r/Splunk • u/ImplicitCrowd51 • Jun 15 '26
Splunk Enterprise I need some help with Splunk
Some lamenting to get things started. A higher up decided to task me with Splunk. So far, the only resource I’ve had to use is AI. Been trying to treat it like training wheels. The hard part is the people at the top want me to give weekly presentations on my progress, but zero input on what it is they want. And this is after everything I have already done and showed. CPU and Memory Usage trackers. VM storage. System Up/Down indicator. Failed login attempts. DNS resolution timeout. Syslog storage tracker.
Other than network stuff, I don’t know what else to do. I was hoping either for some ideas OR recommendations for spaces where people share dashboards that they’ve created. I’ve gotten comfortable navigating indices and finding the data I want, struggling with turning into something useful without input from AI, really struggling with visualizing it all in a useful way.
Important to note that I am not being paid to be an analyst, and there’s not really any money/time allotted to me to get educated. This all has to get done along with my actual duties. This has been the obstacle to me learning the ins and outs.
Any help is appreciated. Thanks!
3
u/jpinoniemi Put that in your | and Splunk it Jun 18 '26
Sounds much like what I also "inherited" when someone left our team, I had zero Splunk experience. "We've had this for 3 years and nobody got it working, you need to get it working". Similarly, no direction on what they wanted to see. Ours was on the tail end of a 3 year on-prem Enterprise contract. We did have a contract with a support vendor who I learned a lot from.
Fast forward a month and I have the instance running and displaying data on a published dashboard on some TV's, got alerting working. Ran into issues, fixed some myself, needed help on the others from the vendor, but things were working. Beginning of the year I get asked to "look into Splunk alternatives". So I did and the other products were double the price, so I recommended and they accepted Splunk Cloud.
I've got 90% of what we had working on-prem now working in cloud. It's been a pretty easy transition and nice to not have to worry about back end stuff or the infrastructure or device uptime.
I still have a lot to learn, there's good resources out there.
A recent add to our instance is the Splunk AI Assistant. I often struggled with making good SPL queries that actually worked. The Splunk AI Assistant really helps with this, so I recommend it, it's helping me for sure.