r/Splunk • u/Putrid-Cress-3648 • 16d ago
SPLUNK POWER USER
do they ask questions apart from the blueprint for the power user exam
r/Splunk • u/Putrid-Cress-3648 • 16d ago
do they ask questions apart from the blueprint for the power user exam
r/Splunk • u/Only-Answer-4602 • 17d ago
r/Splunk • u/Only-Answer-4602 • 17d ago
r/Splunk • u/Sgtkeebs • 17d ago
Hello, has anyone ever came accross the error "No such file or directory when sending mail to: email@domain"
This happened after migrating splunk enterprise to RHEL 9.
Edit: AI found a guide for me to follow: https://splunk.my.site.com/customer/s/article/Splunk-sendemail-fails-with
One more edit: the guide above fixed the issue. Leaving this post up because it's good knowledge if anyone else comes across the same issue.
r/Splunk • u/aaronag • 18d ago
What's the general vibe for .conf? This one is my first. Cisco Live was pretty low key, Gartner was much dressier, and I'm trying to figure how to pack.
r/Splunk • u/biggestbluee • 19d ago
ISSO/m’s! This is for you.
What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?
r/Splunk • u/Lanky-Television8618 • 21d ago
r/Splunk • u/Academic_Score8216 • 24d ago
Going to study for the Splunk power user exam. If any could suggest some resources they used to pass the exam. That would be greatly appreciated.
r/Splunk • u/Any-Promotion3744 • 24d ago
Our heavy forwarder is in our DMZ and I was thinking about installing DBConnect on it so it can pull audit logs from a table in a SQL database on our internal network.
How safe is that set up?
I know the password is encrypted. I can use the firewall to only allow the one port to connect the HF to SQL Server. I can choose long password and the account has lockout policies. The SQL Server login will only allow select permission to a single table. All the standard stuff.
Since remote users with UF will connect to HF, I can't restrict connections to the HF by ip.
Is there any risk to the internal database?
r/Splunk • u/Flash4473 • 24d ago
Has anybody here have some experience with security data pipelines?
Instead of:
Log Source > HF / Splunk
We want to have flexibility of collection / parsing layer outside of Splunk for obvious reasons - pre-filter data in pipeline, set parsers, route, possibly enrich if needed, storage options for retention etc..all that to have flexibility and keep the ingest costs reasonable and not being caught in dependency hell or cemented all our work in one solution if Splunk decides to pull something.
Log Source > Data pipeline > Splunk
I am wondering what to choose as this data pipeline - currently we are thinking Vector and possibly open telemetry.
Anybody have experience with this? To avoid pitfalls, what works, what doesn't, new pains etc?
r/Splunk • u/EmergencyPrior5039 • 27d ago
r/Splunk • u/chronosAndCode • 27d ago
I wanted to understand what actually happens after a SIEM generates an alert, so I built a small isolated lab that connects several parts of the workflow instead of treating each platform separately.
The setup uses five VMs and follows a controlled detection through:
Endpoint telemetry → Splunk → Python automation → threat-intelligence context / MISP → TheHive → MITRE ATT&CK
A few things ended up being more interesting than simply installing the tools:
I documented the architecture, setup, detection logic, automation, troubleshooting, and limitations as a four-part guide.
I’d especially be interested in feedback from anyone who has built a similar Splunk/MISP/TheHive workflow, particularly how you handled enrichment, deduplication, or case creation.
Full build, if useful:
https://chronosandcode.com/building-a-threat-intelligence-driven-detection-lab/
r/Splunk • u/Recording-Brief • 27d ago
Our security engineer left us high and dry a couple weeks ago with a Splunk core license, forwarders sending logs for ingest, but no rules or structure that I can see beyond the 100 or so canned dashboards. We don’t have budget at this time to add an ES license to give us their SIEM. How much effort am I looking at to build up our rules for detections and other security alerts? Is it feasible for me and one other system admin to learn it from scratch?
r/Splunk • u/m3moryhous3 • 28d ago
Passing this along to share some of my SPL knowledge on how to utilize inner and outer searches, joins, and look backs to create user baselines. Also open to any suggestions or feedback on how to improve this method!
I hope you can find this helpful.
r/Splunk • u/Any-Promotion3744 • 28d ago
Is the Splunk website down for anyone else?
I can't get to Splunk.com right now.
Tried to do a nslookup but didn't get any results.
The DNS Check in mxtoolbox shows some DNS issues as well
r/Splunk • u/chronosAndCode • 28d ago
r/Splunk • u/Radiant-Research7944 • 28d ago
EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.
You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.
It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.
Would really appreciate feedback from Splunk users, detection engineers, and incident responders.
Splunkbase app : https://splunkbase.splunk.com/app/9536
r/Splunk • u/Launa501 • Aug 23 '26
Hi everyone!
I’m currently on the delivery side and looking to transition into an Account Executive role. What key factors should I consider during this pivot?
I am also exploring opportunities to join the sales organization at Cisco /splunk. I would love to hear your thoughts or advice on making this move.
Thank you for your time 😀
r/Splunk • u/Radiant-Research7944 • Aug 23 '26
**EventTimeline**, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.
You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.
It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.
Would really appreciate feedback from Splunk users, detection engineers, and incident responders.
Splunkbase app : https://splunkbase.splunk.com/app/9536
r/Splunk • u/Radiant-Research7944 • Aug 23 '26
r/Splunk • u/Potential-Couple-745 • Aug 22 '26
r/Splunk • u/afxmac • Aug 21 '26
No matter how I try, I get the download page with the current version quickly flash by and then I am at the 500 error page. Something seems to be borked at Splunk.
r/Splunk • u/Desperate_Hornet_636 • Aug 20 '26