
Splunk Enterprise RCE Exploited — CVE-2026-20253
CVE-2026-20253 Splunk RCE exploited in the wild with a Sunday CISA deadline. Accenture buys Dragos for $4.1B. FortiBleed hits 86K devices.
Posts tagged: Splunk

CVE-2026-20253 Splunk RCE exploited in the wild with a Sunday CISA deadline. Accenture buys Dragos for $4.1B. FortiBleed hits 86K devices.

Send Cisco ISE syslogs to Splunk — parse with props.conf, build SPL queries for RADIUS auth visibility, and create a live ISE operations dashboard.

Splunk SPLUNK_HOME directory layout, etc/system/default vs local precedence, conf-file merging, and essential splunk CLI commands for administrators.

Splunk Enterprise install on Linux and Windows: ulimit tuning, THP disable, indexer and search-head sizing, and production-ready admin class advice.

Splunk admin notes — search heads, indexers, forwarders, deployment server roles — and the planning steps required before a production install.

Splunk Certified Architect prep — System Admin class topics: license management, configuration files, indexers, user management, and distributed search.

Correlate events in Splunk using transactions — group related events with maxspan, maxpause, startswith, endswith — and when to use stats instead.

Filter and format Splunk data with eval, search, and where commands — calculate field values, apply conditional logic, and clean up report output.

Splunk Fundamentals 2 topics — transforming commands, transactions, knowledge objects, field aliases, tags, macros, data models, and the CIM.

Splunk knowledge objects explained — field extractions, event types, lookups, workflow actions, tags, and data models for sharing reusable assets.