Splunk Administration

Splunk Administration
Category Activity
bpaul_splunk
I am using self-signed certificates to connect to my search heads using SSL. After upgrading to the latest version o...
by bpaul_splunk Splunk Employee Splunk Employee in Security 09-16-2025
0 4
0
4
utoddl
I have a not-very-complicated query that returns a table of my roles and associated default search indexes. One role ...
by utoddl Explorer in Getting Data In 09-15-2025
0 1
0
1
davidoff96
Hello,We're currently having an issue of SC4S tagging Cisco firepower data as nix:syslog, but I was having this issue...
by davidoff96 Path Finder in Getting Data In 09-15-2025
0 2
0
2
lucacaldiero
Hello,I wanna forward all data from a single HF to two splunk different instances. How can i do that? Thanks #splunk ...
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 10
0
10
lucacaldiero
How can I specify all host or sources in a stanza of props.conf?Thank you @gcusello 
by lucacaldiero Path Finder in Getting Data In 09-15-2025
0 3
0
3
paleewawa
I'm seeing hundreds of these errors in the internal splunkd logs01-16-2025 12:05:00.584 -0600 ERROR UserManagerPro [7...
by paleewawa Explorer in Monitoring Splunk 09-15-2025
0 3
0
3
pmerlin1
Since I migrated splunk to version 9.2.4, I've been getting a lot of error messages from all Splunk servers :WARN Use...
by pmerlin1 Path Finder in Monitoring Splunk 09-15-2025
1 4
1
4
martinb
Hi all,I'm new to Splunk and have been thrown in at the deep end, so apologies if this is the wrong place or a basic ...
by martinb Loves-to-Learn in Knowledge Management 09-15-2025
0 7
0
7
vincentwhn
Due to privacy concerns, I would like to modify the _raw content during the data onboarding phase in order to impleme...
by vincentwhn Engager in Getting Data In 09-15-2025
0 7
0
7
Ghostoverflow25
I have a source of logs that I want to ingest into splunk, where each line documents a seperate event. After having s...
by Ghostoverflow25 Engager in Getting Data In 09-14-2025
0 1
0
1
jackbenimble
What would it take to use something like REST API to pull down documents from Splunk Documentation website? The searc...
by jackbenimble New Member in Getting Data In 09-12-2025
0 1
0
1
hrawat
Apply following workaround in default-mode.confAdditionally you can also push this change via DS push across thousand...
by hrawat Splunk Employee Splunk Employee in Getting Data In 09-12-2025
4 17
4
17
JyPl4wNYu7GV1uL
CentOS 7.7.1908, Splunk  v9.1.0.2I want to get an example event for each sourcetype on each host (excluding one host)...
by JyPl4wNYu7GV1uL Explorer in Getting Data In 09-12-2025
0 4
0
4
kumva01
Hi All,I’m looking for an SPL query that can return the list of Tag Names along with their associated field-value pai...
by kumva01 Loves-to-Learn Lots in Getting Data In 09-12-2025
0 2
0
2
taskmaster
I'm new to Splunk... I'm currently running Splunk on an Ubuntu system.  I've noticed that the /proc directory is show...
by taskmaster Engager in Getting Data In 09-12-2025
0 4
0
4
zksvc
Hi all,I’m trying to enable TLS on Splunk using a DigiCert certificate that I only have as a .pfx. I keep running int...
by zksvc Contributor in Security 09-12-2025
0 1
0
1
mchoudhary
I need to build an overall user activities report as in login activities, file accessed, file exported, application a...
by mchoudhary Explorer in Security 09-11-2025
0 6
0
6
AlexIta95
Good morning,I need to monitor a very long file containing data from 2021 onwards.I'm only interested in data from la...
by AlexIta95 New Member in Monitoring Splunk 09-10-2025
0 3
0
3
Nrsch
Hi, I am installing Splunk UBA 5.4.2 on my laptop in a virtual machine (RHEL 8.8) for testing. I followed the install...
by Nrsch Explorer in Getting Data In 09-10-2025
0 2
0
2
srek3502
Hi,I have a requirement to implement the Splunk Monitoring Console (DMC) in a High Availability (HA) setup. At presen...
by srek3502 Explorer in Deployment Architecture 09-10-2025
0 5
0
5
L_Petch
Hello, I am trying to get logs from my opnsense FW to go to an index called prod_opnsense but everything I have tried...
by L_Petch Path Finder in Getting Data In 09-10-2025
0 1
0
1
rk99
Hi - we have been sending data from our K8s cluster to splunk hwf which then forwards to the indexer.  It works great...
by rk99 Explorer in Getting Data In 09-10-2025
0 3
0
3
dr_juice
Is there any form of automation where we would be able to identify if one of our hosts stopped sending logs to splunk...
by dr_juice Explorer in Monitoring Splunk 09-10-2025
0 1
0
1
kramer0101
We are looking at bringing in Semperis DSP logs to evaluate them. Is there documentation on sending those logs to Spl...
by kramer0101 Engager in Getting Data In 09-09-2025
0 2
0
2
inventsekar
Hi As all my splunk projects are using LDAP for login, this issue never occurred to me. 1. if we configure splunk's l...
by SplunkTrust SplunkTrust in Security 09-09-2025
0 6
0
6
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Karma Authors