Splunk Administration

Splunk Administration
Category Activity
splunkreal
Hello, is Splunk opencti addon compatible on Splunk cluster (shc)?From 2/3 search heads we are getting this error: "2...
by splunkreal Influencer in Getting Data In 10-09-2025
0 2
0
2
Anit_Mathew
Hi team,Is there any way to onboard legacy windows (XP, Server 2000) logs to Splunk, without UF? Specifically non dom...
by Anit_Mathew Engager in Getting Data In 10-08-2025
0 6
0
6
gnagasri
Existing Env :1. Indexer Clustering2. Search head Clustering.For testing an Issue. I have a a standalone searchhead i...
by gnagasri Engager in Getting Data In 10-08-2025
0 3
0
3
KendallW
Hey gang, I'm using the Splunk Add on for Microsoft Azure to ingest AAD signin logs to Splunk under the azure:aad:sig...
by KendallW Contributor in Getting Data In 10-07-2025
0 4
0
4
andrewaalin
What is the significance of the list of fields in "search.log", in the line that contains "INFO LocalCollector - Fin...
by andrewaalin Explorer in Deployment Architecture 10-07-2025
3 2
3
2
Na_Kang_Lim
Hi,So I have a HF instance, which receive multiple types of syslog on many different ports. Ideally, you would have a...
by Na_Kang_Lim Path Finder in Getting Data In 10-06-2025
0 17
0
17
maheshnc
We need to install UF on remote application servers (linux/windows) but as a splunk admin, I don't have direct access...
by maheshnc Path Finder in Getting Data In 10-06-2025
0 8
0
8
deepthi5
splunk query to find how much data is coming via hec , how much data is coming via dbconnect , how much data is comin...
by deepthi5 Path Finder in Getting Data In 10-05-2025
0 3
0
3
Nawab
I am getting below error on my dbconnect, every thing was working fineHTTP Error 400, HEC response body: {"text":"Inv...
by Nawab Communicator in Getting Data In 10-05-2025
0 3
0
3
Ghostoverflow25
Hi,I accidentally uploaded too much data on one day (a jsonl file) and violated the 500mb limit in place for the splu...
by Ghostoverflow25 Engager in Getting Data In 10-05-2025
0 5
0
5
mohsplunking
Hello Splunkers,I have a question around Monitoring a same File from different server, The situation is Server1, Serv...
by mohsplunking Path Finder in Getting Data In 10-05-2025
0 2
0
2
zksvc
I encountered an issue where the Active Directory configuration, despite being set in attack_range.yml, failed to pro...
by zksvc Contributor in Deployment Architecture 10-05-2025
0 0
0
0
mmohamed
Environment Setup:Splunk version: Upgraded from 9.0.7 -> 9.3.3OS:  Upgraded from Oracle Linux 7 (OL7) -> Oracle Linux...
by mmohamed New Member in Other Admin 10-04-2025
0 2
0
2
bapun18
Hi we wanted to migrate standalone indexer  to multisite cluster, with 2 site.Below are my questions1. Can I find out...
by bapun18 Communicator in Deployment Architecture 10-04-2025
0 2
0
2
MMershon
Hello,   Attempting to upgrade our test environment from 9.3.2 to 9.4.0 on Windows Server 2019 fails with the followi...
by MMershon Explorer in Security 10-02-2025
1 1
1
1
Paaattt
Has anyone encountered this issue and how did you fixed it on Splunkcloud and Enterprise Security "Identity: An error...
by Paaattt Explorer in Security 10-02-2025
1 7
1
7
dkeck
Hi,I have an HF running  this akamai integration TA (https://splunkbase.splunk.com/app/4310)I recently updated to 9.4...
by dkeck Influencer in Security 10-02-2025
0 1
0
1
rauldevilla
Hi Guys. I just installed splunk into a server with Ubuntu 14 OS. When I run sudo ./splunk start --accept-license I...
by rauldevilla New Member in Security 10-01-2025
0 3
0
3
GattyBiggz
Greeting,I am trying to identify users who have not had any activity in O365 for over 180 days, however my search is ...
by GattyBiggz Loves-to-Learn in Getting Data In 10-01-2025
0 1
0
1
ivohechmann
Hi all;Regarding the Splunk App for JenkinsWe have multiple jenkins instances in our environment; Each project is in ...
by ivohechmann Explorer in Getting Data In 09-30-2025
0 3
0
3
davidoff96
Some data would be mistagged as a different time zone, or would come in very late and would miss our alarms, since th...
by davidoff96 Path Finder in Getting Data In 09-29-2025
0 1
0
1
frank_yin
My goal is to:1. Default send everything from UF agent (excluded syslog source) to syslog group: chron-autolb group.2...
by frank_yin Loves-to-Learn Lots in Getting Data In 09-26-2025
0 1
0
1
mohsplunking
Hello Splunkers,Appreciate if anyone can help me here, I'm after a Best practices guide/ article for Windows Server L...
by mohsplunking Path Finder in Getting Data In 09-26-2025
0 2
0
2
maheshnc
I need to onboard CISCO IOS switch logs with splunk, we have a syslog-ng installed on HF, could somebody explain the ...
by maheshnc Path Finder in Getting Data In 09-26-2025
0 4
0
4
maheshnc
I need to integrate Dell Switches with Splunk using syslog-ng which is installed on, On-Prem HF, what are the prerequ...
by maheshnc Path Finder in Getting Data In 09-26-2025
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk Asynchronous Forwarding Explained

Splunk asynchronous forwarding is often misunderstood as simply setting autoLBVolume. That is not quite right. ...

55 Days to Go: Secure Your Seat at Splunk University in Denver

Your .conf26 Experience Starts Before Opening Keynote  If Denver is known for its mile-high elevation, Splunk ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...
Top Karma Authors