Getting Data In a week ago
0 7
0
7
volly
iv just created a new account.iv have admin role assigned to my user account iv given admin role all permissions, yet...
by volly New Member in Getting Data In a week ago
0 2
0
2
spl_aficionado
We recently found out that we couldn't send TCP data as Syslog because it didn't have the proper header, but streamin...
by spl_aficionado Path Finder in Getting Data In 2 weeks ago
0 4
0
4
wellsjp
We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security ...
by wellsjp Loves-to-Learn Lots in Getting Data In 2 weeks ago
0 5
0
5
licadiw273
Hi everyone, I’ve been hanging around the Splunk community for a while, mostly dealing with application logs, but I’v...
by licadiw273 New Member in Monitoring Splunk 2 weeks ago
0 0
0
0
javier_oshiro
We are currently configuring the DUO security MFA on Splunk Enterprise and we noticed that the local account admin ge...
by javier_oshiro Explorer in Security 2 weeks ago
0 1
0
1
ASierra
There have been reports that the February 2026 MS update kills the RPC call to the Domain Controllers for various ver...
by ASierra Explorer in Monitoring Splunk 2 weeks ago
0 1
0
1
arthy-velusamy
We are trying to ingest JSON data to Splunk Ingest Processor. Sometimes JSON data is getting ingested properly and ma...
by arthy-velusamy Observer in Getting Data In 2 weeks ago
0 1
0
1
jni
Hi,I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".To me, the journald-filte...
by jni Explorer in Getting Data In 2 weeks ago
0 7
0
7
0xAli
Hi Everyone,While using Syslog-NG to monitor network traffic and write it into file,  I want to ask about the Log fil...
by 0xAli Explorer in Getting Data In 2 weeks ago
0 6
0
6
romquestaai_gma
As organizations increasingly adopt AI tools for automation, analytics, and decision-making, protecting sensitive dat...
by romquestaai_gma New Member in Deployment Architecture 2 weeks ago
0 2
0
2
gitau_gm
I am observing inconsistent forwarding of Windows Security Event ID 4624 (Successful Logon) from multiple Windows hos...
by gitau_gm Explorer in Getting Data In 3 weeks ago
0 9
0
9
Hemant0808
PCAP Data contains media and audio file, Is it possible that can be converted to other format and ingest in splunk
by Hemant0808 New Member in Getting Data In 3 weeks ago
0 0
0
0
Khairul_Irsyad
Referring to this  question (Not all Splunk cookies have the HttpOnly tag set) , answered by @anaidu_splunk , I can s...
by Khairul_Irsyad Loves-to-Learn in Security 3 weeks ago
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...

Index This | What is feather-light but cannot be held long?

May 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

.conf26 Registration is Live: Secure Your Early Bird Pass Now

  Lock in Your Spot: Registration Open for .conf26 in Denver Hello Splunkers, I have exciting news! Your ...
Top Karma Authors