Splunk Administration

Splunk Administration
Category Activity
loganallen
I am trying to implement a postfilter in Splunk Connect for Syslog to drop east-west (internal-to-internal) Fortigate...
by loganallen Loves-to-Learn in Getting Data In 05-20-2026
0 0
0
0
Araton71
I've configured my splunk enterprise to get saml login with keycloak.[authentication]authSettings = samlauthType = SA...
by Araton71 Explorer in Security 05-20-2026
0 1
0
1
himanshu2
I have a 2 search heads in a Splunk SH cluster in the dev environment. Recently, I upgraded Splunk from 9.3.8 to 9.4....
by himanshu2 Loves-to-Learn in Deployment Architecture 05-19-2026
0 2
0
2
Karthikeya
We have to pull logs from Tencent COS (Cloud Object Storage) to our Splunk instances which are hosted on AWS. Tencent...
by Karthikeya Communicator in Getting Data In 05-19-2026
0 7
0
7
volly
iv just created a new account.iv have admin role assigned to my user account iv given admin role all permissions, yet...
by volly New Member in Getting Data In 05-18-2026
0 2
0
2
spl_aficionado
We recently found out that we couldn't send TCP data as Syslog because it didn't have the proper header, but streamin...
by spl_aficionado Path Finder in Getting Data In 05-16-2026
0 4
0
4
wellsjp
We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security ...
by wellsjp Loves-to-Learn Lots in Getting Data In 05-15-2026
0 5
0
5
javier_oshiro
We are currently configuring the DUO security MFA on Splunk Enterprise and we noticed that the local account admin ge...
by javier_oshiro Explorer in Security 05-13-2026
0 1
0
1
ASierra
There have been reports that the February 2026 MS update kills the RPC call to the Domain Controllers for various ver...
by ASierra Explorer in Monitoring Splunk 05-13-2026
0 1
0
1
arthy-velusamy
We are trying to ingest JSON data to Splunk Ingest Processor. Sometimes JSON data is getting ingested properly and ma...
by arthy-velusamy Observer in Getting Data In 05-13-2026
0 1
0
1
jni
Hi,I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".To me, the journald-filte...
by jni Explorer in Getting Data In 05-12-2026
0 7
0
7
0xAli
Hi Everyone,While using Syslog-NG to monitor network traffic and write it into file,  I want to ask about the Log fil...
by 0xAli Path Finder in Getting Data In 05-11-2026
0 6
0
6
romquestaai_gma
As organizations increasingly adopt AI tools for automation, analytics, and decision-making, protecting sensitive dat...
by romquestaai_gma New Member in Deployment Architecture 05-11-2026
0 2
0
2
gitau_gm
I am observing inconsistent forwarding of Windows Security Event ID 4624 (Successful Logon) from multiple Windows hos...
by gitau_gm Explorer in Getting Data In 05-08-2026
0 9
0
9
Khairul_Irsyad
Referring to this  question (Not all Splunk cookies have the HttpOnly tag set) , answered by @anaidu_splunk , I can s...
by Khairul_Irsyad Loves-to-Learn in Security 05-07-2026
0 1
0
1
thehow
Current setup - Indexers --> F5 VIP --> CM CM is seeing the requests are coming F5 VIP rather than actual source ip o...
by thehow Loves-to-Learn in Deployment Architecture 05-05-2026
0 2
0
2
mgaraventa_splu
In my use-case my source log (tailed by a monitor input stanza) is being archived once a day at midnight and the resu...
by mgaraventa_splu Splunk Employee Splunk Employee in Monitoring Splunk 05-05-2026
3 3
3
3
kvm
Hi,I'm required to integrate the Alogsec  Security Management Suite (ASMS) logs via API method to cover the richer vi...
by kvm Explorer in Getting Data In 05-05-2026
0 3
0
3
zapping575
One of my sourcetypes is a CSV file (with CSV header)I was using this sourcetype stanza in props.conf:[foo_bar] INDEX...
by zapping575 Communicator in Getting Data In 04-29-2026
0 1
0
1
LovingSplunk
We are planning to decommission our Cribl environment and migrate all data ingestion directly back to Splunk. I am lo...
by LovingSplunk Path Finder in Deployment Architecture 04-28-2026
0 3
0
3
BluFalcon
I was wondering if any one has successfully onboard KnowBe4 data? I don't see a TA or App on Splunkbase.
by BluFalcon Engager in Getting Data In 04-27-2026
0 8
0
8
Wohamed_wakkad
According to Splunk Validated architecture of designing HA between 2 syslog server  the documentation says this -->  ...
by Wohamed_wakkad Explorer in Deployment Architecture 04-27-2026
0 5
0
5
gnagasri
Sample events - working in regex101 : https://regex101.com/r/LuC6ZQ/1| rex field=_raw "nsssvcip\=(?<host>\d+\.\d+\.\d...
by gnagasri Engager in Getting Data In 04-26-2026
0 4
0
4
NullZero
IHAC that has a distributed DS/LM/MC in a DMZ environment (see image). It's a new RHEL build on 10.2.2 and clients ha...
by NullZero Communicator in Deployment Architecture 04-24-2026
0 2
0
2
becksyboy1
Hi All,Has anyone tried to ingest Claude OpenTelemetry logs into Splunk? I'd be interested in understanding what appr...
by becksyboy1 Engager in Getting Data In 04-24-2026
0 4
0
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...
Top Karma Authors