Splunk Administration

Splunk Administration
Category Activity
harman
i am uploading the data in the text format and that data contains logs but when i successfully upload the data of par...
by harman Explorer in Getting Data In 02-18-2026
0 5
0
5
leykevin
Is there any possibility that the app could be released for Version 10?
by leykevin New Member in Deployment Architecture 02-18-2026
0 2
0
2
eddieddieddie
I'm trying to measure the amount of data leaving a heavy forwarder (called HVYFWD01).This is in preparation to moving...
by eddieddieddie Path Finder in Getting Data In 02-17-2026
0 1
0
1
ilhwan
I'm trying to rewrite the host field on events that are coming into a HEC on a HF.  It's populating the hostname of t...
by ilhwan Path Finder in Getting Data In 02-17-2026
0 8
0
8
triptraptresko
After completing the upgrade from Splunk Enterprise version 9.3.3 to v9.4 the KVstore will no longer start. Splunk ha...
by triptraptresko Path Finder in Deployment Architecture 02-17-2026
7 3
7
3
AceX
Cannot read properties of undefined (reading '0') (error(s) 1/1)
by AceX Path Finder in Deployment Architecture 02-16-2026
1 2
1
2
sswigart
My network has Splunk Enterprise 10.0.2, and it is air-gapped.I want to run a Linux and Windows enterprise server sid...
by sswigart Explorer in Getting Data In 02-16-2026
0 4
0
4
dania_abujuma
Hello, I have a question regarding the indexer cluster, can we have 2 peers hosted in different networks / sites? Of ...
by dania_abujuma Explorer in Deployment Architecture 02-16-2026
0 1
0
1
e_charles
I'm working with a Customer who has  some questions in regards how the # Active host are being counted specifically f...
by e_charles New Member in Monitoring Splunk 02-13-2026
0 0
0
0
Abass42
I would like to know how to properly configure my kvstore stanza to use my own self generated Server/Client authentic...
by Abass42 Communicator in Deployment Architecture 02-11-2026
0 3
0
3
spl_aficionado
@richgalloway explained clearly in the post, that INDEXED_EXTRACTIONS=CSV makes all the fields indexed. What would be...
by spl_aficionado Path Finder in Getting Data In 02-10-2026
0 1
0
1
spl_aficionado
I just set INDEXED_EXTRACTIONS = CSV for a large data ingestion sourcetype, and validating with tstats, and it seems ...
by spl_aficionado Path Finder in Getting Data In 02-09-2026
0 2
0
2
esalesapns2
Our indexers are reporting “server-busy” errors back to the kinesis data firehoses periodically.This is an indication...
by esalesapns2 Communicator in Monitoring Splunk 02-09-2026
0 3
0
3
b17gunnr
Hello folks,I have a compliance control requirement to alert when there is a log ingestion failure to Splunk. The des...
by b17gunnr Path Finder in Monitoring Splunk 02-09-2026
0 6
0
6
adnankhan5133
Hi,Does anyone know how to ingest the WAF logs generated by the Oracle Cloud Web Application Firewall service? The lo...
by adnankhan5133 Communicator in Getting Data In 02-09-2026
0 2
0
2
cmeo-bcit
I see from the latest release notes that the recommended sourcetype is ms:iis:auto and the others have been deprecate...
by cmeo-bcit Explorer in Getting Data In 02-08-2026
0 4
0
4
Navanitha
I am trying to forward win event security logs from server using UF to our Heavy forwarder.  UF has all the required ...
by Navanitha Path Finder in Getting Data In 02-06-2026
0 4
0
4
muradgh
I have a Fortigate firewall that was configured to send UDP logs, lately, I have configured it to send TCP logs inste...
by muradgh Path Finder in Getting Data In 02-06-2026
1 20
1
20
StuartMacL
I have the Splunk add-on for Amazon Web Services v 8.0.0 installed on a Heavy Forwarder and we have several inputs wo...
by StuartMacL Path Finder in Getting Data In 02-06-2026
0 1
0
1
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In 02-05-2026
0 3
0
3
Poojitha
Hi Everyone, I have created a custom app that clones current raw data , extracts metrics and dimensions from existing...
by Poojitha Communicator in Getting Data In 02-04-2026
0 2
0
2
marcokrueger
I give my splunk 50GB Mem with max_mem_usage_mb = 50480 in the limits.conf but splunk 5.0.3 gives me a "mvexpand out...
by marcokrueger Path Finder in Monitoring Splunk 02-02-2026
1 15
1
15
danielbb
We recently experienced a data gap for our Google index lasting several days. Our environment uses the following two ...
by danielbb Motivator in Getting Data In 02-02-2026
0 1
0
1
GSNRMUVW
Hi Community,how to cut..., "q": 0, "user": "system.user.admin"...from...{ "val": 0, "ts": 1770058561014, "q": 0, "us...
by GSNRMUVW Loves-to-Learn in Getting Data In 02-02-2026
0 6
0
6
briancronrath
I have been tasked with building out new instances of anything that runs an older OS, and for our EC2 instances this ...
by briancronrath Contributor in Getting Data In 02-02-2026
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...
Top Karma Authors