| Thread Info | |||||
|---|---|---|---|---|---|
| 
      
        Hello All,
  I am testing the data inputs for Splunk Addon for ServiceNow and there is a requirement to include only ...
        
       
         
           by 
           
                
                    
                        izzie123
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               11-28-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi there, what are the best practices to migrate from Azure sentinel to Splunk, we want to migrate sources, historica...
        
       
         
           by 
           
                
                    
                        sa128c
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               11-28-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        We have 24 indexers in an indexer cluster. Recently the CPU usage is almost 100%, not on all the indexers but it fluc...
        
       
         
           by 
           
                
                    
                        shadysplunker
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-27-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi
  I want to inventory all Splunk tools related to artificial intelligence and observability 
  Here is the list: 
...
        
       
         
           by 
           
                
                    
                        jip31
                    
                
           
             
             
               Motivator
             
           
           in
           Splunk Enterprise
           
           
              
               11-27-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi, is it possible to organize users by functional area for example : Security, IT, NetOps,....
  In these areas, eac...
        
       
         
           by 
           
                
                    
                        Redha
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-09-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi, I want to find out how many license warnings there is in the current 60 day rolling window. Why is there not an e...
        
       
         
           by 
           
                
                    
                        Knust
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-22-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I am collecting logs from an Ubuntu server (16.04) using Splunk and would like to create an alert for when the Ubuntu...
        
       
         
           by 
           
                
                    
                        anh_nguyen
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-23-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I've got a new deployment of 9.1.1, upgraded from a prior version, I can't remember which off the top of my head.  I ...
        
       
         
           by 
           
                
                    
                        JSwofford
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Enterprise
           
           
              
               11-21-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi.
  Colleagues.Somebody help me?
  I have this query by current day (figure 1)
  index=xxxx sourcetype=xxx earliest...
        
       
         
           by 
           
                
                    
                        Gabriel_CCI
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-24-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello.
  I have two indexes and three users.  Each user is in specific AD group.  Each group is mapped to a respectiv...
        
       
         
           by 
           
                
                    
                        Jamie
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               11-22-2021
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I'm trying to set up a Proof of Concept (POC) environment for Splunk Heavy Forwarder (HF), which is receiving data fr...
        
       
         
           by 
           
                
                    
                        sarvananth
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-23-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hi Everyone,
  I would like to ask you about configuration ITSI. I want to configure ITSI, as I show you below exampl...
        
       
         
           by 
           
                
                    
                        jack3
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Enterprise
           
           
              
               11-23-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
         
  How to get rid of Splunk UNKNOWN_VERSION on splunk UI. This is happening on all the browsers (Chrome, Edge, Firef...
        
       
         
           by 
           
                
                    
                        himaniarora20
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-20-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  2
	 
 | |||
| 
      
        I have installed a free version of Splunk Enterprise 9.1 in my local system. I would need few logs files from my S3 b...
        
       
         
           by 
           
                
                    
                        akarivaratharaj
                    
                
           
             
             
               Communicator
             
           
           in
           Splunk Enterprise
           
           
              
               11-21-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        We are facing very strange issue as the objects of specific Apps reverted back to old settings even the lookup files ...
        
       
         
           by 
           
                
                    
                        HassanElDesouky
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               11-15-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        Greetings, I have Splunk 9.1.1 trying to import an aruba 7210 into splunk using the aruba app with udp 514. Sourcetyp...
        
       
         
           by 
           
                
                    
                        Daven
                    
                
           
             
             
               New Member
             
           
           in
           Splunk Enterprise
           
           
              
               11-17-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  0
	 
 | |||
| 
      
        Hi, 
  How can I pull data from sharepoint to splunk? 
  What are various options available to pull data? 
  any sugg...
        
       
         
           by 
           
                
                    
                        Ashwini008
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               08-25-2020
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  5
	 
 | |||
| 
      
        Is there a suggested size of lookup that would be the maximum size of a lookup that should be used for an automatic l...
        
       
         
           by 
           
                
                    
                        jaburke1
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               11-15-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hi all,
  I am new to SPLUNK and would appreciate some community wisdom. We are trying to get data from an external A...
        
       
         
           by 
           
                
                    
                        ran
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               11-16-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        Hello everyone,
  
   
    
     I am encountering an issue with the Alert Manager Enterprise application; following ...
        
       
         
           by 
           
                
                    
                        MCH2018
                    
                
           
             
             
               Explorer
             
           
           in
           Splunk Enterprise
           
           
              
               11-14-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  3
	 
 | |||
| 
      
        I'm trying to troubleshoot some Windows Event Log events coming into Splunk.
  The events are stream processed, and c...
        
       
         
           by 
           
                
                    
                        ejwade
                    
                
           
             
             
               Contributor
             
           
           in
           Splunk Enterprise
           
           
              
               11-08-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  7
	 
 | |||
| 
      
        Hi!Faced with a very specific problem.We use splunk enterprise 7.3.0. We have ru_RU written in the address bar instea...
        
       
         
           by 
           
                
                    
                        Vadim_Peskov
                    
                
           
             
             
               Observer
             
           
           in
           Splunk Enterprise
           
           
              
               11-14-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        Hello,
  We had this error on an output query set-up on Splunk DB Connect.
  Basically the Splunk query is inserting ...
        
       
         
           by 
           
                
                    
                        edoardo_vicendo
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               11-14-2023
             
           
         
        
      | 
   
		
		1
   
 | 	 
	  
	  1
	 
 | |||
| 
      
        index=gbts-vconnection sourcetype=VMWareVDM_debug "onEvent: DISCONNECTED" (host=Host1 OR host=host2)| rex field=_raw ...
        
       
         
           by 
           
                
                    
                        Madmax
                    
                
           
             
             
               Path Finder
             
           
           in
           Splunk Enterprise
           
           
              
               11-06-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  4
	 
 | |||
| 
      
        I had this search set up:
   
  
   index=_internal source=*splunkd_ui_access.log /app NOT(user="-" OR uri_path="*/ap...
        
       
         
           by 
           
                
                    
                        fatsug
                    
                
           
             
             
               Builder
             
           
           in
           Splunk Enterprise
           
           
              
               11-14-2023
             
           
         
        
      | 
   
		
		0
   
 | 	 
	  
	  1
	 
 |