Splunk Administration

Splunk Administration
Category Activity
SN1
So i have a search which show the indexes that have 0 events last 24hr.  I want to send this result as an alert to mi...
by SN1 Path Finder in Monitoring Splunk 12-12-2025
0 4
0
4
krynol
After upgrading to UF 10.0 we see many Application Error (EventCode=1000) crashes on a subset of servers only. Faulti...
by krynol Engager in Getting Data In 12-10-2025
1 5
1
5
brentrmc
I've been tasked with using btool (in debug mode) to find where the settings for the “onboarding” index was written b...
by brentrmc Explorer in Getting Data In 12-09-2025
0 7
0
7
kgiri253
I am on-boarding data from 6 different locations the data flow is Splunk Forwarder  ------> DMZ Server (Intermediate ...
by kgiri253 Explorer in Getting Data In 12-08-2025
0 5
0
5
Prakash493
Hi , i have a indexer cluster of 3 indexers and 2 search heads are in a cluster and having the pass4symmkey. Which au...
by Prakash493 Communicator in Security 12-08-2025
0 4
0
4
leenguyen07
If anyone out there has any relevant experience and could share some advice/guidance, that would be great. Thanks!
by leenguyen07 Explorer in Getting Data In 12-08-2025
0 8
0
8
jatin3101
I was just going thorugh the guide to integrate  the searchhead cluster and indexer cluster . So the last step is to ...
by jatin3101 Engager in Deployment Architecture 12-08-2025
0 4
0
4
Iris_Pi
Hello Splunkers!Your help is appreciated!I have a log source coming into Splunk via HEC. The log is in json format, i...
by Iris_Pi Path Finder in Getting Data In 12-08-2025
0 5
0
5
ThuLe
Hello,I have  HF and UF act as intermediate forwarders and forward logs to Splunk Cloud. We installed the credentials...
by ThuLe Explorer in Getting Data In 12-07-2025
0 3
0
3
Andre_
Hello,Veeam App for Splunk how do you install/configure the Veeam App in a distributed environment? Search Head Clust...
by Andre_ Path Finder in Deployment Architecture 12-07-2025
0 3
0
3
meoo
Hi We are planning to automate the Splunk application installation and configuration process for quicker provisionin...
by meoo Explorer in Getting Data In 12-04-2025
2 10
2
10
verbal_666
Hi.OK, this question is totally theory, but i came in case of pratical issue on such problem.So, let's think i have a...
by verbal_666 Builder in Getting Data In 12-04-2025
1 7
1
7
SN1
this message is displaying in the splunkd logs on syslog server.we are forwarding data from syslog server to DMZ serv...
by SN1 Path Finder in Monitoring Splunk 12-03-2025
0 2
0
2
selyian
General question about polling frequency and licensing. Let's say I have about 4 million events in regards to pulling...
by selyian Splunk Employee Splunk Employee in Getting Data In 12-02-2025
0 0
0
0
Andre_
Hello,we encountered a situation today where a monitored Windows Drive disappeared from Spunk.The drive had become co...
by Andre_ Path Finder in Getting Data In 12-02-2025
0 1
0
1
Singhk1
hi All, Got a very strange issue.  DS version 9.4.5. OS rhel 8+DS is not deploying app to clients. Deploy server is e...
by Singhk1 Engager in Deployment Architecture 12-02-2025
0 2
0
2
imKaren
i want to ask one detailed question as a normal user who interacts with splunk on a daily basis without touching deve...
by imKaren New Member in Security 12-01-2025
0 1
0
1
robxzy
Hei,Getting these messages constantly: Splunk Version 9.4.0 - Running on WindowsLogFile: python.log2025-01-31 23:24:1...
by robxzy New Member in Deployment Architecture 12-01-2025
0 1
0
1
nunoaragao
Hi Splunkers,Long time ago we setup a SH cluster, and added search peers using CLISome time later we changed the setu...
by nunoaragao Path Finder in Getting Data In 12-01-2025
0 1
0
1
msmadhu
We are attempting to upgrade Splunk Universal Forwarders using the UF Remote Upgrade Add-on.As per Splunk documentati...
by msmadhu Path Finder in Deployment Architecture 12-01-2025
0 5
0
5
dantimola
Hi, Splunkers, Can someone suggest what is the best practice to integrate Citrix mcs to Splunk? Our case is, we can'...
by dantimola Communicator in Deployment Architecture 11-27-2025
0 3
0
3
ankit13
I am trying to integrate an Oracle database with Splunk using DB Connect. When I attempt to create an input in Data L...
by ankit13 Loves-to-Learn Lots in Security 11-26-2025
0 1
0
1
gteccr
Hello, We have been reported that there is an open vulnerability with openssl for SplunkUniversal Forwarder, as descr...
by gteccr Explorer in Monitoring Splunk 11-26-2025
0 7
0
7
yh
Hi,I have this unusual problem where I am trying to modify the host name in my windows log (text file ingestion) in m...
by yh Path Finder in Getting Data In 11-25-2025
0 6
0
6
hrawat
CHECK_METHOD = modtime is not working as expected due to a regression in 9.x as there is wrong calculation which will...
by hrawat Splunk Employee Splunk Employee in Knowledge Management 11-25-2025
2 2
2
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...
Top Karma Authors