Splunk Administration

Splunk Administration
Category Activity
709_miner
I have 2 heavy forwarder on-prem and one of the HF says license is expired.  I don't have a LM. I have a hybrid syste...
by 709_miner Loves-to-Learn Everything in Getting Data In 06-25-2026
0 3
0
3
Rafaelled
Good Afternoon,I have been at war with the estreamer app for 2 weeks and I can not get this to work. Below is the cur...
by Rafaelled Explorer in Getting Data In 06-23-2026
1 2
1
2
0xAli
Hi,I want to integrate MS Exchange Server : Version 2022 using the below TA-Addon:Splunk Add-on for Microsoft Exchang...
by 0xAli Path Finder in Getting Data In 06-23-2026
0 2
0
2
refahiati
We are using the CiscoSecurityCloud TA 3.6.7 to ingest firewall events via eStreamer from a single FMC that has 5 fir...
by refahiati Explorer in Getting Data In 06-22-2026
0 0
0
0
ankit13
Hi Everyone, We have successfully integrated a Sophos XG Firewall with Splunk using Splunk Connect for Syslog (SC4S)....
by ankit13 Loves-to-Learn Lots in Getting Data In 06-21-2026
0 2
0
2
neelamsantosh
After upgrading our distributed environment to 10.2.x (multi-site indexer cluster, RHEL 8), the Search Head suddenly ...
by neelamsantosh Path Finder in Getting Data In 06-17-2026
4 1
4
1
0xAli
Hi All,I hope all is well.Kindly, anyone works with Guardium API Add-on for Splunk:https://splunkbase.splunk.com/app/...
by 0xAli Path Finder in Getting Data In 06-17-2026
0 2
0
2
licadiw273
Hi everyone, I’ve been hanging around the Splunk community for a while, mostly dealing with application logs, but I’v...
by licadiw273 New Member in Monitoring Splunk 06-17-2026
0 1
0
1
avadhi
HelloI am working on the DynamoDB metrics, where I have found some metrics are available in the cloudwatch but not in...
by avadhi New Member in Getting Data In 06-16-2026
0 1
0
1
las
Hi.I have a business requirement where I need to index data from multiple of our vendors that also use Splunk.The ven...
by las Builder in Getting Data In 06-15-2026
0 16
0
16
Enzo54
Hello,We are using a CSV lookup file in some of our searches. This file was the source of an error, throwing Error in...
by Enzo54 Explorer in Getting Data In 06-15-2026
0 7
0
7
Andre_
Hello,I am about to onboard 1000+ Windows UF. Those have windows event logs going back many years. Is there a way to ...
by Andre_ Communicator in Getting Data In 06-15-2026
0 28
0
28
splunkreal
Hello, can't add Edge processor, also getting errors on health status regarding data management :  Thanks. 
by splunkreal Influencer in Deployment Architecture 06-15-2026
0 5
0
5
Wohamed_wakkad
"I am writing this thread to summarize the Monitoring Console (MC) configuration and highlight the non-obvious nuance...
by Wohamed_wakkad Explorer in Monitoring Splunk 06-15-2026
0 2
0
2
Mohamamd_Mir
Hello,I'm trying to configure Edge Processor using the Data Management App. However, whenever I enable it, I encounte...
by Mohamamd_Mir Explorer in Deployment Architecture 06-14-2026
0 2
0
2
ikulcsar
Hi there, I'm building a test Splunk deployment: 3 SH in cluster, 2x2 IX in multi-site cluster, 1 admin node(CM, Dep...
by ikulcsar Communicator in Monitoring Splunk 06-13-2026
0 9
0
9
Wohamed_wakkad
Question 1: Will co-locating the License Master (LM) and Monitoring Console (MC) cause issues when forwarding interna...
by Wohamed_wakkad Explorer in Deployment Architecture 06-12-2026
0 5
0
5
0xAli
Hi,We want to migrate from the ESXI VM to the Hyper-V:Our Initial approach:Fresh OS + Splunk installations on Hyper-V...
by 0xAli Path Finder in Deployment Architecture 06-12-2026
0 6
0
6
sirpatrick
I use the TA-oci-logging-addon and I have to migrate this add-on to a new server, but I'm not sure if it uses a check...
by sirpatrick Explorer in Getting Data In 06-11-2026
0 2
0
2
narenrecw
How to set up the ' Personal Access Token' using the trial account 
by narenrecw New Member in Monitoring Splunk 06-07-2026
0 2
0
2
martaBenedetti
Hi all,I need to migrate heavy forwarders, search head cluster and search head deployer,  cluster manager, license ma...
by martaBenedetti Path Finder in Deployment Architecture 06-04-2026
0 6
0
6
kfsplunk
Onboarding Cisco FTD firewalls presents the choice of which Add-On to use. Apparently Cisco FTD firewalls run both AS...
by kfsplunk Loves-to-Learn in Getting Data In 06-02-2026
0 3
0
3
igall
Good afternoon,I have a problem on my Splunk instance v.9.4.10 where the "Forwarder Management" page is indefinitely ...
by igall Loves-to-Learn in Deployment Architecture 06-01-2026
0 2
0
2
Hemant0808
PCAP Data contains media and audio file, Is it possible that can be converted to other format and ingest in splunk
by Hemant0808 New Member in Getting Data In 05-31-2026
0 4
0
4
SPLAUR
Dear splunk community,After successfully implementing the input from @afx :"How to Splunk the SAP Security Audit Log"...
by SPLAUR Engager in Getting Data In 05-29-2026
0 7
0
7
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...
Top Karma Authors