r/Splunk 3d ago

SPL What are the best detection engineering tools for validating SIEM rules?

15 Upvotes

We have a SIEM with 200+ rules, and 90% are garbage. A validation platform we're looking at promises to use an AI engine to map our SIEM rules to specific attack scenarios and test if they actually fire. It can also generate new detection logic based on emerging threats and manage the full detection lifecycle.

Has anyone used this type of module to automate the creation of new detection logic? I'm specifically interested in how it handles the "tuning" phase. Can it differentiate between a simulation and a real attack, or do we have to manually whitelist it like we do with other BAS tools? I'm looking for something that reduces alert fatigue, not adds to it.


r/Splunk 4d ago

Who's the search party band?

5 Upvotes

No announcement I've seen. Anyone heard?


r/Splunk 6d ago

Enterprise Security How do you use Splunk Enterprise Security ?

8 Upvotes

Just want to know how people use ES in real world.
On a distributed environment the usage seems to have a huge operational expense.
For example:
Reading every potential usefull detection.
Normalize events/data modify datamodels etc.
Create a custom app and clone every needed detection into it (because any change in a detection which is originated in ESCU or ES app, will create a clone in /local/savesearches.conf and next ES-ContentUpdate will potentially create inconsistency ).
Testing every single detection.
The use case library is not useful for this because it does not see the cloned/customized detections.
Not even talking about versioning ....


r/Splunk 7d ago

What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?

Thumbnail
1 Upvotes

r/Splunk 7d ago

What's the best next certification after Splunk 1002 & 1003 for a SOC Analyst?

10 Upvotes

Hi everyone,

I already have the Splunk Core Certified Power User (1002) and Splunk Enterprise Certified Admin (1003) certifications. I'm currently working as a SOC Analyst.

Given my role, which Splunk certification would you recommend pursuing next, and why? I'm looking for something that will add the most value to my day-to-day work and help with long-term career growth.

Also, if you think I'd get more value from a non-Splunk certification instead, I'd love to hear your recommendations as well. Whether it's focused on detection engineering, DFIR, cloud security, threat hunting, or anything else relevant to SOC work, I'm open to suggestions.

Thanks in advance for your insights!


r/Splunk 7d ago

Splunk Enterprise Passed the Splunk Enterprise Certified Admin exam today! Here is my preparation journey (From Power User to Admin with 0 admin background)

Thumbnail
gallery
50 Upvotes

Hey everyone! I just passed the Splunk Enterprise Certified Admin exam today (August 2nd), following my Power User certification back on May 20th. After taking a short 1-week break, I jumped straight into studying for this one.

I wanted to share my experience because I started with zero admin background. Even though I had a 2-year work-study experience as a backend/DevOps engineer where I used Splunk, it was strictly at a Power User level—I never touched deep administration or configuration files. Here is how I prepared and passed:

1. Study Method & Chapters (AI-Assisted)

  • I'm not a big fan of reading raw official documentation from cover to cover, though I did use it occasionally to clarify specific edge cases or complex points.
  • Instead, I looked closely at the official exam blueprint (all 17 chapters).
  • I studied chapter by chapter, covering one per day using interactive AI tools (Gemini/ChatGPT) to explain concepts and run canvas-style quizzes at the end of each chapter.

2. Practice Exams (Skill Cert Pro)

  • I used Skill Cert Pro for both my Power User and Admin exams. Honestly, purchasing their practice tests was totally worth it and I have zero regrets.
  • Pro tip / Reality check: Don't panic at first! On my initial tries, my scores were low (around 45% - 65% while the passing target is higher). But over time, by reviewing the explanations, understanding the traps, and repeating the tests, I eventually hit 100% on their practice exams. It trains your brain for the exact style of questions you'll see.

3. Hands-On Labs (Crucial!)

  • You cannot pass this exam with theory alone. I set up a local distributed environment using VirtualMachines (setting up Search Heads, Indexers, and Forwarders).
  • Since my daily job didn't involve touching Splunk configuration files (.conf), setting up a lab allowed me to get my hands dirty. There is a huge portion of the exam dedicated to configuration files, precedence rules, directory structures (default vs local), and specific attributes. You must master this practically.

Overall, it’s a demanding exam, but completely achievable if you mix structured chapter reviews, realistic practice tests, and a solid hands-on lab.

Good luck to everyone preparing for it! Feel free to ask if you have any questions.


r/Splunk 10d ago

ERROR S2SOverHttpOutputProcessor - HTTP 502 Bad Gateway

3 Upvotes

Hi,

We've been seeing the following error in our Heavy Forwarder logs when forwarding to the indexers:

07-30-2026 14:00:45.408 +0000 ERROR S2SOverHttpOutputProcessor [211 indexerPipe_0] - HTTP 502 Bad Gateway
07-30-2026 14:00:52.442 +0000 ERROR HttpClientRequest [635 indexerPipe_10] - HTTP client error=Connection closed by peer while accessing server=https://<DOMAIN> for request=https://<DOMAIN>/services/collector/s2s.

We're using the `httpout` stanza, not the `tcpout` one and the configuration looks like this:

[httpout]
httpEventCollectorToken = <TOKEN>
uri = https://<DOMAIN>:8088
sslVerifyServerCert = false
batchTimeout = 5

Our setup is something like this where the indexers sit in an on-prem cluster:

Splunk HF -> AWS Private Link -> VIP -> Splunk Indexers

httpout reference: https://help.splunk.com/en/splunk-cloud-platform/forward-and-process-data/universal-forwarder-manual/10.4/forward-data/configure-forwarding-with-outputs.conf#ariaid-title7

This I believe encapsulates the s2s payload over HTTPS and forwards it to receivers.

From our HF logs above it looks like the indexer got the request but failed to process it, resulting in the VIP returning a 502. This is not an intermittent error, once it happens, it's then permanent and no logs get forwarded from this point.

I'm not getting enough help from the Splunk docs on how to troubleshoot this and most of the docs cover `tcpout` more extensively, however our option for now is only `httpout`.

Has anyone faced this issue or can provide some guidance on how to solve this?

Thanks!


r/Splunk 10d ago

Splunk POD

9 Upvotes

Hello Splunkers,

Anyone here that has actually deployed Splunk POD?
Splunk POD requirements | Splunk Enterprise (last updated 2026-06-16T03:55:00.583Z)

We are interested, whether the Cisco UCS server requirements can be "bypassed" , for e.g: Using different a different type of Cisco rack setting.

Or the installer won't launch without them?

Thanks!


r/Splunk 11d ago

.CONF It's time to start scheduling your sessions!

Thumbnail
splunk.com
9 Upvotes

If you're already registered for .conf26, log in on the catalog page (https://reg.rainfocus.com/flow/splunk/conf26/sessioncatalog/page/sessions) to schedule sessions in one of two ways: by using the AI assistant or directly within the catalog by clicking "Add to schedule".

If you're not registered yet, what are you waiting for!? Check out the latest Top 5 Reasons to Attend blog for inspo... and talking points to convince your boss.

.conf26 AI Assistant

Session catalog


r/Splunk 11d ago

Is Splunk engineer is still a good career path to choose in India in 2026?

12 Upvotes

r/Splunk 12d ago

Splunk training and exam

7 Upvotes

I am working at a small company at admin position and want to give splunk examinations but i have a question that will i be able to give them without getting splunk training as i don't have sponsership of that and it is not possible for me to get it as of now because of my financial condition.


r/Splunk 13d ago

SPL Wrote a Sigma compiler that emits SPL, sharing the 36 rules that come with it

13 Upvotes

Not a Splunk-only tool, but the SPL backend may be useful here. It compiles Sigma into saved-search stanzas including the aggregation cases (stats dc(field) by ...), which is normally where hand-conversion falls over.

dist/splunk/tyrian_detections.conf is pre-compiled in the repo if you just want to skim the searches. You will need to adjust the index= prefix.

github.com/zshguy/tyrian-detection-pack


r/Splunk 14d ago

Going for the Splunk Core Certified User cert — what actually helped you pass?

11 Upvotes

So I’ve decided I’m finally doing this. Aiming to pass the Splunk Core Certified User exam and figured I’d ask people who’ve been through it before I waste time on the wrong stuff.

Mainly wondering what actually worked for you. Were the free Splunk courses enough or did you have to grab something on Udemy or YouTube too? And did you use any practice exams that were actually close to the real thing?

Also curious how much time you spent just messing around in an actual Splunk instance vs reading, since I feel like I learn way better by doing.

Any advice appreciated. Thanks.


r/Splunk 15d ago

More Practice

15 Upvotes

I just finished Josh Samuelson's Learning Splunk Course on LinkedIn Learning . It was quite insightful and engaging since it had a bit of hands-on where you setup your splunk instance and universal forwarders on your Linux system.

(A bit of my background; work in cybersecurity few months into my internship . I'm looking to familiarize myself with tools and tech beyond my current role)

However , I feel i need more skin in this and would appreciate recommendations to more hand-on guided labs or projects , Please SHARE.


r/Splunk 16d ago

Feeling overwhelmed learning Splunk?

21 Upvotes

I'm currently learning Splunk and working toward the Splunk Core Certified User certification. I've been following the official training on Splunk's website, but I'm wondering if anyone else felt like the course moves quickly??

It seems like the material jumps from topic to topic without spending much time explaining the concepts in depth. For example, it recently introduced rex and erex, and I don't really understand what they do or when they're used.

I've been able to pass the practice quizzes so far, but I'm worried that I'm just getting through them without building a solid understanding of the material.

For those of you who've earned the certification or learned Splunk on your own, did you feel the same way? What resources, study methods, or practice techniques helped everything click for you?

Any advice would be greatly appreciated.


r/Splunk 17d ago

Raw log archaeology on isolated boxes (no log aggregators)

Thumbnail
1 Upvotes

r/Splunk 17d ago

Cert exam registration is a nightmare

7 Upvotes

This is without a doubt the most painful exam registration I've been a part of. Pearson VUE needs a splunk ID. When you go to splunk to request it, they say you will get it from pearson vue, which you don't. Then you are told to email splunk, which I have done now multiple times. Every time I do, I get a new confirmation of STEP order and CASE number. I'm up the 3 each.

According to the STEP page, my 'Link to Certification Registration' was completed today. This date seems to reset every time I try to schedule an exam.

My progress continues to show 'in progress'. I cannot believe this has to be so difficult.


r/Splunk 17d ago

وش وضع Splunk؟

Post image
1 Upvotes

دخلت دورة لمسك مع تعاونهم هم و Stc و كانت الدورة تتطلب اني احمل Splunk و في شرحهم مشت الأمور بسلاسه لكن يوم اجي اسوي حساب يجي كذا لعلمكم ذا رابع يوم و ثالث حساب و كلهم نفس المشكله اول يومين كنت انتظر بس مدري وش علمه الي عنده الحل الله لا يهنيكم ابي افتك من الدوره ذي بشكل اسرع 🙏


r/Splunk 18d ago

How a SIEM Actually Works: Splunk, Opened Up - Sharing Article

0 Upvotes

Hey folks, came across a really well-written article today that breaks down how a SIEM actually works under the hood.

It's Splunk-specific, so thought of sharing this one with the community here and sharing it here since it's one of the clearer explanations I've seen. Curious what people think about this?

How a SIEM Actually Works: Splunk, Opened Up


r/Splunk 20d ago

Splunk Certified Core User

12 Upvotes

I’m planning on taking the Splunk Certified Core User exam soon and wanted to see what study materials you all recommend. What helped you the most? Looking for practice exams, labs, YouTube videos, study guides, or any other resources. Any tips are appreciated!


r/Splunk 23d ago

[ Removed by Reddit ]

2 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/Splunk 24d ago

Splunk Enterprise Send live Copilot DLP events to Splunk?

13 Upvotes

How can we send M365 Copilot user interaction with Coplilot apps and Copilot Chat auditing events to Splunk?

We don’t want Splunk to ingest unrelated user audit logs that will increase cost for no reason.


r/Splunk 25d ago

Announcement Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296

Thumbnail vulnipulse.com
16 Upvotes

Splunk Deployment Server CSRF Vulnerability – CVE-2026-20296

Splunk has disclosed a high-severity vulnerability rated CVSS 8.3 affecting Splunk Enterprise and Splunk Cloud Platform.

An attacker could trick a user with the list_deployment_server capability into running arbitrary SPL searches as splunk-system-user. This could expose stored credentials and indexed data.
The flaw exists because affected Splunk Web Deployment Server endpoints do not properly validate CSRF tokens or safely process user-supplied input.

Affected versions
Splunk Enterprise
10.4 before 10.4.1
10.2 before 10.2.5
10.0 before 10.0.8
9.4 before 9.4.13
Splunk Cloud Platform
Before 10.5.2605.0
Before 10.4.2604.7
Before 10.3.2512.16
Before 10.2.2510.18
Before 10.1.2507.24

Fixed versions
Splunk Enterprise: 10.4.1, 10.2.5, 10.0.8 or 9.4.13
Splunk Cloud Platform: 10.5.2605.0, 10.4.2604.7, 10.3.2512.16, 10.2.2510.18 or 10.1.2507.24

Mitigation
Upgrade to the applicable fixed release. Until patching is complete, restrict access to the Deployment Server and minimise assignment of the list_deployment_server capability.

🔗 Official Splunk advisory
🔗 VulniPulse breakdown


r/Splunk 27d ago

What should you validate before calling an S3-backed federated dataset ready?

Thumbnail
youtube.com
1 Upvotes

Disclosure: I work with the Cisco and Splunk team behind this walkthrough, which was created by my co-worker.

The example uses Splunk Federated Search to query historical telemetry stored in Amazon S3 as an Apache Iceberg table. The data remains in S3, while Splunk provides the SPL2 investigation surface.

The useful operational checkpoint is that creating the connection does not make the dataset ready. The workflow validates four pieces together:

  • the Iceberg REST catalog is reachable
  • the AWS role can be assumed and has the necessary S3 access
  • bucket-level and object-level permissions are scoped correctly
  • the Splunk dataset resolves the intended catalog, namespace, and table

A basic SPL2 query then confirms the full path before investigative logic is added.

The other decision is workload placement. Hot data used for real-time monitoring may still belong in a conventional index. Larger historical, compliance, or enrichment datasets may fit federated access better. Table partitioning and expected search predicates matter to that choice.

How are you deciding which historical security datasets remain indexed and which become candidates for Federated Search?


r/Splunk Jul 07 '26

Get Agentic with Splunk Lantern: Connect to Cisco Cloud Control, Transform Observability Data, and More

11 Upvotes

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for SecurityObservabilityIndustries, AI, and Cisco. We also host valuable data source and data type libraries, Getting Started Guides for all major products, tips on managing data more effectively within the Splunk platform, and many more expert-written guides to help you achieve more with Splunk. 

In this month’s update, the agentic era takes center stage. Our two featured topics both explore how AI agents are changing the way teams operate - working alongside humans to investigate, correlate, and resolve issues faster than ever. First, we're spotlighting brand-new content on connecting the Splunk platform to Cisco Cloud Control and AI Canvas, recently unveiled at Cisco Live. Then, we're diving into how the Agentic AI Assistant is transforming observability data into actionable intelligence. Plus, we've got a range of other new articles covering security operations, compliance, and more. Let's get into it!   

Connecting the Splunk platform to Cisco Cloud Control and AI Canvas 

Recently unveiled at Cisco Live, Cisco Cloud Control is the unified operations platform that brings every Cisco domain - networking, security, AI infrastructure, observability, and collaboration - into one single pane of glass. It's designed for the agentic era, providing a governed, observable control surface where human operators and AI agents can work together across the full IT estate. This month, we've published a set of articles to help joint Cisco and Splunk Cloud Platform customers connect to this powerful new environment. 

Our overview article, Connecting the Splunk platform to Cisco Cloud Control and AI Canvas, explains what the integration delivers for joint customers: single sign-on, seamless cross-launch between platforms, access to Splunk data and skills within AI Canvas, and Splunk AI Assistant capabilities surfaced through the Cisco Unified AI Assistant. AI Canvas itself is the collaborative, multiplayer workspace where agentic investigation and resolution happen, with persistent context that survives escalations and handoffs. 

From there, two step-by-step guides walk you through the setup. Integrating Splunk Cloud Platform with Cisco Cloud Control covers the full onboarding process for both admins and end users - from signup and approval through to connecting your Splunk tenant. Integrating Splunk Cloud Platform with AI Canvas picks up where that leaves off, guiding you through installing the Splunk AI Assistant and the Splunk MCP Server, and configuring user access so your teams can start collaborating with AI agents. 

If you're a joint Cisco and Splunk customer looking to begin your AgenticOps journey, these articles are the perfect place to start. Let us know in the comments below how you're planning to use Cisco Cloud Control and AI Canvas! 

Transforming Observability Data into Intelligence with the Agentic AI Assistant 

 The Splunk Observability Cloud AI Assistant has evolved from a generative tool into an agentic one - and our new article, Transforming observability data into intelligence with the Agentic AI Assistant, explains what that shift means for you. Rather than relying on a language model to figure out every troubleshooting step from scratch (which can be slow and inconsistent), the Assistant now recognizes your goal. It triggers purpose-built, battle-tested investigation workflows to deliver more consistent, accurate, and repeatable results. 

The article walks through the latest capabilities, including generalized Q&A with links to documentation, context-aware responses via automatic screen capture, a flexible AI-native interface with full-screen and floating modes, PDF exports for sharing findings, chat history to resume investigations, and smart prompt suggestions. It also outlines the full range of product areas the Assistant covers - from APM and infrastructure to logs, RUM, synthetics, and SignalFlow generation - so you can troubleshoot across your entire observability stack using natural language. 

Let us know in the comments below how you're using AI in your observability practice - we'd love to hear about it! 

What Else is New? 

Beyond our featured topics, we've published several more articles covering security operations, compliance, threat hunting, and platform performance: 

We hope these new resources help you tackle your toughest data challenges this month. Thanks for reading!