Splunk

monitoring Splunk

Splunk monitoring and analytics

About this crawler

Splunk is a web crawler identified by the regular-expression pattern Splunk in the User-Agent request header. It is categorised as monitoring. Use the regex above to detect, log, allow, or block Splunk traffic in your web server, CDN edge rules, or robots.txt.

Block-rate · top 25k sites

No block-rate data for this crawler.

Technical details

Name
Splunk
Pattern
Splunk
Tags
monitoring
Reference
https://knownagents.com/agents/splunk
Added
2026/04/26
rDNS suffixes
.splunk.com, .splunkcloud.com
Instances
1 known sample(s)

rDNS verification (FCrDNS)

Verify a request is genuinely Splunk with forward-confirmed reverse DNS: the client IP's PTR record must end in one of the suffixes below and a forward A/AAAA lookup of that hostname must return the same IP. UA strings alone are spoofable; FCrDNS is not.

Sample User-Agent strings

Mozilla/5.0 (compatible; Splunk/1.0.0; https://splunk.com)

Block this crawler

robots.txt — disallow Splunk:

User-agent: Splunk Disallow: /

Apache .htaccess — return 403:

RewriteEngine On RewriteCond %{HTTP_USER_AGENT} Splunk [NC] RewriteRule .* - [F,L]

Nginx — return 403 inside a server block:

if ($http_user_agent ~* "Splunk") { return 403; }
← back to all crawlers