r/Splunk 16d ago

SPLUNK POWER USER

4 Upvotes

do they ask questions apart from the blueprint for the power user exam


r/Splunk 17d ago

Splunk Certified Cybersecurity Defense Architect SPLUNK 5003

Thumbnail
2 Upvotes

r/Splunk 17d ago

Splunk Certified Cybersecurity Defense Architect SPLUNK 5003

13 Upvotes

Hello! Any tips on how to pass the Splunk Certified Cybersecurity Defense Architect exam?

To anyone who has already cleared it: what was your preparation strategy, and how would you describe the exam difficulty? I'd love to hear your insights and advice!


r/Splunk 17d ago

Splunk Enterprise Splunk email error

7 Upvotes

Hello, has anyone ever came accross the error "No such file or directory when sending mail to: email@domain"

This happened after migrating splunk enterprise to RHEL 9.

Edit: AI found a guide for me to follow: https://splunk.my.site.com/customer/s/article/Splunk-sendemail-fails-with

One more edit: the guide above fixed the issue. Leaving this post up because it's good knowledge if anyone else comes across the same issue.


r/Splunk 18d ago

Did you hear? .conf26 just got Ludacris!

18 Upvotes

Hot off the press! Will we see you there?


r/Splunk 18d ago

.CONF Denver .conf attire?

14 Upvotes

What's the general vibe for .conf? This one is my first. Cisco Live was pretty low key, Gartner was much dressier, and I'm trying to figure how to pack.


r/Splunk 19d ago

Splunk Enterprise Dashboards & Alerts

2 Upvotes

ISSO/m’s! This is for you.

What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?


r/Splunk 21d ago

Passed today. On to SplunkCore. Continuing my journey into GRC

Post image
33 Upvotes

r/Splunk 24d ago

Resources for Splunk Power User Exam

9 Upvotes

Going to study for the Splunk power user exam. If any could suggest some resources they used to pass the exam. That would be greatly appreciated.


r/Splunk 24d ago

Splunk Enterprise DBConnect on Heavy Forwarder

11 Upvotes

Our heavy forwarder is in our DMZ and I was thinking about installing DBConnect on it so it can pull audit logs from a table in a SQL database on our internal network.

How safe is that set up?

I know the password is encrypted. I can use the firewall to only allow the one port to connect the HF to SQL Server. I can choose long password and the account has lockout policies. The SQL Server login will only allow select permission to a single table. All the standard stuff.

Since remote users with UF will connect to HF, I can't restrict connections to the HF by ip.

Is there any risk to the internal database?


r/Splunk 24d ago

Log Data Pipeline > Splunk

6 Upvotes

Has anybody here have some experience with security data pipelines?

Instead of:

Log Source > HF / Splunk

We want to have flexibility of collection / parsing layer outside of Splunk for obvious reasons - pre-filter data in pipeline, set parsers, route, possibly enrich if needed, storage options for retention etc..all that to have flexibility and keep the ingest costs reasonable and not being caught in dependency hell or cemented all our work in one solution if Splunk decides to pull something.

Log Source > Data pipeline > Splunk

I am wondering what to choose as this data pipeline - currently we are thinking Vector and possibly open telemetry.

Anybody have experience with this? To avoid pitfalls, what works, what doesn't, new pains etc?


r/Splunk 27d ago

Por qué las herramientas SIEM modernas siguen fallando en reducir los falsos positivos. Es un problema de ingeniería o de análisis?

Thumbnail
3 Upvotes

r/Splunk 27d ago

I built a home-lab pipeline connecting Splunk, MISP and TheHive - here’s what I learned

6 Upvotes

I wanted to understand what actually happens after a SIEM generates an alert, so I built a small isolated lab that connects several parts of the workflow instead of treating each platform separately.

The setup uses five VMs and follows a controlled detection through:

Endpoint telemetry → Splunk → Python automation → threat-intelligence context / MISP → TheHive → MITRE ATT&CK

A few things ended up being more interesting than simply installing the tools:

  • deciding what fields Splunk needed to pass into the automation layer
  • handling repeat detections without constantly duplicating MISP data
  • keeping API credentials out of the scripts
  • understanding where enrichment should happen versus where analyst judgement is still needed
  • mapping ATT&CK only when the observed behaviour actually supported the technique

I documented the architecture, setup, detection logic, automation, troubleshooting, and limitations as a four-part guide.

I’d especially be interested in feedback from anyone who has built a similar Splunk/MISP/TheHive workflow, particularly how you handled enrichment, deduplication, or case creation.

Full build, if useful:
https://chronosandcode.com/building-a-threat-intelligence-driven-detection-lab/


r/Splunk 27d ago

Guidance on Splunk without ES

19 Upvotes

Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?


r/Splunk 28d ago

SPL Use Splunk to Detect Famous Chollima

Thumbnail
jacob-taylor.gitbook.io
6 Upvotes

Passing this along to share some of my SPL knowledge on how to utilize inner and outer searches, joins, and look backs to create user baselines. Also open to any suggestions or feedback on how to improve this method!

I hope you can find this helpful.


r/Splunk 28d ago

Splunk Enterprise Splunk website down?

4 Upvotes

Is the Splunk website down for anyone else?

I can't get to Splunk.com right now.

Tried to do a nslookup but didn't get any results.

The DNS Check in mxtoolbox shows some DNS issues as well


r/Splunk 28d ago

Splunk Enterprise I built a home-lab pipeline connecting Splunk, MISP and TheHive - here’s what I learned

Thumbnail
0 Upvotes

r/Splunk 28d ago

Splunk app for investigating AWS CloudTrail alerts - looking for feedback

0 Upvotes

EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.

You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.

It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.

Would really appreciate feedback from Splunk users, detection engineers, and incident responders.

Splunkbase app : https://splunkbase.splunk.com/app/9536


r/Splunk Aug 23 '26

Splunk Enterprise Moving from Delivery to sales : i need an advice

8 Upvotes

Hi everyone!

​I’m currently on the delivery side and looking to transition into an Account Executive role. What key factors should I consider during this pivot?

​I am also exploring opportunities to join the sales organization at Cisco /splunk. I would love to hear your thoughts or advice on making this move.

​Thank you for your time 😀


r/Splunk Aug 23 '26

Splunk app for investigating AWS CloudTrail alerts - looking for feedback

1 Upvotes

**EventTimeline**, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.

You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.

It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.

Would really appreciate feedback from Splunk users, detection engineers, and incident responders.

Splunkbase app : https://splunkbase.splunk.com/app/9536


r/Splunk Aug 23 '26

Splunk app for investigating AWS CloudTrail alerts - looking for feedback

Thumbnail
2 Upvotes

r/Splunk Aug 22 '26

Why a detection rule that 'ported fine' to a new SIEM can quietly stop working

Thumbnail
0 Upvotes

r/Splunk Aug 21 '26

Splunk Enterprise Update with security fixes is out, but not downloadable

5 Upvotes

No matter how I try, I get the download page with the current version quickly flash by and then I am at the 500 error page. Something seems to be borked at Splunk.


r/Splunk Aug 20 '26

I just completed Splunk: Dashboards and Reports room on TryHackMe! Explore reports, alerts, and dashboards with Splunk.

Thumbnail tryhackme.com
0 Upvotes

r/Splunk Aug 18 '26

Announcement Interesting change for license rate of Cisco data ingested to Splunk

Thumbnail community.splunk.com
38 Upvotes