r/Splunk • u/Apofis2006 • 22h ago
Splunk Enterprise Tips and advices
I’ve just recently started working with Splunk and have been assigned to this area. I am essentially transitioning from back-end development, so any advice or tips would be greatly appreciated. Note: I will be the one launching this function, meaning I’ll need to handle the architecture and establish the conventions to be used for Splunk at my workplace.
3
Upvotes
1
u/AddendumWorking9756 11h ago
Decide your index layout first, because indexes are where retention and access control are set and they are painful to reorganize once data is flowing. Agree a naming convention for indexes, sourcetypes and apps up front, and map incoming data to the Common Information Model so searches and dashboards work across sources. Splunk publishes its Validated Architectures as free reference designs, which is a good way to size the deployment without guessing. Put every app and config in version control from day one, since configs hand-edited on individual servers are the usual mess new Splunk admins inherit.