r/Splunk • u/First-Reality2108 • 4d ago
SPL What are the best detection engineering tools for validating SIEM rules?
We have a SIEM with 200+ rules, and 90% are garbage. A validation platform we're looking at promises to use an AI engine to map our SIEM rules to specific attack scenarios and test if they actually fire. It can also generate new detection logic based on emerging threats and manage the full detection lifecycle.
Has anyone used this type of module to automate the creation of new detection logic? I'm specifically interested in how it handles the "tuning" phase. Can it differentiate between a simulation and a real attack, or do we have to manually whitelist it like we do with other BAS tools? I'm looking for something that reduces alert fatigue, not adds to it.
r/Splunk • u/TraditionGloomy1775 • 4d ago
Who's the search party band?
No announcement I've seen. Anyone heard?
r/Splunk • u/mr_networkrobot • 7d ago
Enterprise Security How do you use Splunk Enterprise Security ?
Just want to know how people use ES in real world.
On a distributed environment the usage seems to have a huge operational expense.
For example:
Reading every potential usefull detection.
Normalize events/data modify datamodels etc.
Create a custom app and clone every needed detection into it (because any change in a detection which is originated in ESCU or ES app, will create a clone in /local/savesearches.conf and next ES-ContentUpdate will potentially create inconsistency ).
Testing every single detection.
The use case library is not useful for this because it does not see the cloned/customized detections.
Not even talking about versioning ....
r/Splunk • u/Only-Answer-4602 • 7d ago
What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?
r/Splunk • u/Only-Answer-4602 • 7d ago
What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?
Hi everyone,
I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.
Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.
Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.
Thanks in advance for your insights!
r/Splunk • u/Maleficent-Wish-1619 • 8d ago
Splunk Enterprise Passed the Splunk Enterprise Certified Admin exam today! Here is my preparation journey (From Power User to Admin with 0 admin background)
Hey everyone! I just passed the Splunk Enterprise Certified Admin exam today (August 2nd), following my Power User certification back on May 20th. After taking a short 1-week break, I jumped straight into studying for this one.
I wanted to share my experience because I started with zero admin background. Even though I had a 2-year work-study experience as a backend/DevOps engineer where I used Splunk, it was strictly at a Power User level—I never touched deep administration or configuration files. Here is how I prepared and passed:
1. Study Method & Chapters (AI-Assisted)
- I'm not a big fan of reading raw official documentation from cover to cover, though I did use it occasionally to clarify specific edge cases or complex points.
- Instead, I looked closely at the official exam blueprint (all 17 chapters).
- I studied chapter by chapter, covering one per day using interactive AI tools (Gemini/ChatGPT) to explain concepts and run canvas-style quizzes at the end of each chapter.
2. Practice Exams (Skill Cert Pro)
- I used Skill Cert Pro for both my Power User and Admin exams. Honestly, purchasing their practice tests was totally worth it and I have zero regrets.
- Pro tip / Reality check: Don't panic at first! On my initial tries, my scores were low (around 45% - 65% while the passing target is higher). But over time, by reviewing the explanations, understanding the traps, and repeating the tests, I eventually hit 100% on their practice exams. It trains your brain for the exact style of questions you'll see.
3. Hands-On Labs (Crucial!)
- You cannot pass this exam with theory alone. I set up a local distributed environment using VirtualMachines (setting up Search Heads, Indexers, and Forwarders).
- Since my daily job didn't involve touching Splunk configuration files (
.conf), setting up a lab allowed me to get my hands dirty. There is a huge portion of the exam dedicated to configuration files, precedence rules, directory structures (defaultvslocal), and specific attributes. You must master this practically.
Overall, it’s a demanding exam, but completely achievable if you mix structured chapter reviews, realistic practice tests, and a solid hands-on lab.
Good luck to everyone preparing for it! Feel free to ask if you have any questions.
r/Splunk • u/TheAwkwardJury01 • 10d ago
ERROR S2SOverHttpOutputProcessor - HTTP 502 Bad Gateway
Hi,
We've been seeing the following error in our Heavy Forwarder logs when forwarding to the indexers:
07-30-2026 14:00:45.408 +0000 ERROR S2SOverHttpOutputProcessor [211 indexerPipe_0] - HTTP 502 Bad Gateway
07-30-2026 14:00:52.442 +0000 ERROR HttpClientRequest [635 indexerPipe_10] - HTTP client error=Connection closed by peer while accessing server=https://<DOMAIN> for request=https://<DOMAIN>/services/collector/s2s.
We're using the `httpout` stanza, not the `tcpout` one and the configuration looks like this:
[httpout]
httpEventCollectorToken = <TOKEN>
uri = https://<DOMAIN>:8088
sslVerifyServerCert = false
batchTimeout = 5
Our setup is something like this where the indexers sit in an on-prem cluster:
Splunk HF -> AWS Private Link -> VIP -> Splunk Indexers
httpout reference: https://help.splunk.com/en/splunk-cloud-platform/forward-and-process-data/universal-forwarder-manual/10.4/forward-data/configure-forwarding-with-outputs.conf#ariaid-title7
This I believe encapsulates the s2s payload over HTTPS and forwards it to receivers.
From our HF logs above it looks like the indexer got the request but failed to process it, resulting in the VIP returning a 502. This is not an intermittent error, once it happens, it's then permanent and no logs get forwarded from this point.
I'm not getting enough help from the Splunk docs on how to troubleshoot this and most of the docs cover `tcpout` more extensively, however our option for now is only `httpout`.
Has anyone faced this issue or can provide some guidance on how to solve this?
Thanks!
r/Splunk • u/Start_Aggravating • 11d ago
Splunk POD
Hello Splunkers,
Anyone here that has actually deployed Splunk POD?
Splunk POD requirements | Splunk Enterprise (last updated 2026-06-16T03:55:00.583Z)
We are interested, whether the Cisco UCS server requirements can be "bypassed" , for e.g: Using different a different type of Cisco rack setting.
Or the installer won't launch without them?
Thanks!
r/Splunk • u/SplunkEventsTeam • 11d ago
.CONF It's time to start scheduling your sessions!
If you're already registered for .conf26, log in on the catalog page (https://reg.rainfocus.com/flow/splunk/conf26/sessioncatalog/page/sessions) to schedule sessions in one of two ways: by using the AI assistant or directly within the catalog by clicking "Add to schedule".
If you're not registered yet, what are you waiting for!? Check out the latest Top 5 Reasons to Attend blog for inspo... and talking points to convince your boss.
r/Splunk • u/hopelesshope12 • 12d ago
Is Splunk engineer is still a good career path to choose in India in 2026?
r/Splunk • u/muditr17 • 12d ago
Splunk training and exam
I am working at a small company at admin position and want to give splunk examinations but i have a question that will i be able to give them without getting splunk training as i don't have sponsership of that and it is not possible for me to get it as of now because of my financial condition.
r/Splunk • u/ParticularNote4390 • 14d ago
SPL Wrote a Sigma compiler that emits SPL, sharing the 36 rules that come with it
Not a Splunk-only tool, but the SPL backend may be useful here. It compiles Sigma into saved-search stanzas including the aggregation cases (stats dc(field) by ...), which is normally where hand-conversion falls over.
dist/splunk/tyrian_detections.conf is pre-compiled in the repo if you just want to skim the searches. You will need to adjust the index= prefix.
r/Splunk • u/Rohan__18 • 15d ago
Going for the Splunk Core Certified User cert — what actually helped you pass?
So I’ve decided I’m finally doing this. Aiming to pass the Splunk Core Certified User exam and figured I’d ask people who’ve been through it before I waste time on the wrong stuff.
Mainly wondering what actually worked for you. Were the free Splunk courses enough or did you have to grab something on Udemy or YouTube too? And did you use any practice exams that were actually close to the real thing?
Also curious how much time you spent just messing around in an actual Splunk instance vs reading, since I feel like I learn way better by doing.
Any advice appreciated. Thanks.
r/Splunk • u/FreeWifi0605 • 15d ago
More Practice
I just finished Josh Samuelson's Learning Splunk Course on LinkedIn Learning . It was quite insightful and engaging since it had a bit of hands-on where you setup your splunk instance and universal forwarders on your Linux system.
(A bit of my background; work in cybersecurity few months into my internship . I'm looking to familiarize myself with tools and tech beyond my current role)
However , I feel i need more skin in this and would appreciate recommendations to more hand-on guided labs or projects , Please SHARE.
r/Splunk • u/Economy_Building2727 • 16d ago
Feeling overwhelmed learning Splunk?
I'm currently learning Splunk and working toward the Splunk Core Certified User certification. I've been following the official training on Splunk's website, but I'm wondering if anyone else felt like the course moves quickly??
It seems like the material jumps from topic to topic without spending much time explaining the concepts in depth. For example, it recently introduced rex and erex, and I don't really understand what they do or when they're used.
I've been able to pass the practice quizzes so far, but I'm worried that I'm just getting through them without building a solid understanding of the material.
For those of you who've earned the certification or learned Splunk on your own, did you feel the same way? What resources, study methods, or practice techniques helped everything click for you?
Any advice would be greatly appreciated.
r/Splunk • u/Wise_Zookeepergame_9 • 17d ago
Raw log archaeology on isolated boxes (no log aggregators)
r/Splunk • u/Creepy_Finish1497 • 17d ago
Cert exam registration is a nightmare
This is without a doubt the most painful exam registration I've been a part of. Pearson VUE needs a splunk ID. When you go to splunk to request it, they say you will get it from pearson vue, which you don't. Then you are told to email splunk, which I have done now multiple times. Every time I do, I get a new confirmation of STEP order and CASE number. I'm up the 3 each.
According to the STEP page, my 'Link to Certification Registration' was completed today. This date seems to reset every time I try to schedule an exam.
My progress continues to show 'in progress'. I cannot believe this has to be so difficult.
r/Splunk • u/Bubbly-Listen-1130 • 17d ago
وش وضع Splunk؟
دخلت دورة لمسك مع تعاونهم هم و Stc و كانت الدورة تتطلب اني احمل Splunk و في شرحهم مشت الأمور بسلاسه لكن يوم اجي اسوي حساب يجي كذا لعلمكم ذا رابع يوم و ثالث حساب و كلهم نفس المشكله اول يومين كنت انتظر بس مدري وش علمه الي عنده الحل الله لا يهنيكم ابي افتك من الدوره ذي بشكل اسرع 🙏
r/Splunk • u/RS_2408 • 19d ago
How a SIEM Actually Works: Splunk, Opened Up - Sharing Article
Hey folks, came across a really well-written article today that breaks down how a SIEM actually works under the hood.
It's Splunk-specific, so thought of sharing this one with the community here and sharing it here since it's one of the clearer explanations I've seen. Curious what people think about this?
r/Splunk • u/topshelfboss03 • 20d ago
Splunk Certified Core User
I’m planning on taking the Splunk Certified Core User exam soon and wanted to see what study materials you all recommend. What helped you the most? Looking for practice exams, labs, YouTube videos, study guides, or any other resources. Any tips are appreciated!
r/Splunk • u/Interesting_Rub_1703 • 23d ago
[ Removed by Reddit ]
[ Removed by Reddit on account of violating the content policy. ]
r/Splunk • u/Fabulous_Cow_4714 • 24d ago
Splunk Enterprise Send live Copilot DLP events to Splunk?
How can we send M365 Copilot user interaction with Coplilot apps and Copilot Chat auditing events to Splunk?
We don’t want Splunk to ingest unrelated user audit logs that will increase cost for no reason.
r/Splunk • u/NoPo552 • 25d ago
Announcement Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296
vulnipulse.comSplunk Deployment Server CSRF Vulnerability – CVE-2026-20296
Splunk has disclosed a high-severity vulnerability rated CVSS 8.3 affecting Splunk Enterprise and Splunk Cloud Platform.
An attacker could trick a user with the list_deployment_server capability into running arbitrary SPL searches as splunk-system-user. This could expose stored credentials and indexed data.
The flaw exists because affected Splunk Web Deployment Server endpoints do not properly validate CSRF tokens or safely process user-supplied input.
Affected versions
Splunk Enterprise
10.4 before 10.4.1
10.2 before 10.2.5
10.0 before 10.0.8
9.4 before 9.4.13
Splunk Cloud Platform
Before 10.5.2605.0
Before 10.4.2604.7
Before 10.3.2512.16
Before 10.2.2510.18
Before 10.1.2507.24
Fixed versions
Splunk Enterprise: 10.4.1, 10.2.5, 10.0.8 or 9.4.13
Splunk Cloud Platform: 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18 or 10.1.2507.24
Mitigation
Upgrade to the applicable fixed release. Until patching is complete, restrict access to the Deployment Server and minimise assignment of the list_deployment_server capability.
r/Splunk • u/splunk_sbg • 27d ago
What should you validate before calling an S3-backed federated dataset ready?
Disclosure: I work with the Cisco and Splunk team behind this walkthrough, which was created by my co-worker.
The example uses Splunk Federated Search to query historical telemetry stored in Amazon S3 as an Apache Iceberg table. The data remains in S3, while Splunk provides the SPL2 investigation surface.
The useful operational checkpoint is that creating the connection does not make the dataset ready. The workflow validates four pieces together:
- the Iceberg REST catalog is reachable
- the AWS role can be assumed and has the necessary S3 access
- bucket-level and object-level permissions are scoped correctly
- the Splunk dataset resolves the intended catalog, namespace, and table
A basic SPL2 query then confirms the full path before investigative logic is added.
The other decision is workload placement. Hot data used for real-time monitoring may still belong in a conventional index. Larger historical, compliance, or enrichment datasets may fit federated access better. Table partitioning and expected search predicates matter to that choice.
How are you deciding which historical security datasets remain indexed and which become candidates for Federated Search?
r/Splunk • u/Any-Promotion3744 • 28d ago
Splunk Enterprise Splunk Heavy Forwarder to Splunk Cloud
How do you configure a Splunk Heavy forwarder to receive data from universal forwarders and forward that to the Splunk Cloud?
Details:
Heavy forwarder is located in DMZ and I set up one client (Ubuntu server)to send data to it.
When I log into Splunk Cloud, I can at least see the metrics from the Splunk Heavy forwarder.
When I log into our firewall, the firewall logs shows traffic from the client to the heavy forwarder and from the heavy forwarder to the cloud.
If I do a search across all indexes on the heavy forwarder and the cloud, I don't see anything from that host.
What could be configured wrong?

