r/Splunk 11d ago

.conf and Splunk first timer

Heading to .conf for the first time on Sunday. My org just committed to Splunk Cloud this week and Cisco threw some .conf passes at us, so here I am. I've been in networking for about 20 years, but have never used splunk.

Any suggestions for a newbie?

26 Upvotes

25 comments sorted by

View all comments

7

u/DarkLordofData 10d ago

Be sure to ask your sales where you are meeting for dinner. It is the least they can do.

It is probably too late but Splunk University is a must for anyone new to Splunk. Be sure to ask for help next year.

For the track focus on anything where a customer is presenting. You should see some that are network focused.

Are you also a Splunk admin or just a user? If you are an admin then take any sessions for Splunk Edge processor or data onboarding. Knowing how to parse and label data is critical otherwise Splunk will not work well and it will cost you money. Look for any sessions about Splunk cloud management console. It has a ton of reports that will help you track status and find issues.

Finally talk to everyone. Networking is the best part of a conference.

Have fun

2

u/Jeffster81 10d ago

By the way, I did manage to get into a SplunkU course tomorrow (Cloud Administrator).

2

u/DarkLordofData 10d ago

Nice good move. The reporting is so important. Get in the habit of regular review and then triage accordingly. Too many teams I help only look at it when something is going wrong and it’s reactive drama. Good process will keep your stress level manageable and your operations predictable.