Splunk Administration

Splunk Administration
Category Activity
Poojitha
Hi Everyone, I have created a custom app that clones current raw data , extracts metrics and dimensions from existing...
by Poojitha Communicator in Getting Data In 02-04-2026
0 2
0
2
marcokrueger
I give my splunk 50GB Mem with max_mem_usage_mb = 50480 in the limits.conf but splunk 5.0.3 gives me a "mvexpand out...
by marcokrueger Path Finder in Monitoring Splunk 02-02-2026
1 15
1
15
danielbb
We recently experienced a data gap for our Google index lasting several days. Our environment uses the following two ...
by danielbb Motivator in Getting Data In 02-02-2026
0 1
0
1
GSNRMUVW
Hi Community,how to cut..., "q": 0, "user": "system.user.admin"...from...{ "val": 0, "ts": 1770058561014, "q": 0, "us...
by GSNRMUVW Loves-to-Learn in Getting Data In 02-02-2026
0 6
0
6
briancronrath
I have been tasked with building out new instances of anything that runs an older OS, and for our EC2 instances this ...
by briancronrath Contributor in Getting Data In 02-02-2026
0 1
0
1
msaleh7422
I’m relatively new to Splunk and currently designing my first production architecture, so I’d really appreciate your ...
by msaleh7422 Engager in Deployment Architecture 02-02-2026
0 3
0
3
tchimento_splun
I'm an admin and I installed Splunk without an admin password. It’s now saying that "No users exist" and no one can l...
by tchimento_splun Splunk Employee Splunk Employee in Security 02-01-2026
0 3
0
3
msplunk33
Proof point email security app TA-Proofpoint-TAP stopped ingesting log. I get the below SSL error message in the splu...
by msplunk33 Path Finder in Installation 02-01-2026
0 5
0
5
loganallen
Hi All, I have SOC metric reporting dashboards for MTTR (mean time to respond) and MTTC (mean time to close) but am s...
by loganallen Loves-to-Learn in Monitoring Splunk 01-31-2026
0 2
0
2
Jayanthan
We have employed Cymulate, a BAS (Breach Attack Simulation) Solution for Red Teaming activity and Detection Engineeri...
by Jayanthan Loves-to-Learn Everything in Getting Data In 01-30-2026
0 0
0
0
danielbb
I have this "innocent" regex to send to the nullQueue in transforms.conf, and it doesn't work. I'm scratching my head...
by danielbb Motivator in Getting Data In 01-29-2026
0 5
0
5
msaleh7422
We would like your guidance on how to calculate the required number of Splunk indexers for our environment.Currently,...
by msaleh7422 Engager in Getting Data In 01-28-2026
0 2
0
2
LM_ACN
Hello Splunker, i need your help.I have a problem with monitoring a single XML file that records events from an appli...
by LM_ACN Engager in Getting Data In 01-27-2026
0 2
0
2
Vampire_splunk
When I ask the Splunk AI Assistant any question, it takes a long time to process and then returns the error message:A...
by Vampire_splunk New Member in Knowledge Management 01-27-2026
0 1
0
1
ws
Hi,I understand that ports below 1024 are reserved for root access. Is there any supported way for Splunk to listen o...
by ws Path Finder in Getting Data In 01-26-2026
0 6
0
6
johnjester
  I initialize a lookup file using:   | makeresults | outputlookup status.csv   I then have this simple search:   | i...
by johnjester Explorer in Installation 01-26-2026
0 4
0
4
HumanPrinter
We have a Splunk cluster running which consists of search heads, indexers, heavy forwarders and other Splunk instance...
by HumanPrinter Explorer in Security 01-25-2026
1 5
1
5
StephenD1
Currently I'm running the following SPL to confirm the UF downloaded a new config:index=_internal sourcetype=splunkd ...
by StephenD1 Path Finder in Deployment Architecture 01-23-2026
0 1
0
1
_pravin
Hi,I have incoming data from 2 Heavy Forwarders.Both of forward HEC data and the internal logs, how do I identify whi...
by _pravin Contributor in Getting Data In 01-22-2026
0 14
0
14
R15
Recently upgraded to 9.2.2 and Historic License Usage panels in the Monitoring Console are now broken. The panels in ...
by R15 Communicator in Monitoring Splunk 01-22-2026
0 4
0
4
shashankk
Refer below SPL query which I am using to get the UserId count against the server Instance. index=test_uat source=*/D...
by shashankk Communicator in Security 01-21-2026
0 2
0
2
spl_aficionado
Hello Splunk Community,My team is currently processing logs from a single source that can contain events with differe...
by spl_aficionado Path Finder in Getting Data In 01-21-2026
0 6
0
6
bil151515
Hey!My team is interested in integration of Splunk (especially ES) and TheHive Project products.The goal is to provid...
by bil151515 Engager in Getting Data In 01-20-2026
1 3
1
3
splunkreal
Hello, is it possible to push/upgrade a SHC app to single search head for testing, in a production cluster?Thanks. 
by splunkreal Influencer in Deployment Architecture 01-19-2026
0 2
0
2
kn450
 Hi,I’m trying to use Splunk as a log aggregation solution, and eventually as a SIEM. I have three industrial plants ...
by kn450 Explorer in Getting Data In 01-19-2026
0 1
0
1
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security, Observability, Platform and App Developer Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...
Top Karma Authors