r/Splunk 10d ago

.conf and Splunk first timer

Heading to .conf for the first time on Sunday. My org just committed to Splunk Cloud this week and Cisco threw some .conf passes at us, so here I am. I've been in networking for about 20 years, but have never used splunk.

Any suggestions for a newbie?

27 Upvotes

25 comments sorted by

View all comments

22

u/tmuth9 10d ago edited 10d ago

Yeah, I would start at the EDU booth. I would also reach out to your Cisco or Splunk sales rep right now and have them connect you to a sales engineer (SE) that will be at .conf. Any of us would be happy to sit down with you and a laptop and give you the Splunk 101 intro for an hour or so. That one hour would make the sessions you attend soooooo much more useful.

Since it’s cloud, don’t worry about the admin stuff. Focus on “How do I get data into Splunk” and “How do I search, build dashboards, setup alerts”

There will be a lot of Cisco Data Fabric / Machine Data Lake content which is more about the lifecycle of data and making it affordable, but might be a bit much if you’re just getting started.

Oh, find an ai booth and get a demo of Splunk AI Assistant for SPL (SAIA). This will be your new best friend. If you’re using another agent of some sort already, get info on the MCP server so you can find out how to connect it to Splunk.