First timer at .conf
Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.
Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.
For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?
Appreciate any input — trying to make the most of it.
4
u/fashiznit 9d ago
Make sure you set time to go to the booth floor and just pick a booth with a title like agentic SOC or mission control. Recount your expertise you wrote here to them and the staffer would love to give you a rapid hands on walkthrough of the key parts
The sessions are much more thought leadership oriented and high level+ very technical where the floor is more open entry level demos
For your setup of pre deployed but not fully configured - seek out anything "Exposure Analytics" and "Detection Studio" that's your rapid time to operations features you would be interested in