Splunk Administration

Splunk Administration
Category Activity
eddieddieddie
I'm trying to measure the amount of data leaving a heavy forwarder (called HVYFWD01).This is in preparation to moving...
by eddieddieddie Path Finder in Getting Data In 02-17-2026
0 1
0
1
ilhwan
I'm trying to rewrite the host field on events that are coming into a HEC on a HF.  It's populating the hostname of t...
by ilhwan Path Finder in Getting Data In 02-17-2026
0 8
0
8
triptraptresko
After completing the upgrade from Splunk Enterprise version 9.3.3 to v9.4 the KVstore will no longer start. Splunk ha...
by triptraptresko Path Finder in Deployment Architecture 02-17-2026
7 3
7
3
AceX
Cannot read properties of undefined (reading '0') (error(s) 1/1)
by AceX Loves-to-Learn Lots in Deployment Architecture 02-16-2026
0 2
0
2
sswigart
My network has Splunk Enterprise 10.0.2, and it is air-gapped.I want to run a Linux and Windows enterprise server sid...
by sswigart Explorer in Getting Data In 02-16-2026
0 4
0
4
dania_abujuma
Hello, I have a question regarding the indexer cluster, can we have 2 peers hosted in different networks / sites? Of ...
by dania_abujuma Explorer in Deployment Architecture 02-16-2026
0 1
0
1
e_charles
I'm working with a Customer who has  some questions in regards how the # Active host are being counted specifically f...
by e_charles New Member in Monitoring Splunk 02-13-2026
0 0
0
0
Abass42
I would like to know how to properly configure my kvstore stanza to use my own self generated Server/Client authentic...
by Abass42 Communicator in Deployment Architecture 02-11-2026
0 3
0
3
spl_aficionado
@richgalloway explained clearly in the post, that INDEXED_EXTRACTIONS=CSV makes all the fields indexed. What would be...
by spl_aficionado Path Finder in Getting Data In 02-10-2026
0 1
0
1
spl_aficionado
I just set INDEXED_EXTRACTIONS = CSV for a large data ingestion sourcetype, and validating with tstats, and it seems ...
by spl_aficionado Path Finder in Getting Data In 02-09-2026
0 2
0
2
esalesapns2
Our indexers are reporting “server-busy” errors back to the kinesis data firehoses periodically.This is an indication...
by esalesapns2 Communicator in Monitoring Splunk 02-09-2026
0 3
0
3
b17gunnr
Hello folks,I have a compliance control requirement to alert when there is a log ingestion failure to Splunk. The des...
by b17gunnr Path Finder in Monitoring Splunk 02-09-2026
0 6
0
6
adnankhan5133
Hi,Does anyone know how to ingest the WAF logs generated by the Oracle Cloud Web Application Firewall service? The lo...
by adnankhan5133 Communicator in Getting Data In 02-09-2026
0 2
0
2
cmeo-bcit
I see from the latest release notes that the recommended sourcetype is ms:iis:auto and the others have been deprecate...
by cmeo-bcit Explorer in Getting Data In 02-08-2026
0 4
0
4
Navanitha
I am trying to forward win event security logs from server using UF to our Heavy forwarder.  UF has all the required ...
by Navanitha Path Finder in Getting Data In 02-06-2026
0 4
0
4
muradgh
I have a Fortigate firewall that was configured to send UDP logs, lately, I have configured it to send TCP logs inste...
by muradgh Path Finder in Getting Data In 02-06-2026
1 20
1
20
StuartMacL
I have the Splunk add-on for Amazon Web Services v 8.0.0 installed on a Heavy Forwarder and we have several inputs wo...
by StuartMacL Path Finder in Getting Data In 02-06-2026
0 1
0
1
Nraj87
please advise whether there is a solution or monitoring use case to identify interruptions in HEC base data ingestion...
by Nraj87 Explorer in Getting Data In 02-05-2026
0 3
0
3
Poojitha
Hi Everyone, I have created a custom app that clones current raw data , extracts metrics and dimensions from existing...
by Poojitha Communicator in Getting Data In 02-04-2026
0 2
0
2
marcokrueger
I give my splunk 50GB Mem with max_mem_usage_mb = 50480 in the limits.conf but splunk 5.0.3 gives me a "mvexpand out...
by marcokrueger Path Finder in Monitoring Splunk 02-02-2026
1 15
1
15
danielbb
We recently experienced a data gap for our Google index lasting several days. Our environment uses the following two ...
by danielbb Motivator in Getting Data In 02-02-2026
0 1
0
1
GSNRMUVW
Hi Community,how to cut..., "q": 0, "user": "system.user.admin"...from...{ "val": 0, "ts": 1770058561014, "q": 0, "us...
by GSNRMUVW Loves-to-Learn in Getting Data In 02-02-2026
0 6
0
6
briancronrath
I have been tasked with building out new instances of anything that runs an older OS, and for our EC2 instances this ...
by briancronrath Contributor in Getting Data In 02-02-2026
0 1
0
1
msaleh7422
I’m relatively new to Splunk and currently designing my first production architecture, so I’d really appreciate your ...
by msaleh7422 Engager in Deployment Architecture 02-02-2026
0 3
0
3
tchimento_splun
I'm an admin and I installed Splunk without an admin password. It’s now saying that "No users exist" and no one can l...
by tchimento_splun Splunk Employee Splunk Employee in Security 02-01-2026
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...
Top Karma Authors