Splunk Administration

Splunk Administration
Category Activity
vishalduttauk
I am in the middle of a Splunk migration. One of the tasks is to moved data from some sourcetypes onto the new server...
by vishalduttauk Communicator in Getting Data In 06-19-2025
0 3
0
3
sandeep_A1997
Suddenly we observed /opt/data was unmounted, and ownership has changed from splunk to root. Mounted back and restart...
by sandeep_A1997 Loves-to-Learn in Deployment Architecture 06-19-2025
0 3
0
3
danielbb
I see multiple versions of the inputs.conf Visio stencil however I'm looking for props.conf and transforms.conf ones....
by danielbb Motivator in Deployment Architecture 06-19-2025
0 1
0
1
KishoreSrini
I am newbie to this env and I'm trying to understand some logs regrading a linux server troubleshoot. A server stoppe...
by KishoreSrini Explorer in Monitoring Splunk 06-19-2025
0 4
0
4
Mirza_Jaffar1
why this issues I was trying to upgrade the splunk enterprise Checking prerequisites...        Checking http port [80...
by Mirza_Jaffar1 Explorer in Getting Data In 06-19-2025
0 6
0
6
ilhwan
I'm struggling to get data in from Infoblox using Splunk Add-on for Infoblox.  I looked at the documentation and real...
by ilhwan Path Finder in Getting Data In 06-19-2025
0 1
0
1
_joe
Hello all Is the Nutanix TA (version 2.5.0) compatible with Splunk 9.3.4+? It is listed as such on the splunk base (h...
by _joe Contributor in Getting Data In 06-19-2025
0 1
0
1
msatish
I think Splunk doesn't have a built-in/defined sourcetype for ExtremeCloud XIQ logs. Can we define a custom sourcetyp...
by msatish Path Finder in Getting Data In 06-18-2025
0 7
0
7
Bedrohungsjäger
Hey FolkesIngesting ZPA logs in Splunk using the Zscaler LSS service, I believe the configuration is correct based on...
by Bedrohungsjäger Observer in Getting Data In 06-18-2025
0 2
0
2
sverdhan
Hello team , Please help me modify this query such that it is able to loop through all the values of the csv file :  ...
by sverdhan Loves-to-Learn Lots in Getting Data In 06-18-2025
0 6
0
6
splunkreal
Hello, I put this regex on SHC inline extraction : "<(?<pri>\d+)>1\s(?<timestamp>\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}(...
by splunkreal Influencer in Getting Data In 06-18-2025
0 2
0
2
sgarcia
Hello community. We have a cluster architecture with 5 indexes. We have detected high license consumption, we are try...
by sgarcia Explorer in Security 06-18-2025
0 2
0
2
kumva01
Hi Team,We are trying to extract JSON data with custom sourcetype and With the current configuration, all JSON object...
by kumva01 Loves-to-Learn Lots in Getting Data In 06-18-2025
0 1
0
1
splunkreal
Hello,we have 2 Splunk platforms and we are using _TCP_ROUTING to forward logs.System logs from 1st platform indexers...
by splunkreal Influencer in Getting Data In 06-17-2025
0 1
0
1
parthbhawsar
Hello,I have been trying to configure this application on one of our on-prem Heavy forwarder to be able to ingest our...
by parthbhawsar Loves-to-Learn in Getting Data In 06-17-2025
0 5
0
5
Jflow
0
1
gargantua
Hi,I'm onboarding some new data and I'm working on the fields extraction.Data is some proper JSON related to emails.I...
by gargantua Path Finder in Getting Data In 06-17-2025
0 2
0
2
Bedrohungsjäger
Hey everyone, I'm doing testing regarding ingesting Zscaler ZPA Logs into Splunk using LSS, I'd like any assistance a...
by Bedrohungsjäger Observer in Getting Data In 06-16-2025
0 1
0
1
sawwinnaung
I am trying to setup props & transforms in indexers to send PROCTITLE events to null queuei tried below regex but tha...
by sawwinnaung Explorer in Getting Data In 06-16-2025
0 8
0
8
Trevorator
Hello there, In our environment we have datamodel accelerations that are consistently reaching the Max Summarization ...
by Trevorator Explorer in Knowledge Management 06-15-2025
0 7
0
7
Splunkers2
Hey everyone I am using the misp42slunk app but can't get the events and I don't see any errors what am I doing wrong...
by Splunkers2 Observer in Getting Data In 06-15-2025
0 3
0
3
harryvdtol
Hello,I have search for some old posting, but i did not find the proper answers.In Splunk i have a column date field ...
by harryvdtol Path Finder in Getting Data In 06-15-2025
0 4
0
4
splunklearner
We are currently pulling Akamai logs to Splunk using akamai add-on in Splunk. As of now I am giving single configurat...
by splunklearner Communicator in Getting Data In 06-14-2025
0 1
0
1
b17gunnr
Hello folks,I'm fighting some events in the future and am having some trouble breaking the code for parsing an event....
by b17gunnr Path Finder in Getting Data In 06-13-2025
0 2
0
2
SplunkExplorer
Hi Splunkers, a colleague team si facing some issues related to .csv file collection. Let me share  the required cont...
by SplunkExplorer Contributor in Getting Data In 06-13-2025
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors