Splunk Enterprise

Splunk Enterprise
Community Activity
garias_splunk
Due to a disaster the Cluster Master of my indexer cluster is gone. There is no way to recover its data and we do not...
by garias_splunk Splunk Employee Splunk Employee in Splunk Enterprise 11-28-2021
0 1
0
1
SamHTexas
There is a maintenance being performed & we are told that an Index (part of a cluster) is going to be moved to a new ...
by SamHTexas Builder in Splunk Enterprise 11-27-2021
0 4
0
4
SamHTexas
Since TAs run in the background & usually not viewed, how do I check on their health? Any useful SPLs are appreciated...
by SamHTexas Builder in Splunk Enterprise 11-26-2021
0 3
0
3
shreyasamin64
| eval new_name=mvindex(split(name, ","),0),         first name 0 and last name 1split first and last namewhy split a...
by shreyasamin64 Explorer in Splunk Enterprise 11-26-2021
0 4
0
4
antonio147
hi,I have a question to ask: can you assign values to multiple variables in Splunk with the case command?I need that ...
by antonio147 Communicator in Splunk Enterprise 11-26-2021
0 4
0
4
robertlynch2020
HI Is it possible to do left outer join after using two |mstats commands like below?I have Process_Name common to bot...
by robertlynch2020 Influencer in Splunk Enterprise 11-25-2021
0 0
0
0
tbenpr
Hello,I am new to Splunk and I would like to create an app for my dashboards that would be visible on all Search Head...
by tbenpr New Member in Splunk Enterprise 11-25-2021
0 3
0
3
sh254087
What is the license required to be acquired for a single instance splunk enterprise deployment which involves zero da...
by sh254087 Communicator in Splunk Enterprise 11-25-2021
0 2
0
2
SamHTexas
I work in a large environment clustered mostly, have Splunk Ent., ES. SHs & Indexers clustered) There is a maintenanc...
by SamHTexas Builder in Splunk Enterprise 11-24-2021
0 3
0
3
gitingua
Not working SEDCMD in my props.conf /opt/splunk/etc/system/local/props.conf [ActiveDirectory]SEDCMD-mask_ms_pwd = s/(...
by gitingua Communicator in Splunk Enterprise 11-23-2021
0 12
0
12
Rcope96
I am looking to see if anyone knows how to do this or if it is possible. I am trying to have splunk read to the Activ...
by Rcope96 New Member in Splunk Enterprise 11-23-2021
0 0
0
0
anil15694
Hi Splunkers,I am getting below error while configuring the SSL certificate among the splunk hosts.ERROR DistributedT...
by anil15694 Explorer in Splunk Enterprise 11-23-2021
0 1
0
1
roopeshetty
Hi Guys, We are using “Microsoft Azure App for Splunk” by getting inputs from “Splunk Add-on for Microsoft Cloud Serv...
by roopeshetty Path Finder in Splunk Enterprise 11-22-2021
0 0
0
0
msyazdani
HiFriends, does anyone know the Application for cyberoam firewall?After selling Cyberoam to Sophos, other Application...
by msyazdani Loves-to-Learn in Splunk Enterprise 11-21-2021
0 0
0
0
robertlynch2020
After using multiple append=t and prestat=tI am unable to use stats to capture the data into one nice line, as one of...
by robertlynch2020 Influencer in Splunk Enterprise 11-19-2021
0 4
0
4
antonio147
Hi all,I have a problem that I cannot solve.I have data that is a result of a loadjob where the fields are named 0_PR...
by antonio147 Communicator in Splunk Enterprise 11-19-2021
0 9
0
9
splunkingsplk
Splunk app for AWS - config loading issue Using enterprise and app for aws both are latest versions .Please find the ...
by splunkingsplk Explorer in Splunk Enterprise 11-19-2021
0 0
0
0
SamHTexas
What settings, functionalities or areas would you check in a Newly installed Splunk Enterprise 8.2.3 making sure all ...
by SamHTexas Builder in Splunk Enterprise 11-18-2021
0 0
0
0
tnguyengtn
In a locked down environment where outbound traffic is explicit, what is the IP range or URL to facilitate the "splun...
by tnguyengtn Engager in Splunk Enterprise 11-18-2021
0 3
0
3
schose
Hi all,we are currently testing desaster recovery of our enviroment. We have a full backup of kvstore, apps and passw...
by schose Builder in Splunk Enterprise 11-18-2021
0 1
0
1
SamHTexas
I am making a list of Splunk critical services to be notified about after hours & weekends to revive Splunk in case i...
by SamHTexas Builder in Splunk Enterprise 11-18-2021
0 1
0
1
eduardo1989
I have faced a very interesting situation and have no clue what is going wrong.I have a forwarded info from a particu...
by eduardo1989 Path Finder in Splunk Enterprise 11-18-2021
0 10
0
10
Che
Splunk Enterprise specifically lists Windows OS requirements being Windows Server 2016 and Server 2019.  Is Windows S...
by Che New Member in Splunk Enterprise 11-17-2021
0 0
0
0
SamHTexas
I need to learn the data Retention settings for Splunk Ent. & ES in my environment. Would you share a SPL if there ar...
by SamHTexas Builder in Splunk Enterprise 11-16-2021
0 1
0
1
Azwaliyana
I want to extract the Country and the Node. When I use the rex in regex101, it works fine. But when I put it on Splun...
by Azwaliyana Path Finder in Splunk Enterprise 11-16-2021
0 3
0
3
Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...
Top Solution Authors