Splunk Administration

Splunk Administration
Category Activity
malisushil119
we have below setupSite 1- Search Head, Indexer, Cluster master & License MasterSite 2: Search Head, Indexer, Cluster...
by malisushil119 Explorer in Deployment Architecture 04-21-2026
0 9
0
9
hazem
Is there any documentation in Splunk's documentation to guide a load balancer administrator on configuring the load b...
by hazem Path Finder in Deployment Architecture 04-21-2026
0 19
0
19
Solitus31
Hello,we are trying to use splunk_app_uf_remote_upgrade_windows to upgrade our UF using Deployment server.I have inst...
by Solitus31 Explorer in Getting Data In 04-20-2026
0 2
0
2
harrymclaren
Hello, I have built a Splunk testing / staging environment on top of 6 VMs. Splunk version is 6.2.3 and us running on...
by harrymclaren Explorer in Deployment Architecture 04-20-2026
0 23
0
23
Kat7
Hello, I would like to automatically send the audit logs from PDQ Connect into our Splunk environment.  I can manuall...
by Kat7 Explorer in Getting Data In 04-19-2026
0 3
0
3
HexalNull
Hi All, I’m facing an issue while installing the Splunk Universal Forwarder on my Windows server using the MSI comman...
by HexalNull Engager in Deployment Architecture 04-17-2026
0 13
0
13
ljo4497
Hi, We currently have a centralized WEF collection server that collects all windows logs across the environment.This ...
by ljo4497 Explorer in Getting Data In 04-15-2026
1 9
1
9
splunker_ak
On our SOC operations dashboard we can already see the overall MTTD (Mean Time to Detect) and MTTT (Mean Time to Tria...
by splunker_ak Explorer in Monitoring Splunk 04-13-2026
0 4
0
4
duesser
I have data of the following structure in Kafka.{"id": "ABC", "name": "lukas", "timestamp": 1775567475, "payload": 37...
by duesser Path Finder in Getting Data In 04-12-2026
0 7
0
7
durnan13
Hello Everyone!We have what we have been told is not a complete ideal setup where we have searchable data for 90 days...
by durnan13 Explorer in Getting Data In 04-11-2026
0 11
0
11
ChrisTahoe
After a complete install of Splunk Enterprise 10.2.2 for macOS, was about to launch it then I had this error:ERROR: s...
by ChrisTahoe Loves-to-Learn in Installation 04-09-2026
0 2
0
2
LogUx
Hello Splunkers1!I am encountering an issue with field extraction related to the sourcetype. My requirement is to map...
by LogUx Motivator in Getting Data In 04-08-2026
0 9
0
9
splunkettes
When restarting an indexer in our cluster, I first put the cluster in maintenance mode. The indexer restarts within m...
by splunkettes Path Finder in Getting Data In 04-08-2026
0 4
0
4
kjain041523
kjain041523_0-1775550170150.png 
by kjain041523 Observer in Knowledge Management 04-08-2026
0 4
0
4
cjharmening
Hello all,  Starting end of next week my team will be doing a POV of Splunk ES as a possible replacement of our curre...
by cjharmening Loves-to-Learn Lots in Getting Data In 04-07-2026
0 3
0
3
LovingSplunk
We have this vulnerability on several forwarders -OpenSSL 1.0.2 < 1.0.2zn Multiple Vulnerabilities(https://www.tenabl...
by LovingSplunk Path Finder in Deployment Architecture 04-07-2026
0 1
0
1
Beerman
After upgrading to Debian 13 Journald input is not working anymore with Splunk 10.x.This error I found in the interna...
by Beerman New Member in Getting Data In 04-07-2026
0 5
0
5
aoliver
Hello,I’m a Splunk admin supporting a government environment. We’ve historically used both the STIGs and the SRGs to ...
by aoliver Engager in Security 04-02-2026
1 1
1
1
Darkvader
Search peer appprd09 has the following message: The current bundle directory contains a large lookup file that might ...
by Darkvader Explorer in Monitoring Splunk 04-01-2026
0 1
0
1
spulivarthi700
Hey team,If we want to reduce pressure on our Splunk indexers and our data is routing through Cribl, what does Splunk...
by spulivarthi700 Loves-to-Learn in Getting Data In 04-01-2026
0 2
0
2
Cerum
Has anyone had any luck getting Open AI Compliance API logs into Splunk Cloud? This API ships logs that provide visib...
by Cerum Loves-to-Learn in Getting Data In 03-31-2026
0 3
0
3
Stem
I have installed the UF(.v 10.2.1) on a Windows server using the cli command below. Splunk appears to install success...
by Stem Engager in Getting Data In 03-30-2026
1 4
1
4
manchou0709
Hi All,I am trying to list out all the universal forwarders which are currently not connected/disconnected with the d...
by manchou0709 Explorer in Deployment Architecture 03-30-2026
0 15
0
15
eafitt
Hello, Fresh out of college with a Cyber Security degree, I'm relatively new to the field. We recently purchased a ...
by eafitt Path Finder in Security 03-30-2026
0 4
0
4
Chris_Urman
I'm setting up Dynatrace synthetic monitors to replicate user experience in Splunk and I am having trouble getting a ...
by Chris_Urman Engager in Monitoring Splunk 03-26-2026
0 4
0
4
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.
Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...
Top Karma Authors