Splunk Administration

Splunk Administration
Category Activity
Praz_123
Is there is any Query  to check whether the indexers status  is  down, up or in unknown state . I can check in monito...
by Praz_123 Communicator in Monitoring Splunk 03-13-2025
0 4
0
4
blanky
I'm planning to upgrade upgrade splunk environment now.3 shcluster - 3 index cluster - 2 heavy forwarder - 1 master. ...
by blanky Explorer in Deployment Architecture 03-13-2025
0 5
0
5
JoshuaJJ
Hello, I have a bash script that basically creates a cronjob. Not sure if this is allowed or not but I am able to exe...
by JoshuaJJ Path Finder in Getting Data In 03-12-2025
0 4
0
4
potnuru
Q: Need to forward the data from all the indexes (Windows, Linux, etc...) to CyberArk PTA via Syslog or any other fro...
by potnuru Path Finder in Getting Data In 03-12-2025
0 11
0
11
lar06
HelloUsing Splunk 9.3.2What does this error mean ?ERROR TcpOutputFd [ TcpOutEloop] - Expecting to be in eWaitCapabili...
by lar06 Explorer in Deployment Architecture 03-12-2025
0 3
0
3
ParsaIsHash
Description:I am using a Splunk Heavy Forwarder (HF) to forward logs to an indexer cluster. I need to configure props...
by ParsaIsHash Loves-to-Learn Lots in Getting Data In 03-12-2025
0 13
0
13
abhisplunk1
0
3
clightburn1
As the computer laptop field continues to grow the use of ARM based chips for Windows 11, is there an ETA on a Splunk...
by clightburn1 Engager in Getting Data In 03-11-2025
0 1
0
1
rksharma2808
Teamam looking for some suggestions or insights Patch Automation  through Ansible , Terraform   
by rksharma2808 Loves-to-Learn in Deployment Architecture 03-11-2025
0 1
0
1
cfrank
Hi all,My customer would like to use Smartstore with on prem S3 storage(Storagegrid) and then tier the older data(aft...
by cfrank Engager in Deployment Architecture 03-11-2025
0 2
0
2
cherrypick
Hi,I have a python modular input that populates an index (index_name). This ran into some gateway error issues causin...
by cherrypick Path Finder in Getting Data In 03-11-2025
0 1
0
1
Rastegui
I am trying to identify the user or process responsible for stopping the Splunk UF agent. What log source do I requir...
by Rastegui Engager in Monitoring Splunk 03-10-2025
0 2
0
2
thanh_on
Dear fellas,I have an issue on Monitoring Console that show wrong information of instance after upgrade from 9.2.2 up...
by thanh_on Path Finder in Knowledge Management 03-10-2025
0 6
0
6
sureshkumaar
I have configured an app and added 7 different source files in a single inputs.conf with the same index name and sour...
by sureshkumaar Path Finder in Getting Data In 03-08-2025
0 6
0
6
Karthikeya
Hi, We have configured a data input in HF and there is an option to select index there. I have created new index in C...
by Karthikeya Communicator in Getting Data In 03-08-2025
0 35
0
35
securepoint
I'm trying to extract endpoint data from Cortex XDR, but I don't want to see just alerts in Splunk—I need all the end...
by securepoint Engager in Getting Data In 03-08-2025
0 3
0
3
rrossetti
I am having difficulty converting event logs to metric data pointshttps://docs.splunk.com/Documentation/Splunk/9.4.0/...
by rrossetti Splunk Employee Splunk Employee in Getting Data In 03-07-2025
0 1
0
1
jbeach
Splunk Cloud had an update this past Sunday, 3 Mar 2025. Since then, admins are unable to change a user's role. Is th...
by jbeach Explorer in Security 03-07-2025
0 5
0
5
lar06
HelloUsing Splunk 9.3.2I want to deploy an app to all Windows UF only. This config doesn't work. [serverClass:scalluf...
by lar06 Explorer in Deployment Architecture 03-07-2025
0 2
0
2
NoSpaces
I'm new in Splunk and have a test environment contains search head cluster with three Splunk 9.0.1 instances: one dep...
by NoSpaces Contributor in Deployment Architecture 03-07-2025
0 2
0
2
Nawab
I have 3 new splunk enterprise. 2 are acting as search heads and 1 is acting as deployer.I have successfully made the...
by Nawab Communicator in Deployment Architecture 03-07-2025
0 2
0
2
RSS_STT
I want to send the all the event to nullqueue except having match "EventType": 5000. {"EventID": 2154635, "EventType"...
by RSS_STT Explorer in Getting Data In 03-07-2025
0 5
0
5
ts00011
input: {author=John, book=Splunk } output table author book John Splunk
by ts00011 New Member in Knowledge Management 03-07-2025
0 4
0
4
rjastrze
The current version is not available for the cloud.According to conversations with Splunk Support, the update address...
by rjastrze Explorer in Getting Data In 03-06-2025
0 3
0
3
azer271
Hello there. I would like to ask about Splunk best practices, specifically regarding cluster architecture. One sugges...
by azer271 Path Finder in Deployment Architecture 03-06-2025
0 2
0
2
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...
Top Karma Authors