Splunk Administration

Splunk Administration
Category Activity
Poojitha
Hi All,I am trying to extract a value from the indexed field. i.e from source field . I have added the regex in props...
by Poojitha Path Finder in Security 14m ago
0 0
0
0
stefani
I have the following environment: 1 HF -> 1 indexer -> 1 SH , code 9.1How do I onboard the AD controller data into my...
by stefani Engager in Security 32m ago
0 3
0
3
splunky_diamond
Hello Splunkers!Imagine a scenario:There is a test environment with Splunk being deployed in ubuntu-server 20.04 virt...
by splunky_diamond Engager in Getting Data In an hour ago
0 1
0
1
burakatabay
Hi, My problem is duplicated windows security logs. 2 or more log same as each other. why do that ? 03/18/2019 10:...
by burakatabay Path Finder in Getting Data In 3 hours ago
1 10
1
10
SahilGupta942
Hello,I need to upgrade the Splunk indexer version to version 9.2But, we have a few instances which have Splunk forwa...
by SahilGupta942 New Member in Deployment Architecture 3 hours ago
0 1
0
1
yh
Hello I am referring to the following documentation Route and filter data - Splunk Documentation I would like to disc...
by yh Explorer in Getting Data In 3 hours ago
0 16
0
16
SReopelle
Splunk version is 9.1.0.2We are trying to resolve searches that are orphaned from the report "Orphaned Scheduled Sear...
by SReopelle New Member in Security 4 hours ago
0 2
0
2
ArianeSantos
We have splunk installed and the collection was happening normally, but for a few days now the collection has stopped...
by ArianeSantos New Member in Getting Data In yesterday
0 2
0
2
fde
Hello,I've got a cluster with 2 peers, 1 seach head and 1 CM. All of them with a single network.Due to network change...
by fde Explorer in Deployment Architecture yesterday
0 2
0
2
whitecat001
pls whats the better way to create a search query for identifying knowledge object from inactive users and cleaning i...
by whitecat001 Explorer in Security yesterday
0 1
0
1
talosops
Has any one seen this issue while installing the splunk forwarder in the Freebsd 13.3 ? or any idea why we are gettin...
by talosops Loves-to-Learn in Installation yesterday
0 1
0
1
automagication
Whenever I package the splunk app, I get execute permission error because I have 744 permission for conf files but sp...
by automagication New Member in Deployment Architecture yesterday
0 6
0
6
jdhart1312
I have a PowerShell script that needs to be ran as admin to be able to load in all of the data. It returns a .csv fil...
by jdhart1312 Loves-to-Learn in Getting Data In yesterday
0 2
0
2
anandhalagaras1
Hi Team,Our Splunk Search heads are hosted in Cloud and managed by Support and currently we are running with the late...
by anandhalagaras1 Communicator in Security yesterday
0 1
0
1
mshakeb
We want to migrate cluster indexers data from default location that is from (opt/splunk/var/lib/splunk) to customize ...
by mshakeb Loves-to-Learn Lots in Getting Data In yesterday
0 3
0
3
Haleb
I need to connect data from a third party application via HEC to Splunk. It sends data in this format 1 event per req...
by Haleb Explorer in Getting Data In yesterday
0 1
0
1
Poojitha
Hi All,I have setup new deployment server and new heavy forwarder. There is successful phonehome connection when I ch...
by Poojitha Path Finder in Security yesterday
0 3
0
3
splunky_diamond
Hello Splunk community. I have been searching for this question quite a lot and went through many articles, but it’s ...
by splunky_diamond Engager in Getting Data In Wednesday
0 4
0
4
auzark
I have multiple Dashboards that I have cloned to make changes. What is the best method to rename the existing dashboa...
by auzark Communicator in Installation Wednesday
0 2
0
2
DaClyde
In previous versions of Splunk (at least up to 9.1.0), we could re-arrange the Apps menu by dragging the apps up or d...
by DaClyde Contributor in Knowledge Management Wednesday
0 5
0
5
devraajpandya11
How do i integrate my website hosted on AWS(ec2) with splunk?
by devraajpandya11 New Member in Getting Data In Wednesday
0 1
0
1
alemack
Hi folks,  our field parsing/extraction has broken across all sourcetypes (nginx, log4j, aws:elb's, fix,custom format...
by alemack Observer in Monitoring Splunk Wednesday
0 1
0
1
hrawat_splunk
splunkd.log is flooded by following log.WARN AutoLoadBalancedConnectionStrategy [xxxx TcpOutEloop] - Current dest hos...
by hrawat_splunk Splunk Employee Splunk Employee in Getting Data In Wednesday
0 13
0
13
hrawat_splunk
Heavy forwarder or indexer crashes with FATAL error on typing thread. Note: Issue is now fixed for next 9.2.2/9.1.5/9...
by hrawat_splunk Splunk Employee Splunk Employee in Knowledge Management Wednesday
2 7
2
7
Jarohnimo
Hello All, I have a solid understanding of the files/ how to deploy this application but my issue is with permission...
by Jarohnimo Builder in Security Wednesday
0 11
0
11
Splunk Learning

Splunk has training and education options for everyone, whether it's your first or fiftieth deployment.

Get Started

Announcements
Register for Upcoming Live Tech Talks! Security and Observability Editions are held every month.

Where are you on your adoption journey? Take the quick Security or Observability Resilience Check quiz to find out!
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...
Top Karma Authors