Splunk Administration

Splunk Administration
Category Activity
inventsekar
Hi As all my splunk projects are using LDAP for login, this issue never occurred to me. 1. if we configure splunk's l...
by SplunkTrust SplunkTrust in Security 09-09-2025
0 6
0
6
d_lim
Are we able to ingest into Splunk the config change events such as the attached image, using "Proofpoint On Demand Em...
by d_lim Path Finder in Getting Data In 09-09-2025
0 1
0
1
gcusello
Hi at all,I have to parse Juniper Switch logs that are very similar to Cisco ios.In the Juniper Add-On there isn't an...
by SplunkTrust SplunkTrust in Getting Data In 09-09-2025
0 4
0
4
sirisha
I’m currently instrumenting a .NET application to send telemetry to Splunk Observability Cloud using the Splunk Distr...
by sirisha New Member in Getting Data In 09-09-2025
0 0
0
0
Na_Kang_Lim
Hi,I am configure the apps on the UF from a Deploy Server, and get this weird behavior:What I am trying to do is assi...
by Na_Kang_Lim Path Finder in Getting Data In 09-08-2025
0 3
0
3
gsiebert
Environment- Splunk Enterprise 10.0.0 (Ubuntu 24.04), single VM (indexer+SH+Stream)- splunk_app_stream 8.1.5, Splunk_...
by gsiebert New Member in Getting Data In 09-08-2025
0 0
0
0
roshanadabala
I have added a New SAML group and assigned a role which was created before with limited privileges/capabilities and a...
by roshanadabala Observer in Security 09-07-2025
0 3
0
3
karol
I got my data stream in a following format:[ { "name": "event 1" "attributes": [false, true, true...
by karol Engager in Getting Data In 09-07-2025
0 1
0
1
_Raj
Hi,I want to install the BOTS v3 dataset on Splunk 10.0 in Windows OS. Is it compatible with this version? If yes, ho...
by _Raj Path Finder in Getting Data In 09-06-2025
0 2
0
2
huynha
In my indexer cluster, one of my indexers has inflight files in the cold and warm storage that range from 1.5-2 month...
by huynha Explorer in Deployment Architecture 09-05-2025
1 4
1
4
bigchungusfan55
I am having issues trying to outputlookup to a new empty KV Store lookup table I made. When I try to run the followin...
by bigchungusfan55 Explorer in Knowledge Management 09-05-2025
0 6
0
6
asees
I’m working with CEF logs in Splunk where some fields contain comma-separated values.GoalFind a generic solution so t...
by asees Explorer in Security 09-05-2025
0 7
0
7
Raghavsri
we have one HF , configured to routing into 3 destinations 2 * syslogNG1* Splunk HF clusterour requirement is to drop...
by Raghavsri Loves-to-Learn Lots in Getting Data In 09-04-2025
0 2
0
2
umd06
 I’m trying to split my Windows events so that:All events get forwarded to a syslog server.Only certain Event IDs (ex...
by umd06 Engager in Getting Data In 09-04-2025
0 2
0
2
Raffaele53
Hello,I’m using Cribl Cloud to pull JSON events from an Azure Event Hub and forward them to Splunk via HEC.Each incom...
by Raffaele53 Loves-to-Learn in Getting Data In 09-04-2025
0 6
0
6
dersonje2
Hello,I'm not finding info on the limits within Splunk's data rebalancing. Some context, I have ~40 indexers and stoo...
by dersonje2 Engager in Knowledge Management 09-04-2025
0 4
0
4
thekevinkalis
Hi all, sorry if this has been asked before, but my initial searches haven't turned up anything.I'm fairly new to Spl...
by thekevinkalis Engager in Getting Data In 09-04-2025
0 4
0
4
DanAlexander
Why SC4S over a generic “syslog servers tier”1. It is Splunk’s best practice todaySplunk Validated Architectures call...
by DanAlexander Communicator in Deployment Architecture 09-03-2025
0 1
0
1
msunilreddy
Hi Team,  How to get last 5 mins triggered alerts and its data like host, source, sourcetype, message, etc fields usi...
by msunilreddy New Member in Getting Data In 09-02-2025
0 1
0
1
msunilreddy
Hi Team,   I got one trail account from Splunk Cloud. I need to access below API.services/saved/searchesBut when I tr...
by msunilreddy New Member in Getting Data In 09-02-2025
0 1
0
1
spisiakmi
Hi, can anybody help, please?Description of very simple problem| makeresults | eval tmp1=1, tmp2=1| table tmp1, tmp2H...
by spisiakmi Contributor in Knowledge Management 09-01-2025
0 2
0
2
dheld
When I try to access the Splunk web interface over HTTPS I get the error: ERR_SSL_VERSION_OR_CIPHER_MISMATCH When I ...
by dheld Engager in Security 08-30-2025
1 6
1
6
stehsa
Hey,i am trying to connect from EDGE Processor to my Splunk Server and iam getting the following error:/opt/splunk-ed...
by stehsa Engager in Getting Data In 08-29-2025
0 2
0
2
mmendez-opentec
We are currently having an issue where our masking transforms are not working due to the length of _raw being too lar...
by mmendez-opentec Explorer in Getting Data In 08-28-2025
0 9
0
9
wayne333
I've set up my SC4S and connected to my indexer. Logs are ingested as show below but further down, those does not get...
by wayne333 Explorer in Getting Data In 08-28-2025
0 2
0
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Karma Authors