Splunk Administration

Splunk Administration
Category Activity
maheshnc
Hello,I need to upgrade the o365 add-On to the latest version on both the search head and the heavy forwarder, can so...
by maheshnc Path Finder in Getting Data In a month ago
0 5
0
5
drggfish1
I am trying to configure the Splunk Add-on for AWS for brining in CloudTrail logs via SQS S3. I have the following Us...
by drggfish1 Explorer in Getting Data In a month ago
0 3
0
3
Poojitha
Hi All,I have a requirement  where I have to write metrics data to metrics index from existing events index as soon a...
by Poojitha Communicator in Getting Data In a month ago
0 3
0
3
splunkisaurus
Greetings,    I am trying to create a little TA to run a command to collect status for the nessus agent. I have it to...
by splunkisaurus New Member in Getting Data In a month ago
0 12
0
12
andrewtrobec
Hello!I am working with version 4.1.3 (latest) of the Splunk Add-on for Microsoft Cloud Services that is installed on...
by andrewtrobec Motivator in Getting Data In a month ago
0 10
0
10
yuanliu
I am onboarding a JSON dataset whose event size is very close to 1MB.  I have to increase TRUNCATE to 1000000 (from d...
by SplunkTrust SplunkTrust in Getting Data In 12-29-2025
0 2
0
2
Space_Crawler
Hi, I have recently changed the OS hostname, followed by Splunk hostname change on a single node deployment. I am sti...
by Space_Crawler Observer in Monitoring Splunk 12-29-2025
0 3
0
3
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In 12-28-2025
0 1
0
1
dsfyxcasdcertzu
We're updating our Linux Servers to Debian 12. A few host went "missing" afterwards in Splunk.While investigating int...
by dsfyxcasdcertzu Explorer in Getting Data In 12-23-2025
0 4
0
4
ThuLe
Hello everyone,We are using a Universal Forwarder (UF) as an intermediate forwarder to send logs from other UFs in ou...
by ThuLe Explorer in Getting Data In 12-22-2025
0 1
0
1
drggfish1
I am getting a mismatch between the version of OPENSSL installed on my OS and in the Universal Forwarder. It seems to...
by drggfish1 Explorer in Getting Data In 12-21-2025
0 5
0
5
shashankk
I am trying to setup Splunk choropleth world map for the first time.Refer below splunk query:index=app_events_test so...
by shashankk Communicator in Security 12-20-2025
0 3
0
3
NoSpaces
Have a nice day, everyone!For continuous event truncation tracking, I have a simple alert that notifies me about trun...
by NoSpaces Contributor in Getting Data In 12-19-2025
0 2
0
2
CHIBUIKEM
Hello Everyone,  please for the past four weeks I have been struggling with ensuring that the Universal splunk Forwar...
by CHIBUIKEM Engager in Getting Data In 12-18-2025
0 3
0
3
richah
I am hired in an organization as a Splunk architect, and I need to start with onboading data. I don't know much about...
by richah Explorer in Getting Data In 12-18-2025
0 8
0
8
onlyenz404
Hi. I've asked this question in the Splunk Connect for Syslog GitHub repository as it relates to that product, but fo...
by onlyenz404 New Member in Getting Data In 12-17-2025
0 1
0
1
wayne333
Hi,I was recieving fortigate log just fine when i was using the below config in the env file.SC4S_SOURCE_TLS_ENABLE=y...
by wayne333 Explorer in Getting Data In 12-17-2025
0 1
0
1
atari1050
Hello Splunk Gurus- We have noticed that a Splunk job does not end gracefully (version 6.6.3) if the post-pipe comma...
by atari1050 Path Finder in Getting Data In 12-17-2025
0 3
0
3
viewpost_rgora
I am trying to install my Dev License to my local Splunk Instance but am getting the following error. Splunk.License:...
by viewpost_rgora Explorer in Installation 12-13-2025
4 15
4
15
chinmay25
Hello,I am trying to replace the wildcard in my field by several specific workloads. I worked on a query using the mv...
by chinmay25 Path Finder in Security 12-12-2025
0 7
0
7
JyPl4wNYu7GV1uL
I also have this issue: [idx01,idx02] Error in 'IndexScopeSearch': The search failed. More than 1000000 events found ...
by JyPl4wNYu7GV1uL Explorer in Getting Data In 12-12-2025
0 9
0
9
KJ10
Currently we are checking data already exists in Splunk DB by isinstance method, here we need to iterate through enti...
by KJ10 Loves-to-Learn Lots in Getting Data In 12-12-2025
0 4
0
4
SN1
So i have a search which show the indexes that have 0 events last 24hr.  I want to send this result as an alert to mi...
by SN1 Path Finder in Monitoring Splunk 12-12-2025
0 4
0
4
krynol
After upgrading to UF 10.0 we see many Application Error (EventCode=1000) crashes on a subset of servers only. Faulti...
by krynol Engager in Getting Data In 12-10-2025
1 5
1
5
brentrmc
I've been tasked with using btool (in debug mode) to find where the settings for the “onboarding” index was written b...
by brentrmc Explorer in Getting Data In 12-09-2025
0 7
0
7
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Karma Authors