Splunk Administration

Splunk Administration
Category Activity
johnfaldo3
I'm running universalforwarder as a service in docker, here is my docker-compose config:services:   services: splu...
by johnfaldo3 New Member in Getting Data In 56m ago
0 0
0
0
kymenope
My inputs.conf from the deployment server (confirmed that it is being pushed to all hosts correctly): {WinEventLog://...
by kymenope Explorer in Getting Data In yesterday
0 2
0
2
mikefg
I am working on migrating from Centos 7 to Ubuntu 22. Single search head, indexer cluster (3 indexers), and a deploym...
by mikefg Communicator in Installation yesterday
0 9
0
9
m_nouman
I want to search for an Account_Name that has the maximum number of login attempts within a span of 10 minutes with r...
by m_nouman New Member in Deployment Architecture yesterday
0 3
0
3
BRFZ
I have an architecture with a single SH and two indexers. I've installed the Splunk for Microsoft 365 add-on on the s...
by BRFZ Loves-to-Learn Lots in Deployment Architecture yesterday
0 7
0
7
pm2012
HI SMEs, I am having problem where logs coming from one of the syslog server are getting clubbed into one single raw ...
by pm2012 Explorer in Getting Data In yesterday
0 6
0
6
TheEggi98
Hi fellow Splunkers,i recently came across an authentication Token created by splunk-system-user and i had no clue wh...
by TheEggi98 Path Finder in Security yesterday
1 1
1
1
SampathkumarK
How to check if the host has been correctly whitelisted to receive configuration from Splunk Deployment Server?
by SampathkumarK Observer in Deployment Architecture Thursday
0 4
0
4
LearningGuy
Hello,I have a static data about 200,000 rows (potentially grow) needs to be moved to a summary index daily.1) Is it ...
by LearningGuy Builder in Monitoring Splunk Thursday
0 9
0
9
Uzumaki
Hello,first of all, sorry for my bad English, I hope you can understand everything.My goal is to get the journald log...
by Uzumaki Loves-to-Learn Everything in Getting Data In Thursday
0 4
0
4
pulen
I am really struggling to add my macos data into splunk just like how we can upload the event logs of windows. is the...
by pulen New Member in Monitoring Splunk Thursday
0 1
0
1
dersa
Hi, I am having troubles with providing the correct regex to extract the hostname from the file location. The file st...
by dersa Path Finder in Getting Data In Thursday
0 3
0
3
Trusty
HeloI have a search query like this: index=test dscip=192.168.1.1 OR dscip=192.168.1.2 ...I would like to search this...
by Trusty Engager in Getting Data In Thursday
0 2
0
2
matcher123
I have a sc4s deployment running in an ec2 instance. I followed the documentation provided here https://splunk.github...
by matcher123 Loves-to-Learn in Getting Data In Thursday
0 0
0
0
hishamjan
Hi,  I have a Linux machine running on Centos 6.10 with a quad-core processor  (16 threads) On Splunk, is there a way...
by hishamjan Explorer in Getting Data In Wednesday
0 4
0
4
SumitSharma
I am trying below blogs to use Splunk Cloud Trial version in SAP Cloud Integration.However, I am getting below error ...
by SumitSharma New Member in Getting Data In Wednesday
0 1
0
1
pp219
Hi,Our application uses log4j2 logging framework. We are trying to send log signals created by Otel Logs SDK to Splun...
by pp219 Observer in Getting Data In Wednesday
0 0
0
0
hrawat_splunk
splunkd.log is flooded by following log.WARN AutoLoadBalancedConnectionStrategy [xxxx TcpOutEloop] - Current dest hos...
by hrawat_splunk Splunk Employee Splunk Employee in Getting Data In Wednesday
0 11
0
11
elephant
I have changed my appserver/static/javascript directory and the setup page that reffers to it does not update.I tried...
by elephant Engager in Getting Data In Wednesday
0 0
0
0
pm2012
Hi SMEs,Hope you are doing great, i am curious to know how to check the daily data consumption (GB/Day) from a specif...
by pm2012 Explorer in Installation Wednesday
0 3
0
3
AndrewBurnett
When we go to look at the UI sometimes, it says the app is missing so the UI is unavailable. When it does let us look...
by AndrewBurnett Observer in Getting Data In Wednesday
0 0
0
0
russellrobertso
I'm struggling to get Exchange Universal Forwarders to connect to the central instance. This is the error in the spl...
by russellrobertso Engager in Getting Data In Wednesday
0 6
0
6
whitecat001
I made my configuration for inputs.conf to ingest data into splunk but not getting data, during my investigation to c...
by whitecat001 Explorer in Getting Data In Wednesday
0 1
0
1
manta0101
 I have created a search that contains a field that is unique. I am using this search to populate the index. however ...
by manta0101 Engager in Getting Data In Wednesday
0 2
0
2
mataharry
I have a Storm project and I want to clean all and reindex only the last days, and some specific files. I have Splunk...
by mataharry Communicator in Getting Data In Wednesday
12 14
12
14
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security and Observability Editions are held every month.

Where are you on your adoption journey? Take the quick Security or Observability Resilience Check quiz to find out!
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...
Top Karma Authors