Splunk Enterprise

Splunk Enterprise
Community Activity
AviSharma8
I need to upgrade the universal forwarder agents on the multiple instance from the current 7.3.0 to the latest versio...
by AviSharma8 New Member in Splunk Enterprise 04-03-2025
0 8
0
8
jfaldmomacu
I'm getting thousands of log events that says --ERROR CMSlave [2549383 CMNotifyThread] - Cannot find bid=wineventlog~...
by jfaldmomacu Path Finder in Splunk Enterprise 04-02-2025
0 6
0
6
krusovice
In my environment, I've setup the SSL communication and authentication between Deployment Server and its deployment c...
by krusovice Path Finder in Splunk Enterprise 04-02-2025
0 8
0
8
splunkkk
Hi. Recently I notice that the splunk heavy forwarder has stop receiving logs from network devices.  We are using TLS...
by splunkkk Loves-to-Learn in Splunk Enterprise 04-02-2025
0 6
0
6
SplunkExplorer
Hi Splunkers, today I have the following issue: on our SHC, there is a small app subset that is managed, and so modif...
by SplunkExplorer Contributor in Splunk Enterprise 04-02-2025
0 2
0
2
msmadhu
HiPlease assist how to build Splunk deployment servers clustering with minimum requirement. 
by msmadhu Path Finder in Splunk Enterprise 04-02-2025
0 1
0
1
chengjiok
 Is it normal for this script to run all the time and take up a lot of memory? Is there any way to reduce memory usag...
by chengjiok Observer in Splunk Enterprise 04-02-2025
0 2
0
2
azer271
Hi. I am new to Splunk and SentinelOne. Here is what I've done so far:I need to forward logs from SentinelOne to a si...
by azer271 Path Finder in Splunk Enterprise 03-28-2025
0 6
0
6
Devika_20
We are using the following PowerShell script to monitor Azure AD authentication-enabled URLs in Splunk. However, when...
by Devika_20 New Member in Splunk Enterprise 03-28-2025
0 1
0
1
sylee
I'm experiencing an issue with the Splunk DB Connect app under Data Inputs > Choose Table where the Schema dropdown f...
by sylee Engager in Splunk Enterprise 03-27-2025
0 9
0
9
SrinivasuluS
Hi All,I want a SPL query to get total size occupied/consumed by each index till now since the date of onboarding and...
by SrinivasuluS Observer in Splunk Enterprise 03-25-2025
0 4
0
4
johnjohn
Hi All,I need to automate the execution of specific queries in Splunk Enterprise on a weekly basis, export the result...
by johnjohn Engager in Splunk Enterprise 03-24-2025
0 2
0
2
domino30
There a about 3 ways to set up outputs.conf and  when you trying to setup forwarders.  you can either do a cli entry ...
by domino30 Path Finder in Splunk Enterprise 03-24-2025
0 2
0
2
MichaelM1
I have a configuration where I have an intermediate forward that is forwarding logs to central indexer that I do not ...
by MichaelM1 Explorer in Splunk Enterprise 03-24-2025
0 13
0
13
msmadhu
Hello, teamI've made script, which uses the sudo command. I've deployed it on my forwarders and I get the error:messa...
by msmadhu Path Finder in Splunk Enterprise 03-23-2025
0 14
0
14
Andre_
Hello, is it possible to restrict Splunk roles by source IP?example:Splunk role: my_user_role, allowed source IPs 172...
by Andre_ Path Finder in Splunk Enterprise 03-23-2025
0 9
0
9
robertlynch2020
HiI have the following data.I am looking to get a line per data, so I can work with it better.If I use mvexpand I hit...
by robertlynch2020 Influencer in Splunk Enterprise 03-20-2025
0 13
0
13
MrLR_02
Hello,I have defined a frozenTimePeriodInSecs for 1 hour on my IDX for a certain index, so that the logs it contains ...
by MrLR_02 Explorer in Splunk Enterprise 03-20-2025
0 3
0
3
blanky
There was a time when the indexer server shut down unexpectedly, And I've been struggle with indexer clustering rf & ...
by blanky Explorer in Splunk Enterprise 03-19-2025
0 7
0
7
scottmkirkland
I'm having trouble getting my duration into the format I'd prefer... I'd like to see the duration to be MM:SS. Howeve...
by scottmkirkland Explorer in Splunk Enterprise 03-19-2025
0 6
0
6
Sukhmeet
Here is the situationSearch web security appliance data (index=network sourcetype=cisco_wsa_squid) for non-businessac...
by Sukhmeet New Member in Splunk Enterprise 03-19-2025
0 1
0
1
Space_Crawler
Hi,I am working on installing CA-signed (ssl.com) cert to a splunk enterprise instance, and keep hitting these two er...
by Space_Crawler Observer in Splunk Enterprise 03-19-2025
0 3
0
3
danielbb
For our indexers, we see the following under 'Storage I/O Saturation (Mount Point)' - 0.90% (/opt/splunk) 6.56% (/ind...
by danielbb Motivator in Splunk Enterprise 03-18-2025
0 1
0
1
Nraj87
Hi , How to convert 2025-03-13T11:03:38Z to the "%d/%m/%Y %I:%M:%S ".I have tried this, but it didn't work.| eval Las...
by Nraj87 Explorer in Splunk Enterprise 03-17-2025
0 3
0
3
TheEggi98
Hi splunkers,is it possible to restrict indexaccess to specific appcontext?like a user has read access to app a and w...
by TheEggi98 Path Finder in Splunk Enterprise 03-14-2025
0 2
0
2
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...