Hemant Seth's Blog Posts

Hemant is a Principal Product Manager at Splunk, leading the Kubernetes Monitoring offering within Splunk Observability Cloud. Prior to this role, he focused on Splunk Observability Platform administration, including identity management and license usage. Hemant brings over a decade of experience in the observability domain and holds a Master’s degree in Electrical Engineering with a specialization in Telecommunications.

Managing your Ingestion with the search bar
Tips & Tricks
1 Minute Read

Managing your Ingestion with the search bar

Custom searches for drilling down into data in your Splunk Cloud service; Total Ingestion Volume search over time, usage, volume by sourcetype & forwarder.
I can’t make my time range picker pick my time field.
Tips & Tricks
3 Minute Read

I can’t make my time range picker pick my time field.

Hadoop, Hunk or Splunk users have a choice in time field settings, can pull data from csv files, use specific searches & filters to achieve usable data subsets.
Configuring Microsoft’s Active Directory Federation Services (ADFS) Security Assertion Markup Language (SAML) Single Sign On (SSO) with Splunk Cloud
Tips & Tricks
12 Minute Read

Configuring Microsoft’s Active Directory Federation Services (ADFS) Security Assertion Markup Language (SAML) Single Sign On (SSO) with Splunk Cloud

Assisting customers with pre-req & integration steps for setting up ADFS-Active Directory Federation Services-SAML for Single Sign On with Splunk Cloud.
How to Create a Modular Alert
Tips & Tricks
10 Minute Read

How to Create a Modular Alert

Splunk 6.3 users can use API to write modular alerts for apps-notifications, automation, info-gathering. See apps.splunk.com & the official docs for more info.
Handling HTTP Event Collector (HEC) Content-Length too large errors without pulling your hair out
Tips & Tricks
1 Minute Read

Handling HTTP Event Collector (HEC) Content-Length too large errors without pulling your hair out

Answer for dealing with HTTP Event Collector (HEC) error message 413 content too large: reset configurable pre-defined limit for max content using limits.conf.
Secure Splunk Web in Five Minutes Using Let’s Encrypt
Tips & Tricks
2 Minute Read

Secure Splunk Web in Five Minutes Using Let’s Encrypt