Splunk Administration

Splunk Administration
Category Activity
XOR
Guys i have Splunk Cloud , i created Http Event Collector & in prisma i gave url /service/collector but logs are not ...
by XOR Loves-to-Learn in Getting Data In 07-09-2025
0 3
0
3
fatsug
When collecting Linux logs using a Universal Forwarder we are collecting a lot of unnecessary audit log from cronjobs...
by fatsug Builder in Getting Data In 07-09-2025
0 5
0
5
rk60422
Has anyone figured out how to successfully join the three new _DS indexes into a meaningful report?I would like to cr...
by rk60422 Explorer in Monitoring Splunk 07-08-2025
0 3
0
3
ASGrover
Hi everyone,I’m currently working with a Splunk distributed clustered environment (v9.4.1), with 3 indexers, 3 search...
by ASGrover Loves-to-Learn Lots in Deployment Architecture 07-08-2025
0 3
0
3
Sidpet
HiI have created a playbook to capture inputs from the user like short description, description and priority and crea...
by Sidpet Loves-to-Learn in Deployment Architecture 07-07-2025
0 0
0
0
corti77
Hi,I am running splunk standalone 8.4.1 with Citrix add-on installed 8.2.3.  Also, I have SC4S running version 3.31.0...
by corti77 Contributor in Getting Data In 07-07-2025
0 4
0
4
fatsug
We recently switched over from an ingest based license to a resource based (vCPU) license model in our deployment.The...
by fatsug Builder in Monitoring Splunk 07-04-2025
0 2
0
2
wsmworkhard
I'm getting duplicated data when using lambda function to send events from cloudwatch to splunk through HTTP Event Co...
by wsmworkhard Explorer in Getting Data In 07-03-2025
0 3
0
3
SN1
I want to send alerts to ms teams channel how to do it
by SN1 Path Finder in Other Admin 07-03-2025
0 2
0
2
TestAdminHorst
We are getting the following error when trying to ingest EXO mail logs into splunk using the add-in.line 151, in __ca...
by TestAdminHorst New Member in Getting Data In 07-03-2025
0 2
0
2
SN1
I am not able to see the schedule of the saved searches although they are cron scheduled . so when i am saving again ...
by SN1 Path Finder in Other Admin 07-02-2025
0 5
0
5
DineshElumalai
Hello EveryoneI need to export the search results to a folder outside the Splunk. To do this job we've exportresults ...
by DineshElumalai Explorer in Getting Data In 07-02-2025
0 3
0
3
kaushik3g
I am getting the below error. Unable to initialize modular input "TA-Akamai_SIEM" defined inside the app "Splunk_TA_...
by kaushik3g Engager in Getting Data In 07-01-2025
0 4
0
4
Ravi1
We are experiencing consistent log duplication and data loss when the Splunk Universal Forwarder (UF) running as a He...
by Ravi1 Loves-to-Learn in Getting Data In 06-30-2025
0 1
0
1
_joe
The current Netscaler guidance is that logs should be exported via HEC. However, it seems like the app doesn't have a...
by _joe Contributor in Getting Data In 06-30-2025
0 1
0
1
Kosyay
Hello! I have logs from Domain Controller Active Directory in Splunk and try to configure monitoring of user logons ...
by Kosyay Explorer in Getting Data In 06-30-2025
0 12
0
12
hv64
Hello,im facing a problem on my Dbx connect : Cannot communicate with task server, please check your settings. DBX Se...
by hv64 Explorer in Getting Data In 06-30-2025
0 4
0
4
tanjiro_rengo
Hi guys,I am new here and I want to explore some things in splunk. I have a txt file, I uploaded it and I want to get...
by tanjiro_rengo New Member in Getting Data In 06-30-2025
0 4
0
4
kn450
Hello everyone,I have a network monitoring system that exports data via IPFIX using Forwarding Targets.I am trying to...
by kn450 Explorer in Getting Data In 06-29-2025
0 1
0
1
RAVISHANKAR
Hello,Planning to Upgrade Splunk Enterprise from version 9.2.1 to latest version 9.4.2 - So can a 9.4.2 latest versio...
by RAVISHANKAR Explorer in Installation 06-27-2025
0 3
0
3
meg
My linux logs cannot parsed in dashboard. My renderxml is setted to false 
by meg Observer in Getting Data In 06-27-2025
0 3
0
3
mbissante
Hi,I need to upgrade Splunk v.8.2.2.1 on RHEL 7.6 to Splunk v.9.4 on RHEL 9.6.I saw that Splunk 8.2 does not support ...
by mbissante Engager in Deployment Architecture 06-27-2025
0 2
0
2
Pete_
Hello,I am having issues getting data into Splunk Cloud with two new Universal forwarders.I have two existing Univers...
by Pete_ Explorer in Getting Data In 06-26-2025
0 7
0
7
untieshoe
I don't mean SharePoint activity, admin or audit logs. I mean actual data files (that will be converted later to look...
by untieshoe Path Finder in Getting Data In 06-26-2025
0 3
0
3
splunklearner
Jun 26 13:46:12 128.23.84.166 [local0.err] <131>Jun 26 13:46:12 GBSDFA1AD011HMA.systems.uk.fed ASM:f5_asm=PROD vs_na...
by splunklearner Communicator in Getting Data In 06-26-2025
0 6
0
6
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors