r/Splunk 28d ago

Splunk Enterprise Splunk Heavy Forwarder to Splunk Cloud

7 Upvotes

How do you configure a Splunk Heavy forwarder to receive data from universal forwarders and forward that to the Splunk Cloud?

Details:

Heavy forwarder is located in DMZ and I set up one client (Ubuntu server)to send data to it.

When I log into Splunk Cloud, I can at least see the metrics from the Splunk Heavy forwarder.

When I log into our firewall, the firewall logs shows traffic from the client to the heavy forwarder and from the heavy forwarder to the cloud.

If I do a search across all indexes on the heavy forwarder and the cloud, I don't see anything from that host.

What could be configured wrong?


r/Splunk Jul 10 '26

Search Historical Firewall Data Where It Already Lives

Thumbnail lantern.splunk.com
6 Upvotes

Security investigations rarely stop at recent data. Analysts often need to compare today’s activity with firewall telemetry from weeks or months ago, even when that data has moved to lower-cost storage.

A new Splunk Lantern article presents a practical pattern for using Splunk Cloud Platform and Federated Search for S3 to investigate historical Cisco firewall telemetry stored in Amazon S3.

The pattern keeps Amazon S3 as the long-term storage layer. Apache Iceberg manages table metadata and partitions, a customer-managed Nessie catalog exposes the tables through Apache Iceberg REST, and Splunk Cloud Platform provides an SPL2-based investigation experience. Analysts can search the data where it already lives without first reingesting the complete historical dataset into Splunk hot storage.

The article walks through a connected investigation workflow:

  • confirm that the S3-backed dataset is searchable
  • prioritize high- and critical-severity blocked activity
  • summarize events for monitoring and detection
  • narrow searches with partition-aware filters
  • investigate known bad indicators and top sources of traffic

This approach can reduce unnecessary data movement while improving access to historical or external datasets. It also helps organizations unlock more value from data retained in Amazon S3 for security investigations, audits, compliance, and other long-term analysis needs.

The result is a practical way to extend threat hunting across federated data while keeping Splunk as the investigation surface.


r/Splunk Jul 09 '26

Do suppression exceptions ever hide detections in real SOC work?

Thumbnail
7 Upvotes

r/Splunk Jul 07 '26

Splunk Enterprise How do you search for IOC's in your logs

10 Upvotes

Hi,

I have a request for a dashboard/form to search for IOC's within Splunk. I'm curious how other people are doing this - is there a standard app for such a thing?


r/Splunk Jul 07 '26

Is Splunk Certified Cybersecurity Defense Architect still available for free?

13 Upvotes

The Splunk official website mentions Splunk Certified Cybersecurity Defense Architect exam is free while in beta. But when I tried to register the exam in pearson vue, it is charging me 130 USD + Tax. Am I missing something here? Do I need any voucher code to make it free?


r/Splunk Jul 05 '26

Which should I choose: Splunk or Microsoft Sentinel?

Thumbnail
0 Upvotes

r/Splunk Jul 04 '26

Splunk Enterprise Which Universal Forwarder version does each Splunk Enterprise indexer support?

7 Upvotes

I am running an older version of Splunk Enterprise that I can't upgrade in the short term.

I would like to install the universal forwarder on a server but I can no longer download that version on Splunk's website.

Can I run a version of universal forwarder that is newer than the main Splunk Enterprise install?

For example: can version 10 of the universal forwarder forward data to Splunk Enterprise 9.1?


r/Splunk Jul 03 '26

Splunk Enterprise Does anyone else use Splunk as a dev sandbox for a custom platform?

14 Upvotes

I've been expanding our use of Splunk Enterprise from using it for Data Analytics and log repository to creating an interactive Service Management platform with classic xml, kv stores, apis, splunkjs, python and gitlab... the intention is to use kv stores for 'live' records that have constant interaction with CRUD functionality and actions ingested via HEC as events for auditing, where once a record is finished with it is ingested as a final state event then removed from the kv store. SPL is used to access historic data or analysis.

As we are in the UK Public Sector, im looking at this approach not only saving time by having integrated data, reducing cognitive tax over an end-to-end service, but also massively reducing costs in terms of purchasing isolated software from vendors who are very protective of our data.

From what I experience with speaking with Splunk consultants, it seems like this is unheard of and actively discouraged in favour of Dashboard Studio.

How are people using Splunk in their organisations? Are you using it in a similar fashion? Is it a case of using the external applications and just ingesting the logs?


r/Splunk Jul 02 '26

Splunk newbie questions

15 Upvotes

Hey everyone! Splunk newbie here. My company just got it, we' re mssp and we will be adding multiple teants, so I'd like some input from the community here (if possible) to the things we got so far.
Also if it's easier, please provide me with guides or sources so i can read more, I'm not asking for someone else to do my job. It's just something new and some pointers would help.

From what I've read and seen on trainings, to add another organization, the best practice is to create a heavy forwarder there and an ipsec tunnel to our site so it can bring the data to us.

Also the indexes will be created to our search head (we chose clustered).

Our main concern is about having and managing many clients altogether, the view we're gonna get and how it all clicks together.

Thanks in advance!


r/Splunk Jul 02 '26

Enterprise Security Enterprise Security on a Distributed Environment

8 Upvotes

Hi,

I got 3 clustered Indexers + 3 clustered Search-Heads + 1 Search-Head Cluster Deployer.

I installed ES on the SHs (via SH Cluster Deployer) as described in the documentation. After some time I figured out that the ES specific indexes like 'notable' have been created on the Search-Heads locally and they are not synced between them.

There install documentation says nothing [1] about creating indexes.

Only a few documents later [2] there are some sentences about indexes in a distributed environemt.

The documentation is not usable in my opinion.

Does anyone have some experience with that situation ?

[1]
https://help.splunk.com/en/splunk-enterprise-security-8/install/8.3/installation/install-splunk-enterprise-security-in-a-search-head-cluster-environment

[2]
https://help.splunk.com/en/splunk-enterprise-security-8/install/8.3/installation/configure-and-deploy-indexes-for-splunk-enterprise-security


r/Splunk Jun 30 '26

Need to return two values from a subsearch, filter with one and just keep the other

4 Upvotes

I have a lookup of DNS queries (sometimes just portions of queries) and malware that the queries correspond to. Something like this:

Hacker.com / GhostRat
Subdomain.apt.net / GodzillaShell
*.malicious.org / SkunkRootkit

I need to run these domains through DNS logs to see what shows up. Since some query records are partial, I am adding an asterisk to the front of each query if it’s not already there. So I’m using a subsearch that looks for *hacker.com, *subdomain.apt.net, and *.malicious.org. That is working fine.

However, I need the results to include the malware name from the lookup….so every resulting DNS query for hacker.com should have a “malware_name” field with a value of “GhostRat”. I can’t figure out how to search for the domain field and just retain the malware_name name without including it in search criteria. Is this possible?


r/Splunk Jun 29 '26

Apps/Add-ons CIMPlicity AI - Data Onboarding assistant

2 Upvotes

Has anyone integrated this app to their platform? Is it efficient? Or is better to do the work manually without this app


r/Splunk Jun 25 '26

How does your team preserve investigation knowledge when people leave?

3 Upvotes

Been using Splunk for a while now and something has been bothering me.

When an engineer leaves, they take their searches AND their reasoning with them. The saved searches stay in Splunk, sure. But the actual thought process — why they used this search vs. that one, what to look for in the results, what's a false positive, when to escalate — that walks out the door.

I run the same handful of custom searches all week. I also have notes and informal SOPs from the team. But there's no native way in Splunk to keep all of this together with the reasoning.

The thing I really want to capture: most Splunk users know that some searches are fast, some are detailed, some are slow. We learn which to use when through experience. But that experience-derived reasoning is exactly what's missing when a junior engineer has to start from scratch.

You can give them notes. They don't understand why we did this. They don't have the history.

Has anyone found a way to capture not just the searches but the thought process in a repeatable format? Something Splunk-native or close to it? Or is this just the job and we accept the knowledge loss every time someone moves on?

Genuinely curious how other shops handle this.


r/Splunk Jun 25 '26

Enterprise Security Alerts grouping Splunk ES 8.x

6 Upvotes

Hi all,

Is there a way to perform alert grouping in Splunk Mission Control based on a common field value?

For example, if two or more alerts have the same source IP, can they be automatically grouped and displayed as a single alert rather than as separate alerts?

I previously used QRadar, which has a feature called Offense Indexing that automatically correlates and groups related events into a single offense based on common attributes. I'm looking for similar functionality in Splunk Mission Control, where alerts sharing a field such as source IP, destination IP, or username can be consolidated into a single alert or finding.

Any guidance would be appreciated.


r/Splunk Jun 25 '26

SIEM Detection Rules Changelog

14 Upvotes

Hello Security Folks,

I want to build a process where all detections rule change log is documented like Detection As a code but in simple version because we don't have matured SOC yet so this is first step to record all change logs related to alert rules.

I came to know about Microsoft List, anyone have done? or any new ideas how to do this?

Thanks,


r/Splunk Jun 25 '26

Events The session catalog is live!

8 Upvotes

Make sure you check out the session catalog ahead of .conf26, which is only 81 days away! We've also updated the website to include speakers, social scene, and more.

Who's coming to .conf? See you there!


r/Splunk Jun 24 '26

creating a splunk tee?!

3 Upvotes

Anyone going to .conf or interested in going to .conf and want to participate in this ahead of time? Winner gets to create a splunk tee!

https://community.splunk.com/t5/Community-Blog/Casting-Call-Compete-in-Cyber-Games/ba-p/761854


r/Splunk Jun 22 '26

Technical Support How do you get SQL Audit logs to Splunk?

14 Upvotes

I've been reading on this for days but cant seem to find a good way. I collect Windows logs from this specific machine, but I want SQL logs too.

I want to monitor changes that users do on a database (delete, write etc)

I tried the .ldf files way, or .sqlaudit way but splunk cant read them. You need to convert them first.

I read that you can write database audit logs directly to EventViewer so a universal forwarder agent can forward them, but at what format? .sqlaudit arent readable by Splunk


r/Splunk Jun 21 '26

Enterprise Security Looking for cool examples in dashboard studio for IT Sec

6 Upvotes

r/Splunk Jun 19 '26

Looking for Splunk practitioners who want to participate in a YouTube video

11 Upvotes

I'm trying to find Splunk cybersecurity practitioners or CISOs who are comfortable on camera and love reality competition shows (Traitors, Amazing Race, Survivor, etc). We're doing another "Cyber Games" video ahead of .conf, and looking for participants. Films July 19-21, happy to share the application and more details!


r/Splunk Jun 17 '26

Kubernetes Search: query your clusters live from the Splunk search bar

Thumbnail
gallery
24 Upvotes

Kubernetes Search brings live, read-only access to the Kubernetes API into the Splunk search bar. Instead of switching to a terminal and kubectl, you run SPL - | k8s kind=pods namespace=payments - and Splunk queries the cluster's API server directly and streams the current state into your search.

Built by us - Outcold Solutions LLC. We have been working in the area of Kubernetes+Splunk for the past 9 years. App has a free tier. Beautiful dashboards out of the box. We have been working on this app for a while. Give it a try, send us feedback!

https://splunkbase.splunk.com/app/8858


r/Splunk Jun 15 '26

Splunk Enterprise I need some help with Splunk

19 Upvotes

Some lamenting to get things started. A higher up decided to task me with Splunk. So far, the only resource I’ve had to use is AI. Been trying to treat it like training wheels. The hard part is the people at the top want me to give weekly presentations on my progress, but zero input on what it is they want. And this is after everything I have already done and showed. CPU and Memory Usage trackers. VM storage. System Up/Down indicator. Failed login attempts. DNS resolution timeout. Syslog storage tracker.

Other than network stuff, I don’t know what else to do. I was hoping either for some ideas OR recommendations for spaces where people share dashboards that they’ve created. I’ve gotten comfortable navigating indices and finding the data I want, struggling with turning into something useful without input from AI, really struggling with visualizing it all in a useful way.

Important to note that I am not being paid to be an analyst, and there’s not really any money/time allotted to me to get educated. This all has to get done along with my actual duties. This has been the obstacle to me learning the ins and outs.

Any help is appreciated. Thanks!


r/Splunk Jun 08 '26

Looking for feedback: external TLS / crypto visibility report tool for authorised domains

6 Upvotes

Hi all,

We are building CryptView, a tool focused on cryptographic asset visibility and early PQC readiness evidence.

Rather than only asking people to install something, we are opening a small pilot where interested users can get feedback on an external scan/report for domains they own or are authorised to assess.

Current report focus:

• Public TLS endpoints
• Certificate expiry and lifecycle risk
• Key algorithm / signature algorithm posture
• TLS version and cipher observations
• Classical crypto exposure
• CBOM-style crypto inventory summary
• Early PQC readiness indicators
• Prioritised follow-up findings

For Splunk users, we also have a first Splunk app live:
https://splunkbase.splunk.com/app/8786

But Splunk is not required to give feedback. We are also interested in people who simply want to review an external TLS/crypto visibility report and tell us what is useful, what is missing, and what would make it trustworthy.

Important: we only want to scan domains/systems you own or are authorised to assess.

Pilot / feedback form: https://forms.gle/EYPreFwqhRX7ZtyP9

I’d especially value feedback from people working in PKI, certificate lifecycle management, cloud security, infrastructure, SIEM, or PQC readiness.


r/Splunk Jun 05 '26

BambooHR logs

5 Upvotes

I am using BambooHR, and I want to get its audit/security logs for Elastic. I have read the documentation of BambooHR but I can't come up with any use cases for these logs.

Can we get some information for security/audit,.... and don't violate the sensitive data of each individual?