Splunk Administration

Splunk Administration
Category Activity
msatish
Newly installed Universal forwarders on windows servers are forwarding logs to Splunk Cloud but newly installed forwa...
by msatish Path Finder in Getting Data In 05-16-2025
0 4
0
4
rubeniturrieta
Hi all, I have a Splunk server, that suddenly stops working, and i don't know why. I've added the 'Splunk enable bo...
by rubeniturrieta Communicator in Deployment Architecture 05-16-2025
0 15
0
15
LogUx
Hi Splunkers!!,We have recently configured SSO in Splunk using Keycloak, and it's working fine — users are able to lo...
by LogUx Motivator in Getting Data In 05-16-2025
0 2
0
2
ahennewig_sva
Hi,we are currently experiencing reliability issues when using the Microsoft Teams Add-on for Splunk  (https://splunk...
by ahennewig_sva Observer in Getting Data In 05-16-2025
0 2
0
2
KeithH
Hi All,Help please.Can I get people to agree with me that the following is a bug/design flaw - as my splunk case is g...
by KeithH Communicator in Getting Data In 05-16-2025
0 6
0
6
abhi
Hello Team,I am configuring Splunk, but the UF (Universal Forwarder) details are not reflecting in the Deployment Ser...
by abhi Observer in Deployment Architecture 05-16-2025
0 4
0
4
tah7004
Hello, has anyone worked with ingest-time lookup and familiar with it?https://docs.splunk.com/Documentation/Splunk/8....
by tah7004 Path Finder in Getting Data In 05-16-2025
0 8
0
8
daniel333
All, I found myself writing this props.conf today. Say I have this: [tomcat:src:server] EXTRACT-springapp_name =...
by daniel333 Builder in Getting Data In 05-16-2025
0 5
0
5
DanielaHerold
Hi everyone, I am currently trying to run the Universal Forwarder for Linux ARM on a Raspberry Pi 2 Model B with an ...
by DanielaHerold New Member in Deployment Architecture 05-16-2025
0 12
0
12
Ciccius
Hi all,I am trying to deploy my apps from the deployment server with the command: /opt/splunk/bin/splunk apply shclus...
by Ciccius Explorer in Deployment Architecture 05-16-2025
0 3
0
3
vikas_gopal
Hello Experts , I am trying to send windows security logs to logstash(http) receiver . Below is what I have based on ...
by vikas_gopal Builder in Getting Data In 05-15-2025
0 14
0
14
666Meow
Hi all,I’ve recently encountered several challenges since migrating to Splunk Mission Control (MS) and would apprecia...
by 666Meow Explorer in Monitoring Splunk 05-15-2025
0 0
0
0
sreddem
Hi Team,Greetings !!This is Srinivasa, Could you please provide Splunk with Unified Applications (CUCM) On-prem , how...
by sreddem Observer in Getting Data In 05-15-2025
0 1
0
1
antnovo
Hello, have a question regarding log ingestion from Azure. At the moment, im using REST API to onboard logs to the on...
by antnovo New Member in Getting Data In 05-15-2025
0 6
0
6
tkw03
HelloIm working on a new script to install Splunk via bash. before accepting the license and starting Splunk, with no...
by tkw03 Communicator in Installation 05-14-2025
0 17
0
17
tech_g706
Hi All,Anyone who has worked with OpenText NetIQ Logs before?We are receiving the NetIQ logs via syslog, but the sour...
by tech_g706 Path Finder in Getting Data In 05-14-2025
0 4
0
4
Mobyd
Hi,     I am trying to gather data from a specific organisation unit in Active Directory and ignore everything else? ...
by Mobyd New Member in Getting Data In 05-14-2025
0 2
0
2
buzzard192
I have a field with the system's IP in it and am trying to add additional fields during ingest.  It works if the IP f...
by buzzard192 Explorer in Getting Data In 05-14-2025
0 4
0
4
GaetanVP
Hello Splunkers,I have a small question, what is the best practice (or for what reasons) should I use Syslog or TCP c...
by GaetanVP Contributor in Getting Data In 05-13-2025
0 8
0
8
sgutierrez
Hello, I am new to the Splunk interface and I have been recently given a task to configure Splunk to monitor the foll...
by sgutierrez Engager in Getting Data In 05-13-2025
1 4
1
4
Dilsheer_P
I ma trying to onboard the %SystemRoot%\System32\Winevt\Logs\Microsoft-AzureADPasswordProtection-DCAgent%4Admin.evtx ...
by Dilsheer_P Loves-to-Learn Lots in Getting Data In 05-13-2025
0 2
0
2
Niro
I have the following transforms.conf file:[pan_src_user]INGEST_EVAL=src_user_idx=json_extract(lookup("user_ip_mapping...
by Niro Explorer in Getting Data In 05-13-2025
0 10
0
10
patelmc
I need to use federated search which does not support search time lookup at this time in splunk 8.2.2.1.I came across...
by patelmc Explorer in Getting Data In 05-13-2025
0 2
0
2
Skins
I have syslog events being written to a HF locally via syslog-ng - these events are then consumed via file reader and...
by Skins Path Finder in Getting Data In 05-13-2025
0 3
0
3
dtamburin
Brand new to splunk, inherited a slightly configured system.I want to move certain cribl events to an index called vm...
by dtamburin Engager in Getting Data In 05-13-2025
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors