Splunk Enterprise

Splunk Enterprise
Community Activity
rukshar
 We are trying to configure event monitoring for Security Event ID 4624 (successful login) and Event ID 4625 (unsucce...
by rukshar Explorer in Splunk Enterprise 04-04-2025
0 6
0
6
ynag
Hi, I'm trying to use the Splunk Add-On for VMware with the DCN OVA. The installation process is done according to th...
by ynag Explorer in Splunk Enterprise 04-04-2025
0 4
0
4
Knust
Hi, I want to know if there is any resources available to get a notification or some way to know when a new Splunk En...
by Knust Explorer in Splunk Enterprise 04-03-2025
1 4
1
4
AviSharma8
I need to upgrade the universal forwarder agents on the multiple instance from the current 7.3.0 to the latest versio...
by AviSharma8 New Member in Splunk Enterprise 04-03-2025
0 8
0
8
jfaldmomacu
I'm getting thousands of log events that says --ERROR CMSlave [2549383 CMNotifyThread] - Cannot find bid=wineventlog~...
by jfaldmomacu Path Finder in Splunk Enterprise 04-02-2025
0 6
0
6
krusovice
In my environment, I've setup the SSL communication and authentication between Deployment Server and its deployment c...
by krusovice Path Finder in Splunk Enterprise 04-02-2025
0 8
0
8
splunkkk
Hi. Recently I notice that the splunk heavy forwarder has stop receiving logs from network devices.  We are using TLS...
by splunkkk Loves-to-Learn in Splunk Enterprise 04-02-2025
0 6
0
6
SplunkExplorer
Hi Splunkers, today I have the following issue: on our SHC, there is a small app subset that is managed, and so modif...
by SplunkExplorer Contributor in Splunk Enterprise 04-02-2025
0 2
0
2
msmadhu
HiPlease assist how to build Splunk deployment servers clustering with minimum requirement. 
by msmadhu Path Finder in Splunk Enterprise 04-02-2025
0 1
0
1
chengjiok
 Is it normal for this script to run all the time and take up a lot of memory? Is there any way to reduce memory usag...
by chengjiok Observer in Splunk Enterprise 04-02-2025
0 2
0
2
azer271
Hi. I am new to Splunk and SentinelOne. Here is what I've done so far:I need to forward logs from SentinelOne to a si...
by azer271 Path Finder in Splunk Enterprise 03-28-2025
0 6
0
6
Devika_20
We are using the following PowerShell script to monitor Azure AD authentication-enabled URLs in Splunk. However, when...
by Devika_20 New Member in Splunk Enterprise 03-28-2025
0 1
0
1
sylee
I'm experiencing an issue with the Splunk DB Connect app under Data Inputs > Choose Table where the Schema dropdown f...
by sylee Engager in Splunk Enterprise 03-27-2025
0 9
0
9
SrinivasuluS
Hi All,I want a SPL query to get total size occupied/consumed by each index till now since the date of onboarding and...
by SrinivasuluS Observer in Splunk Enterprise 03-25-2025
0 4
0
4
johnjohn
Hi All,I need to automate the execution of specific queries in Splunk Enterprise on a weekly basis, export the result...
by johnjohn Engager in Splunk Enterprise 03-24-2025
0 2
0
2
domino30
There a about 3 ways to set up outputs.conf and  when you trying to setup forwarders.  you can either do a cli entry ...
by domino30 Path Finder in Splunk Enterprise 03-24-2025
0 2
0
2
MichaelM1
I have a configuration where I have an intermediate forward that is forwarding logs to central indexer that I do not ...
by MichaelM1 Explorer in Splunk Enterprise 03-24-2025
0 13
0
13
msmadhu
Hello, teamI've made script, which uses the sudo command. I've deployed it on my forwarders and I get the error:messa...
by msmadhu Path Finder in Splunk Enterprise 03-23-2025
0 14
0
14
Andre_
Hello, is it possible to restrict Splunk roles by source IP?example:Splunk role: my_user_role, allowed source IPs 172...
by Andre_ Communicator in Splunk Enterprise 03-23-2025
0 9
0
9
robertlynch2020
HiI have the following data.I am looking to get a line per data, so I can work with it better.If I use mvexpand I hit...
by robertlynch2020 Influencer in Splunk Enterprise 03-20-2025
0 13
0
13
MrLR_02
Hello,I have defined a frozenTimePeriodInSecs for 1 hour on my IDX for a certain index, so that the logs it contains ...
by MrLR_02 Explorer in Splunk Enterprise 03-20-2025
0 3
0
3
blanky
There was a time when the indexer server shut down unexpectedly, And I've been struggle with indexer clustering rf & ...
by blanky Explorer in Splunk Enterprise 03-19-2025
0 7
0
7
scottmkirkland
I'm having trouble getting my duration into the format I'd prefer... I'd like to see the duration to be MM:SS. Howeve...
by scottmkirkland Explorer in Splunk Enterprise 03-19-2025
0 6
0
6
Sukhmeet
Here is the situationSearch web security appliance data (index=network sourcetype=cisco_wsa_squid) for non-businessac...
by Sukhmeet New Member in Splunk Enterprise 03-19-2025
0 1
0
1
Space_Crawler
Hi,I am working on installing CA-signed (ssl.com) cert to a splunk enterprise instance, and keep hitting these two er...
by Space_Crawler Observer in Splunk Enterprise 03-19-2025
0 3
0
3
Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...
Top Solution Authors