Splunk Administration

Splunk Administration
Category Activity
0xAli
Hi Everyone,Anyone integrated the Forcepoint DLP with splunk? What is the proper method? is there any Add-on FP DLP?
by 0xAli Path Finder in Getting Data In 05-26-2026
0 3
0
3
pdominicb
I am about to have a few UFs monitoring some extremely high volume logs. These high volume logs are less critical tha...
by pdominicb Explorer in Getting Data In 05-24-2026
0 8
0
8
spl_aficionado
We have two active-active deployment servers in place. Quite often, apps reach their destination in a week's delay. I...
by spl_aficionado Path Finder in Deployment Architecture 05-22-2026
0 9
0
9
VK18
Hi All,We have approximately 100 Splunk Universal Forwarders (UFs) installed at a remote site, and we're interested i...
by VK18 Explorer in Deployment Architecture 05-22-2026
0 9
0
9
pdominicb
I have events with URLs, and the URLs contain parameters with KV values in them. Splunk auto extracts the KV pairs, b...
by pdominicb Explorer in Getting Data In 05-22-2026
0 10
0
10
loganallen
I am trying to implement a postfilter in Splunk Connect for Syslog to drop east-west (internal-to-internal) Fortigate...
by loganallen Loves-to-Learn in Getting Data In 05-20-2026
0 0
0
0
Araton71
I've configured my splunk enterprise to get saml login with keycloak.[authentication]authSettings = samlauthType = SA...
by Araton71 Explorer in Security 05-20-2026
0 1
0
1
himanshu2
I have a 2 search heads in a Splunk SH cluster in the dev environment. Recently, I upgraded Splunk from 9.3.8 to 9.4....
by himanshu2 Loves-to-Learn in Deployment Architecture 05-19-2026
0 2
0
2
Karthikeya
We have to pull logs from Tencent COS (Cloud Object Storage) to our Splunk instances which are hosted on AWS. Tencent...
by Karthikeya Communicator in Getting Data In 05-19-2026
0 7
0
7
volly
iv just created a new account.iv have admin role assigned to my user account iv given admin role all permissions, yet...
by volly New Member in Getting Data In 05-18-2026
0 2
0
2
spl_aficionado
We recently found out that we couldn't send TCP data as Syslog because it didn't have the proper header, but streamin...
by spl_aficionado Path Finder in Getting Data In 05-16-2026
0 4
0
4
wellsjp
We use HEC to ingest data from multiple sources but are starting to see the requirement for OAuth and other security ...
by wellsjp Loves-to-Learn Lots in Getting Data In 05-15-2026
0 5
0
5
javier_oshiro
We are currently configuring the DUO security MFA on Splunk Enterprise and we noticed that the local account admin ge...
by javier_oshiro Explorer in Security 05-13-2026
0 1
0
1
ASierra
There have been reports that the February 2026 MS update kills the RPC call to the Domain Controllers for various ver...
by ASierra Explorer in Monitoring Splunk 05-13-2026
0 1
0
1
arthy-velusamy
We are trying to ingest JSON data to Splunk Ingest Processor. Sometimes JSON data is getting ingested properly and ma...
by arthy-velusamy Observer in Getting Data In 05-13-2026
0 1
0
1
jni
Hi,I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".To me, the journald-filte...
by jni Explorer in Getting Data In 05-12-2026
0 7
0
7
0xAli
Hi Everyone,While using Syslog-NG to monitor network traffic and write it into file,  I want to ask about the Log fil...
by 0xAli Path Finder in Getting Data In 05-11-2026
0 6
0
6
romquestaai_gma
As organizations increasingly adopt AI tools for automation, analytics, and decision-making, protecting sensitive dat...
by romquestaai_gma New Member in Deployment Architecture 05-11-2026
0 2
0
2
gitau_gm
I am observing inconsistent forwarding of Windows Security Event ID 4624 (Successful Logon) from multiple Windows hos...
by gitau_gm Explorer in Getting Data In 05-08-2026
0 9
0
9
Khairul_Irsyad
Referring to this  question (Not all Splunk cookies have the HttpOnly tag set) , answered by @anaidu_splunk , I can s...
by Khairul_Irsyad Loves-to-Learn in Security 05-07-2026
0 1
0
1
thehow
Current setup - Indexers --> F5 VIP --> CM CM is seeing the requests are coming F5 VIP rather than actual source ip o...
by thehow Loves-to-Learn in Deployment Architecture 05-05-2026
0 2
0
2
mgaraventa_splu
In my use-case my source log (tailed by a monitor input stanza) is being archived once a day at midnight and the resu...
by mgaraventa_splu Splunk Employee Splunk Employee in Monitoring Splunk 05-05-2026
3 3
3
3
kvm
Hi,I'm required to integrate the Alogsec  Security Management Suite (ASMS) logs via API method to cover the richer vi...
by kvm Explorer in Getting Data In 05-05-2026
0 3
0
3
zapping575
One of my sourcetypes is a CSV file (with CSV header)I was using this sourcetype stanza in props.conf:[foo_bar] INDEX...
by zapping575 Communicator in Getting Data In 04-29-2026
0 1
0
1
LovingSplunk
We are planning to decommission our Cribl environment and migrate all data ingestion directly back to Splunk. I am lo...
by LovingSplunk Path Finder in Deployment Architecture 04-28-2026
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...
Top Karma Authors