Splunk Administration

Splunk Administration
Category Activity
nmohammed
We've logs coming to HEC as nested JSON in chunks; We're trying to break them down into individual events at the HEC ...
by nmohammed Builder in Getting Data In an hour ago
0 9
0
9
AsmaF2025
I have abunch of Splunk universal forwarder which runs on the version 6.6.3 - Linux machines. Im looking forward to u...
by AsmaF2025 Explorer in Deployment Architecture 6 hours ago
0 8
0
8
dendel
Hi All.Using Splunk for collecting logs from different devices.  But logs from on  devices on the network , is not pr...
by dendel New Member in Getting Data In 7 hours ago
0 1
0
1
VeloPunk
I'm on the server / infrastructure team at my organization. There is a dedicated Splunk team, and they want to replac...
by VeloPunk Engager in Deployment Architecture 7 hours ago
0 9
0
9
Mit
I'm attempting to set up an Independent Stream Forwarder on a RHEL machine to collect netflow data, and have it forwa...
by Mit New Member in Getting Data In 8 hours ago
0 0
0
0
corti77
Hi,I run splunk 9.0.8 and after an issue with our storage (LUN full). I had to full scan the disk and successfully re...
by corti77 Contributor in Knowledge Management 10 hours ago
0 4
0
4
capjacksparo
Hi Folks,New to Splunk and SC4S deploymenet. So far I have been able to make good progress. I have setup 2 SC4S serve...
by capjacksparo Engager in Getting Data In 13 hours ago
0 5
0
5
corti77
Hi,I am running splunk standalone 8.4.1 with Citrix add-on installed 8.2.3.  Also, I have SC4S running version 3.31.0...
by corti77 Contributor in Getting Data In 13 hours ago
0 1
0
1
Numb78
Hi all,I'm struggling with an issue related to collecting Fortinet Fortios events through SC4S. If I use UDP protocol...
by Numb78 Engager in Getting Data In 18 hours ago
0 1
0
1
msatish
Newly installed Universal forwarders on windows servers are forwarding logs to Splunk Cloud but newly installed forwa...
by msatish Explorer in Getting Data In 19 hours ago
0 2
0
2
kn450
Dear Splunk Community,I’m currently facing an urgent issue in my Splunk environment: my storage utilization has reach...
by kn450 Explorer in Deployment Architecture 19 hours ago
0 4
0
4
NatanS
Response Code: 401Response text: <?xml version="1.0" encoding="UTF-8"?><response><messages><msg type="WARN">call not ...
by NatanS Explorer in Getting Data In yesterday
1 8
1
8
shangshin
Hi, I downloaded splunk-4.3.1-119532-Linux-i686.gz on line, extracted, and ran the command /splunk start. However,...
by shangshin Builder in Installation yesterday
0 5
0
5
abhi
Hello Team,I am configuring Splunk, but the UF (Universal Forwarder) details are not reflecting in the Deployment Ser...
by abhi Observer in Deployment Architecture yesterday
0 3
0
3
Na_Kang_Lim
I have this kind of weird custom app (and dangerous too) that changes the UF Instance GUID.  Basically, I created a ....
by Na_Kang_Lim Explorer in Getting Data In Tuesday
0 1
0
1
Kieffer87
I'm running into a strange issue where Splunk is using the current time for a HTTP Event Collector input rather than ...
by Kieffer87 Communicator in Getting Data In Tuesday
1 10
1
10
KeithH
Hi All,Help please.Can I get people to agree with me that the following is a bug/design flaw - as my splunk case is g...
by KeithH Path Finder in Getting Data In Tuesday
0 5
0
5
msatish
I think Splunk doesn't have a built-in/defined sourcetype for ExtremeCloud XIQ logs. Can we define a custom sourcetyp...
by msatish Explorer in Getting Data In Tuesday
0 4
0
4
Anam
Hello Splunk Community! Welcome to the first post of the Splunk Answers Content Calendar  This week, I'll be spotlig...
by Community Manager Community Manager in Getting Data In Tuesday
2 0
2
0
tawfiq15
2025-05-06T13:50:00.857Z error helper/transformer.go:118 Failed to process entry {"otelcol.component.id": "filelog", ...
by tawfiq15 New Member in Getting Data In Tuesday
0 1
0
1
uagraw01
Hi Splunkers!!,We have recently configured SSO in Splunk using Keycloak, and it's working fine — users are able to lo...
by uagraw01 Motivator in Getting Data In Tuesday
0 1
0
1
Nicolas2203
Hi splunk community, I have a question on logs cloning/redirectionPurpose :Extract logs containing "network-guest", a...
by Nicolas2203 Path Finder in Getting Data In Tuesday
0 19
0
19
Waitomo
I'm trying to download Splunk using "wget -O splunk-9.4.2-e9664af3d956.x86_64.rpm "https://download.splunk.com/produc...
by Waitomo Engager in Installation Monday
0 3
0
3
hrawat
See SPL-248479 in release notes.If you are using persistent queue and see following errors in splunkd.log.  ERROR Tcp...
by hrawat Splunk Employee Splunk Employee in Knowledge Management Monday
5 8
5
8
ws
Hi,After setting up a test index and ingesting a test record, I’m now planning to remove the index from the distribut...
by ws Path Finder in Getting Data In Monday
0 3
0
3
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security and Observability Editions are held every month.

How digitally resilient are you? Take a quick Digital Resilience Assessment to find out if you're prepared for disruption!
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...
Top Karma Authors