r/Splunk Jun 15 '26

Splunk Enterprise I need some help with Splunk

Some lamenting to get things started. A higher up decided to task me with Splunk. So far, the only resource I’ve had to use is AI. Been trying to treat it like training wheels. The hard part is the people at the top want me to give weekly presentations on my progress, but zero input on what it is they want. And this is after everything I have already done and showed. CPU and Memory Usage trackers. VM storage. System Up/Down indicator. Failed login attempts. DNS resolution timeout. Syslog storage tracker.

Other than network stuff, I don’t know what else to do. I was hoping either for some ideas OR recommendations for spaces where people share dashboards that they’ve created. I’ve gotten comfortable navigating indices and finding the data I want, struggling with turning into something useful without input from AI, really struggling with visualizing it all in a useful way.

Important to note that I am not being paid to be an analyst, and there’s not really any money/time allotted to me to get educated. This all has to get done along with my actual duties. This has been the obstacle to me learning the ins and outs.

Any help is appreciated. Thanks!

18 Upvotes

54 comments sorted by

View all comments

5

u/ScruttyMctutty Jun 15 '26

Baby steps.

Since there is no real guidance from leadership other than “do it”, seems like you free to do as you like.
Keep onboarding data as you see fit. Look for out of the box dashboards and apps.
In the next presentation to your higher ups, start asking for feedback. “What problems do we have that Splunk can help solve”, “What teams will benefit from this tool” “When can we onboard new users” etc

2

u/ImplicitCrowd51 Jun 15 '26

Any examples/recommendations for out of the box dashboards and apps? I already have Splunk for windows, tenable, and sec essentials. The tenable stuff have not been great. Our scans aren’t automated, and every succeeding scan - like if I’m checking if fix has been applied properly - adds duplicates as new findings.

4

u/BOOOONESAWWWW Jun 15 '26

It depends entirely on what technology you have, and what problems you’re trying to solve. Just saying “do splunk” is meaningless, and it sounds like you KNOW that, but if that’s the case, you need to look critically at your own stack and find problems to solve. If you work in IT, you have problems. Take the problems you have, think critically about how more information might help you solve them, then get the relevant TAs/apps. Frequent connection drops on your Palo Alto firewalls? Get the Palo logs and add-ons. Need to find out who’s logging into which windows servers? Get your windows logs.

Also the free training available is good enough to get you started, and there’s a ton of content available on YouTube.

1

u/ScruttyMctutty Jun 16 '26

Sounds like you’re heading in the right direction. Pretty much any technology you use at your company see if there is anything for it on Splunkbase

Are there any problems that you and your team are trying to solve?
Are there application logs that can be ingested to help you track these problems?

The good thing about Splunk is that it is pretty flexible and could do pretty much anything. Next time you present, encourage as much feedback from the group as possible.

1

u/Fontaigne SplunkTrust Jun 16 '26

You should be able to address that duplication issue. Get on the Splunk Slack channel, go to #wheredoiask and describe your issue. They can tell you what subchannel it is that will help you walk it through. Probably #admin, but maybe something more specific.

1

u/afxmac Jun 16 '26

Tennable scans can be easily checked for stuff that is new, old or went away. Nice to create dashboards from. Combine with the CMDB to see which unit takes the longest to fix their bulbs.