Splunk Administration

Splunk Administration
Category Activity
kn450
Hello,I’m experiencing an issue with my Kafka broker integration with Splunk.The error message I’m seeing is:Kafka Br...
by kn450 Explorer in Getting Data In 08-28-2025
0 2
0
2
AliMaher
Hi I hope you are doing well. I have reinstalled the UF after that i found there are duplicate clients on the Deploym...
by AliMaher Path Finder in Deployment Architecture 08-28-2025
0 4
0
4
spisiakmi
Hi, can anybody help, please?Here the status quo:In the Dashboard there is time picker object.selected time range: 20...
by spisiakmi Contributor in Getting Data In 08-28-2025
0 7
0
7
LymanHurd
I am the technical lead for a product that we hope to integrate to Splunk instances using webhooks.  As an intermedia...
by LymanHurd New Member in Getting Data In 08-27-2025
0 1
0
1
azer271
After the Splunk Master enters maintenance mode, one of the indexers goes offline and then back online, and disables ...
by azer271 Path Finder in Getting Data In 08-27-2025
0 2
0
2
coddydaddy88
EnvironmentSending from: Azure Web Apps (Kudu CLI)Target: Two Splunk instancesPersonal trial Splunk (working)Customer...
by coddydaddy88 Explorer in Getting Data In 08-26-2025
0 7
0
7
StephenD1
I have UFs in the DMZ and internal networks with a load balancer managing traffic between both zones. There is a sing...
by StephenD1 Path Finder in Deployment Architecture 08-25-2025
0 8
0
8
jni
Hi, I have issues with Splunk Enterprise 9.4.2 not expanding $_index_name from etc/system/local/indexes.conf.My defau...
by jni Explorer in Getting Data In 08-25-2025
0 2
0
2
b17gunnr
Hello friends,Splunk is cranky with errors stating: Failed to parse timestamp in first MAX_TIMESTAMP_LOOKAHEAD (40) c...
by b17gunnr Path Finder in Getting Data In 08-25-2025
0 2
0
2
Vivek
Hello,I had set up a Distributed Search setup in VirtualBox with a Search Head, indexer and Deployment Server. Initia...
by Vivek Engager in Installation 08-25-2025
0 3
0
3
isahu
Unable to get the recent logs for today for an production environment. It is throwing an error stating "ERROR [Proper...
by isahu Observer in Monitoring Splunk 08-25-2025
0 3
0
3
kevinhsu
Hello folks,We are doing splunkforwarder upgrade to 9.4.x (from 8.x) recently, we build the splunk sidecar image for ...
by kevinhsu New Member in Deployment Architecture 08-25-2025
0 1
0
1
Karthikeya
I Need to exclude or discard specific field values which contains sensitive info from indexed events. Users should no...
by Karthikeya Communicator in Getting Data In 08-25-2025
0 17
0
17
haraksin
This just makes things confusing - why do the RPM and DEB versions (both x86 and ARM) and Windows of v9.3.3 have buil...
by haraksin Communicator in Getting Data In 08-23-2025
0 3
0
3
M1k3Smith
We have 2 indexers in a cluster and are running 9.4.0I removed an index from the cluster by removing its stanza from ...
by M1k3Smith Explorer in Monitoring Splunk 08-22-2025
0 5
0
5
tech_g706
Hi,I’m currently receiving Windows logs in Splunk via the (UF → HF → Splunk Cloud). The logs are being assigned to tw...
by tech_g706 Path Finder in Getting Data In 08-22-2025
0 1
0
1
klowke_svbz
Hi all,we collect some json data from a logfile with a universal forwarder.Most times the events were indexed correct...
by klowke_svbz Loves-to-Learn in Getting Data In 08-22-2025
0 4
0
4
LIS
I have two time stamps in each record 2025-08-20 17:37:00.317 and SEN_20250820153640.1703351.txt.And want to use firs...
by LIS Path Finder in Getting Data In 08-22-2025
0 9
0
9
phamanh1652
We are using SC4S to collect local logs from FortiAnalyzer. We've noticed a error: the timestamp within the log file ...
by phamanh1652 Path Finder in Getting Data In 08-21-2025
0 14
0
14
splunk_admin
I have noticed that my vmware logs which are forwarded to my HF via TCP are very large.  We would like to filter out ...
by splunk_admin Observer in Getting Data In 08-21-2025
0 2
0
2
hrawat
index=_internal source=*splunkd.log* host=<all indexer hosts> bucketreplicator full earliest=-15m | stats count dc(h...
by hrawat Splunk Employee Splunk Employee in Knowledge Management 08-21-2025
7 1
7
1
Priya70
.
by Priya70 Explorer in Getting Data In 08-21-2025
0 5
0
5
chuvii
Hello Splunkers!After deploying the Splunk Otel Collector I wanted to check all of the traces and metrics send from o...
by chuvii New Member in Getting Data In 08-20-2025
0 0
0
0
Nawab
we have a running splunk deployment, where UFs are reading inputs from system/local and now we want to switch from sy...
by Nawab Communicator in Other Admin 08-19-2025
0 4
0
4
bellb
We are looking for Power Platform audit logs to ensure that these logs will automatically show up in SPLUNK if they a...
by bellb New Member in Getting Data In 08-19-2025
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...
Top Karma Authors