Splunk Administration

Splunk Administration
Category Activity
ra__22
If I have a transforms.conf like the below:[ORIGIN2]REGEX = (?:"id":"32605")FORMAT = sourcetype::test-2DEST_KEY = Met...
by ra__22 Explorer in Getting Data In 03-17-2025
0 5
0
5
BookerRick
When I try to install the UF for AIX, it fails to extract to with a checksum errorAIXSERVER:/nim/media/SOFTWARE/splun...
by BookerRick New Member in Getting Data In 03-17-2025
0 2
0
2
siemsplunk
I tried to run ./splunk remove shcluster-member -mgmt_uri https://<CAPTAIN_IP>:8089 on the non-captain search head, w...
by siemsplunk Explorer in Deployment Architecture 03-15-2025
0 6
0
6
mstodola
I am trying to fix the issue of my zeek logs not being broken into separate events. These logs are in json format and...
by mstodola New Member in Getting Data In 03-15-2025
0 4
0
4
andy_itperson
I've had a working Splunk instance for a month, but post patch it refuses to start the webUI.Where I would either sta...
by andy_itperson New Member in Deployment Architecture 03-14-2025
0 2
0
2
ITSplunk117
Hello,I'm to try changing the sourcetype at the indexer level based on the source.  First question is that possible o...
by ITSplunk117 Path Finder in Getting Data In 03-14-2025
0 6
0
6
chetan_patidar
If you download https://splunkbase.splunk.com/app/7208 Full Tor Node List Lookup App, it comes already with a csv fil...
by chetan_patidar Engager in Getting Data In 03-13-2025
0 0
0
0
alec_stan
We have a discrepancy of 30 to 40 seconds between the event timestamp and _time. I have tries changing the config on ...
by alec_stan Explorer in Deployment Architecture 03-13-2025
0 5
0
5
matt
I want to Splunk to listen on a specific interface not 0.0.0.0. How do I do this?
by matt Splunk Employee Splunk Employee in Security 03-13-2025
8 8
8
8
gpradeepkumarre
This document explains ssl_reload for all ports except 9998 - Data receiving port on indexerhttps://docs.splunk.com/D...
by gpradeepkumarre Engager in Security 03-13-2025
0 1
0
1
MrLR_02
Hello,I have written a Python script that performs an API query from a system. This script is to be executed as scrip...
by MrLR_02 Explorer in Getting Data In 03-13-2025
0 9
0
9
Praz_123
Is there is any Query  to check whether the indexers status  is  down, up or in unknown state . I can check in monito...
by Praz_123 Communicator in Monitoring Splunk 03-13-2025
0 4
0
4
blanky
I'm planning to upgrade upgrade splunk environment now.3 shcluster - 3 index cluster - 2 heavy forwarder - 1 master. ...
by blanky Explorer in Deployment Architecture 03-13-2025
0 5
0
5
JoshuaJJ
Hello, I have a bash script that basically creates a cronjob. Not sure if this is allowed or not but I am able to exe...
by JoshuaJJ Path Finder in Getting Data In 03-12-2025
0 4
0
4
potnuru
Q: Need to forward the data from all the indexes (Windows, Linux, etc...) to CyberArk PTA via Syslog or any other fro...
by potnuru Path Finder in Getting Data In 03-12-2025
0 11
0
11
lar06
HelloUsing Splunk 9.3.2What does this error mean ?ERROR TcpOutputFd [ TcpOutEloop] - Expecting to be in eWaitCapabili...
by lar06 Explorer in Deployment Architecture 03-12-2025
0 3
0
3
ParsaIsHash
Description:I am using a Splunk Heavy Forwarder (HF) to forward logs to an indexer cluster. I need to configure props...
by ParsaIsHash Loves-to-Learn Lots in Getting Data In 03-12-2025
0 13
0
13
abhisplunk1
0
3
clightburn1
As the computer laptop field continues to grow the use of ARM based chips for Windows 11, is there an ETA on a Splunk...
by clightburn1 Engager in Getting Data In 03-11-2025
0 1
0
1
rksharma2808
Teamam looking for some suggestions or insights Patch Automation  through Ansible , Terraform   
by rksharma2808 Loves-to-Learn in Deployment Architecture 03-11-2025
0 1
0
1
cfrank
Hi all,My customer would like to use Smartstore with on prem S3 storage(Storagegrid) and then tier the older data(aft...
by cfrank Engager in Deployment Architecture 03-11-2025
0 2
0
2
cherrypick
Hi,I have a python modular input that populates an index (index_name). This ran into some gateway error issues causin...
by cherrypick Path Finder in Getting Data In 03-11-2025
0 1
0
1
Rastegui
I am trying to identify the user or process responsible for stopping the Splunk UF agent. What log source do I requir...
by Rastegui Engager in Monitoring Splunk 03-10-2025
0 2
0
2
thanh_on
Dear fellas,I have an issue on Monitoring Console that show wrong information of instance after upgrade from 9.2.2 up...
by thanh_on Path Finder in Knowledge Management 03-10-2025
0 6
0
6
sureshkumaar
I have configured an app and added 7 different source files in a single inputs.conf with the same index name and sour...
by sureshkumaar Path Finder in Getting Data In 03-08-2025
0 6
0
6
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...
Top Karma Authors