Splunk Administration

Splunk Administration
Category Activity
ARC1
Can you clarify Splunk Data Lake support around schema (schema-on-read vs enforced), available APIs for ingest/query,...
by ARC1 Loves-to-Learn in Deployment Architecture yesterday
0 10
0
10
falcon
I have multiple fields under the interesting fields section named field1, field2, field3, and so on. Each of these fi...
by falcon Observer in Getting Data In yesterday
0 4
0
4
danielbb
I want to add vault logs to my inputs.conf for the Google Workspace TA. I added the following stanza[activity_report:...
by danielbb Motivator in Getting Data In yesterday
0 1
0
1
maheshnc
Hello,I need to upgrade the o365 add-On to the latest version on both the search head and the heavy forwarder, can so...
by maheshnc Path Finder in Getting Data In yesterday
0 5
0
5
drggfish1
I am trying to configure the Splunk Add-on for AWS for brining in CloudTrail logs via SQS S3. I have the following Us...
by drggfish1 Explorer in Getting Data In yesterday
0 3
0
3
Poojitha
Hi All,I have a requirement  where I have to write metrics data to metrics index from existing events index as soon a...
by Poojitha Communicator in Getting Data In Wednesday
0 3
0
3
splunkisaurus
Greetings,    I am trying to create a little TA to run a command to collect status for the nessus agent. I have it to...
by splunkisaurus New Member in Getting Data In Tuesday
0 12
0
12
andrewtrobec
Hello!I am working with version 4.1.3 (latest) of the Splunk Add-on for Microsoft Cloud Services that is installed on...
by andrewtrobec Motivator in Getting Data In Tuesday
0 10
0
10
yuanliu
I am onboarding a JSON dataset whose event size is very close to 1MB.  I have to increase TRUNCATE to 1000000 (from d...
by SplunkTrust SplunkTrust in Getting Data In Monday
0 2
0
2
Space_Crawler
Hi, I have recently changed the OS hostname, followed by Splunk hostname change on a single node deployment. I am sti...
by Space_Crawler Observer in Monitoring Splunk Monday
0 3
0
3
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In Sunday
0 1
0
1
shinigami35
Hello Everyone, I need your help about a problem with Splunk HEC. I use the endpoint "event" to send logs into multip...
by shinigami35 Explorer in Getting Data In a week ago
0 14
0
14
nonno_pinto
I have a local Splunk Enterprise with free license. I'm trying to connect AI Toolkit with my GPT token, but returns t...
by nonno_pinto Explorer in Security a week ago
0 4
0
4
dsfyxcasdcertzu
We're updating our Linux Servers to Debian 12. A few host went "missing" afterwards in Splunk.While investigating int...
by dsfyxcasdcertzu Explorer in Getting Data In 2 weeks ago
0 4
0
4
ThuLe
Hello everyone,We are using a Universal Forwarder (UF) as an intermediate forwarder to send logs from other UFs in ou...
by ThuLe Explorer in Getting Data In 2 weeks ago
0 1
0
1
drggfish1
I am getting a mismatch between the version of OPENSSL installed on my OS and in the Universal Forwarder. It seems to...
by drggfish1 Explorer in Getting Data In 2 weeks ago
0 5
0
5
shashankk
I am trying to setup Splunk choropleth world map for the first time.Refer below splunk query:index=app_events_test so...
by shashankk Communicator in Security 2 weeks ago
0 3
0
3
NoSpaces
Have a nice day, everyone!For continuous event truncation tracking, I have a simple alert that notifies me about trun...
by NoSpaces Contributor in Getting Data In 2 weeks ago
0 2
0
2
CHIBUIKEM
Hello Everyone,  please for the past four weeks I have been struggling with ensuring that the Universal splunk Forwar...
by CHIBUIKEM Engager in Getting Data In 2 weeks ago
0 3
0
3
richah
I am hired in an organization as a Splunk architect, and I need to start with onboading data. I don't know much about...
by richah Explorer in Getting Data In 2 weeks ago
0 8
0
8
onlyenz404
Hi. I've asked this question in the Splunk Connect for Syslog GitHub repository as it relates to that product, but fo...
by onlyenz404 New Member in Getting Data In 2 weeks ago
0 1
0
1
wayne333
Hi,I was recieving fortigate log just fine when i was using the below config in the env file.SC4S_SOURCE_TLS_ENABLE=y...
by wayne333 Explorer in Getting Data In 2 weeks ago
0 1
0
1
mmendez-opentec
Hello,I'm trying to access the Data Management Experience and specifically Edge Processors. Our company has Splunk En...
by mmendez-opentec Explorer in Getting Data In 2 weeks ago
0 0
0
0
atari1050
Hello Splunk Gurus- We have noticed that a Splunk job does not end gracefully (version 6.6.3) if the post-pipe comma...
by atari1050 Path Finder in Getting Data In 2 weeks ago
0 3
0
3
viewpost_rgora
I am trying to install my Dev License to my local Splunk Instance but am getting the following error. Splunk.License:...
by viewpost_rgora Explorer in Installation 3 weeks ago
4 15
4
15
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...
Top Karma Authors