Splunk Administration

Splunk Administration
Category Activity
AAlhabba
Dears,       After upgraded Splunk from 9.1.2 version to 9.2.0 version, the deployment server not showing the clients...
by AAlhabba Explorer in Deployment Architecture 55m ago
1 26
1
26
RAVISHANKAR
Hello,Planning to Upgrade Splunk Enterprise from version 9.2.1 to latest version 9.4.2 - So can a 9.4.2 latest versio...
by RAVISHANKAR Loves-to-Learn Lots in Installation 3 hours ago
0 3
0
3
meg
My linux logs cannot parsed in dashboard. My renderxml is setted to false 
by meg Observer in Getting Data In 6 hours ago
0 3
0
3
mbissante
Hi,I need to upgrade Splunk v.8.2.2.1 on RHEL 7.6 to Splunk v.9.4 on RHEL 9.6.I saw that Splunk 8.2 does not support ...
by mbissante New Member in Deployment Architecture 6 hours ago
0 2
0
2
Pete_
Hello,I am having issues getting data into Splunk Cloud with two new Universal forwarders.I have two existing Univers...
by Pete_ Explorer in Getting Data In yesterday
0 7
0
7
untieshoe
I don't mean SharePoint activity, admin or audit logs. I mean actual data files (that will be converted later to look...
by untieshoe Path Finder in Getting Data In yesterday
0 3
0
3
splunklearner
Jun 26 13:46:12 128.23.84.166 [local0.err] <131>Jun 26 13:46:12 GBSDFA1AD011HMA.systems.uk.fed ASM:f5_asm=PROD vs_na...
by splunklearner Communicator in Getting Data In yesterday
0 6
0
6
danielbb
I came across in our repo a monitoring stanza for f5, which is [UDP://9514]. I wonder if there is any reason not to u...
by danielbb Motivator in Getting Data In yesterday
0 3
0
3
danielbb
We would like to produce statistics about the usage of Splunk and we would like to categorize the searches by ranges,...
by danielbb Motivator in Monitoring Splunk yesterday
0 3
0
3
LOP22456
Hello,I have a request from a systems manager related to SOX controls. They are requesting information around the loc...
by LOP22456 Engager in Security yesterday
0 2
0
2
splunkreal
Hello, is it possible in Splunk HEC from Kafka to receive raw events on HF in order to parse fields with addons?It se...
by splunkreal Motivator in Getting Data In yesterday
0 4
0
4
L_Petch
Hello,2 questions but the second is more of a keepalived question than it is an SC4S question.First question is what ...
by L_Petch Path Finder in Deployment Architecture yesterday
0 4
0
4
Kosyay
Hello! I have logs from Domain Controller Active Directory in Splunk and try to configure monitoring of user logons (...
by Kosyay Engager in Getting Data In Wednesday
0 5
0
5
Runals
This information is probably located in one of the docs but didn't find it in anything I've read just now. Under norm...
by Runals Motivator in Getting Data In Wednesday
0 6
0
6
kn450
Hello everyone,I have a network monitoring system that exports data via IPFIX using Forwarding Targets.I am trying to...
by kn450 Explorer in Getting Data In Wednesday
0 0
0
0
karn
I have a question about modify kvstore configuration in search head cluster environment. I have created kvstore with ...
by karn Path Finder in Deployment Architecture Wednesday
0 4
0
4
meng
I use metadata to monitor the activity status of member nodes in my cluster, but recently I discovered an exception. ...
by meng New Member in Monitoring Splunk Wednesday
0 2
0
2
chrisyounger
I have a data source of significant size and I want to filter a large percentage of the data on the UF so it isnt sen...
by SplunkTrust SplunkTrust in Getting Data In Tuesday
0 1
0
1
DarthHerm
Thought I would post here in the community as well since I have this opened with support. A couple weeks ago, another...
by DarthHerm Explorer in Getting Data In Tuesday
0 4
0
4
_pravin
Hi,I am using mcollect to collect data from certain metrics into another metric index. I have created the new metric ...
by _pravin Contributor in Getting Data In Tuesday
0 4
0
4
LOP22456
Hello,We have multiple fortigate devices forwarding to a logstash server that is storing all the device's logs in 1 f...
by LOP22456 Engager in Getting Data In Tuesday
0 5
0
5
zksvc
Hi Everyone, in default correlation search the name "Excessive Failed Logins" my drilldown cannot define $info_min_ti...
by zksvc Communicator in Deployment Architecture Monday
1 7
1
7
sdiaz5796
We have a stand-alone splunk instance in a closed area. We had to roll back the server to a snapshot and now the clie...
by sdiaz5796 Loves-to-Learn in Deployment Architecture Monday
0 5
0
5
yash_eng
Hey mates, I'm new to Splunk and while ingesting the data from my local machine to Splunk this message shows up."The ...
by yash_eng New Member in Getting Data In Monday
0 3
0
3
Anders333
Hello, I have a Windows machine with an UF installed that logs various logs such as wineventlog. These logs work corr...
by Anders333 Explorer in Getting Data In Monday
0 8
0
8
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security and Observability Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...
Top Karma Authors