Splunk Administration

Splunk Administration
Category Activity
shoaibalimir
Hi Community,I'm exploring ways to ingest data into Splunk Cloud from a Amazon s3 Bucket which has multiple directori...
by shoaibalimir Path Finder in Getting Data In 07-28-2025
0 2
0
2
stefanlasiewski
I'm installing Splunk on an Enterprise Linux 6.1 machine. The Install on Linux instructions talk about a RPM, but d...
by stefanlasiewski Contributor in Security 07-28-2025
36 65
36
65
n_hoh
Hi All I've been tasked with setting up logging for Windows Certification Services and getting this into Splunk.Have ...
by n_hoh Observer in Getting Data In 07-28-2025
0 6
0
6
verbal_666
Hi.During the day, some on my Indexers completely stops sending back the ACK, so many agents keep data in queue until...
by verbal_666 Builder in Getting Data In 07-26-2025
0 6
0
6
isahu
I onboarded one production logs to splunk but after restarting the UF I am not able to see the recent logs also I am ...
by isahu Observer in Getting Data In 07-26-2025
0 3
0
3
samalchow
I’ve inherited a fleet of about 150 Windows Servers, all configured identically — same Deployment Server, TAs, inputs...
by samalchow Observer in Getting Data In 07-25-2025
0 6
0
6
jbanAtSplunk
Hi,Does anyone have a good example from Logstash to Splunk HEC?I only get "services/collector/raw" working with logst...
by jbanAtSplunk Communicator in Getting Data In 07-24-2025
0 18
0
18
elend
I wanna ask something on my lab clustered indexer. I got max primary capacity on my indexer. Last time i just reduce ...
by elend Communicator in Deployment Architecture 07-24-2025
0 8
0
8
Scottk1
Client is asking about Splunk Cloud backup and recovery procedure for DR. Specifically all the configuration, searche...
by Scottk1 Loves-to-Learn Lots in Monitoring Splunk 07-24-2025
0 2
0
2
zaks191
Hi Splunk Community,I'm new to Splunk and working on a deployment where we index large volumes of data (approximately...
by zaks191 New Member in Getting Data In 07-24-2025
0 5
0
5
sabari80
I have a scheduled export report for daily 11PM from my monitoring dashboard. we are in EST time zone and my dashboar...
by sabari80 Explorer in Knowledge Management 07-23-2025
0 2
0
2
zksvc
Hi Everyone, in default correlation search the name "Excessive Failed Logins" my drilldown cannot define $info_min_ti...
by zksvc Contributor in Deployment Architecture 07-22-2025
3 10
3
10
nopera
Hi,Could you help me retrieve message-tracking logs from our on-premises Exchange server? I added the following lines...
by nopera Explorer in Getting Data In 07-22-2025
0 11
0
11
dsgoody
Hi all,I'm having some issues excluding events from our Juniper SRX logs. These events are ingested directly on our W...
by dsgoody Engager in Getting Data In 07-22-2025
0 2
0
2
verbal_666
Hello.I'm actually using aparallelIngestionPipelines = 2feature on my Indexers. Works.Servers (Linux) are professiona...
by verbal_666 Builder in Getting Data In 07-22-2025
0 5
0
5
tsocyberoperati
Hello All,We have a Splunk Universal Forwarder 9.4.0 (then 9.4.3) installed on a Windows 2022 box to which we don't h...
by tsocyberoperati Loves-to-Learn Lots in Deployment Architecture 07-21-2025
0 5
0
5
LS1
   Hello, maybe I don't have the vocabulary to find the answer when Googling.  I only submit this question after many...
by LS1 Loves-to-Learn Lots in Getting Data In 07-21-2025
0 12
0
12
AAlhabba
Dears,       After upgraded Splunk from 9.1.2 version to 9.2.0 version, the deployment server not showing the clients...
by AAlhabba Explorer in Deployment Architecture 07-21-2025
1 29
1
29
palyogit
http event data is not received at index though in the log it says HttpInputDataHandler - handled token name=xyz How ...
by palyogit New Member in Getting Data In 07-20-2025
0 5
0
5
azer271
Hello! I'm new to Splunk Cloud. Could you please explain the difference between hot, warm, cold and thawed buckets in...
by azer271 Path Finder in Deployment Architecture 07-20-2025
0 4
0
4
thambisetty
Hi everyone, I am working on Splunk clustered environment, where i have 3 indexers,1 search head, and 1 head. Now i a...
by SplunkTrust SplunkTrust in Deployment Architecture 07-18-2025
3 13
3
13
nomaduw
I've been asked to assist another department with getting their Splunk configuration working with windows UFs. They h...
by nomaduw Loves-to-Learn in Security 07-18-2025
0 1
0
1
vulnfree
Hi Splunkers,I'm having issues ingesting Windows DNS Server Analytical logs. What's strange is that I am able to pull...
by vulnfree Explorer in Getting Data In 07-18-2025
0 1
0
1
BoscoBaracus
Good morning All,I have been trying to figure out how can I create a data input on a heavy forwarder to forward data ...
by BoscoBaracus Engager in Getting Data In 07-18-2025
0 12
0
12
ez-secops-awn
I would greatly appreciate support for customer model as a correlation search option in the VT4splunk app.
by ez-secops-awn Engager in Getting Data In 07-17-2025
0 5
0
5
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors