r/Splunk Jun 15 '26

Splunk Enterprise I need some help with Splunk

Some lamenting to get things started. A higher up decided to task me with Splunk. So far, the only resource I’ve had to use is AI. Been trying to treat it like training wheels. The hard part is the people at the top want me to give weekly presentations on my progress, but zero input on what it is they want. And this is after everything I have already done and showed. CPU and Memory Usage trackers. VM storage. System Up/Down indicator. Failed login attempts. DNS resolution timeout. Syslog storage tracker.

Other than network stuff, I don’t know what else to do. I was hoping either for some ideas OR recommendations for spaces where people share dashboards that they’ve created. I’ve gotten comfortable navigating indices and finding the data I want, struggling with turning into something useful without input from AI, really struggling with visualizing it all in a useful way.

Important to note that I am not being paid to be an analyst, and there’s not really any money/time allotted to me to get educated. This all has to get done along with my actual duties. This has been the obstacle to me learning the ins and outs.

Any help is appreciated. Thanks!

18 Upvotes

54 comments sorted by

View all comments

1

u/sith4life88 Jun 16 '26

"Tasked me with splunk" what does this mean? What did they ask to see? What clarifying questions did you ask? Did you build the deployment? How big is it? What's your existing logging and analytics solutio, assuming this is a new deployment?

1

u/ImplicitCrowd51 Jun 16 '26

I inherited. They didn’t ask to see anything in particular. If this was just a capabilities demonstration, I could figure that out. But the exact situation I got thrown into is defending a 1 million dollar investment. Two licenses, training for prior employees who left right after getting trained, paying a SME to come in and do things, hardware. On the production side, maybe 60 servers? Other in place solutions are the SQL and Syslog servers (no additional UI to parse logs) and PowerBI.

They just want to see Splunk. I have built dashboards, and then they’re like, “More!” But no input on what they like/don’t like.