<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Splunk-Platform-Wed-9-11-24/ec-p/699717#M116</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;What are the optimal forwarder configurations forgetting data into Splunk Cloud with Forwarders (e.g., best practices architectures, with a more technical how to)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Use Universal Forwarders, when possible &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;(unless an HF is necessary - for&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;transforms, routing, or to run some apps such as DB Connect)&lt;/SPAN&gt;&lt;/I&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Include EVENT_BREAKER in props.conf&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Avoid intermediate forwarders&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Layers add complexity, increase failure points, and may lead to uneven distribution of events across indexers.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Use volume-based load balancing over time-based load balancing&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Consider using HEC&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/Intermediaterouting" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Validated Architectures&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2: What are some new features/solutions for getting data into Splunk?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Edge Processor&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available to all, but must also be a Splunk Cloud customer&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processes data locally, before it is sent to indexers&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest Processor&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available in Splunk Cloud only&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processes data in Splunk Cloud,&amp;nbsp; before shipping to destination(s)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest Actions&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available to all&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Unlike transforms, can process cooked data&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;OpenTelemetry Collector (CNCF, second largest project after Kubernetes)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Open source&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Supports HEC, OTLP&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/IngestProcessor/AboutIngestProcessorSolution" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;About Ingest Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2406/EdgeProcessor/AboutEdgeProcessorSolution" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;About Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://opentelemetry.io" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;OpenTelemetry.io&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;I am very new to Edge and Ingest Processor. Could you please walk-through with an example from a beginner's perspective?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Resources:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/resources/videos/edge-processor-demo-video.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Edge Processor Demo video&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; - live example of how to create a pipeline to filter, enrich, and route data.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/customer-success/adopt-splunk/adoption-boards.html?board=data-management" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Data Management Pipeline Builders Resource Hub&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Lantern step-by-step guide: &lt;/SPAN&gt;&lt;A href="https://lantern.splunk.com/Splunk_Platform/Getting_Started/Getting_started_with_Splunk_Data_Management_Pipeline_Builders" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Getting started with Splunk Data Management Pipeline Builders&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;First-time setup instructions for:&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/EdgeProcessor/Firsttimesetup" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/IngestProcessor/Firsttimesetup" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Ingest Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions/Topics (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How can I start routing and filtering with the ingest processor after it has been enabled in the Cloud Stack?&lt;/LI&gt;&lt;LI&gt;Splunk licence saving tips&lt;/LI&gt;&lt;LI&gt;AWS S3 data ingestion through SQS&lt;/LI&gt;&lt;LI&gt;Let's talk about Hybrid landscape&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Commvault storage data?&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Dell Unity data?&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Microsoft System Center VM Manager (SCVMM) and System Center Operations Manager (SCOM) data?&lt;/LI&gt;&lt;LI&gt;Best services to use for best practice for S3 data lakes and Splunk?&amp;nbsp; Security, anomaly detection, scanning of logs, etc.&lt;/LI&gt;&lt;LI&gt;GDI and Auto-discovery of entities from BMC Helix/ADMM and auto creation and dependency mapping of related services, entities in ITSI&lt;/LI&gt;&lt;LI&gt;Testing custom apps with splunk cloud. IE testing in prod because it’s cloud.&lt;/LI&gt;&lt;LI&gt;I am sending data via HEC to a stand alone Indexer, how can I send data via HEC to an Indexer Cluster instead? Best practice ?&lt;/LI&gt;&lt;LI&gt;When Edge processor and Ingest Processor will be available for Splunk onprem ?&lt;/LI&gt;&lt;LI&gt;I have an indexer cluster where an IDX is getting more activity that others? how can i fix it ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2024 19:43:11 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2024-09-20T19:43:11Z</dc:date>
    <item>
      <title>Getting Data In: Splunk Platform - Wed 9/11/24</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Splunk-Platform-Wed-9-11-24/ec-p/690523#M105</link>
      <description>&lt;P data-unlink="true"&gt;&lt;STRONG&gt;&lt;A href="https://discover.splunk.com/Community-Office-Hours-Getting-Data-In-Splunk-Platform.html" target="_blank" rel="noopener"&gt;Register here&lt;/A&gt;.&lt;/STRONG&gt;&lt;SPAN&gt; This thread is for the Community Office Hours session on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI) to Splunk Platform&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Wed, September 11, 2024 at 1pm PT / 4pm ET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is your opportunity to ask questions related to your specific GDI challenge or use case, including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Onboarding common data sources (AWS, Azure, Windows, *nix, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;Forwarder t&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;roubleshooting, connectivity issues, blocked queues, etc.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apps and add-ons to get data in&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processing data (filter, mask, enrich, route) with Edge Processor, Ingest Processor, or Ingest Actions&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Archiving your data&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration or as comments below.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;You can also head to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel to ask questions (request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will open the floor up to live Q&amp;amp;A with meeting participants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 19:43:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Splunk-Platform-Wed-9-11-24/ec-p/690523#M105</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-09-20T19:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Splunk Platform - Wed 9/11/24</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Splunk-Platform-Wed-9-11-24/ec-p/699717#M116</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;What are the optimal forwarder configurations forgetting data into Splunk Cloud with Forwarders (e.g., best practices architectures, with a more technical how to)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Use Universal Forwarders, when possible &lt;/SPAN&gt;&lt;I&gt;&lt;SPAN&gt;(unless an HF is necessary - for&amp;nbsp;&lt;/SPAN&gt;&lt;/I&gt;&lt;I&gt;&lt;SPAN&gt;transforms, routing, or to run some apps such as DB Connect)&lt;/SPAN&gt;&lt;/I&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Include EVENT_BREAKER in props.conf&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Avoid intermediate forwarders&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Layers add complexity, increase failure points, and may lead to uneven distribution of events across indexers.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Use volume-based load balancing over time-based load balancing&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Consider using HEC&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/Intermediaterouting" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Validated Architectures&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2: What are some new features/solutions for getting data into Splunk?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Edge Processor&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available to all, but must also be a Splunk Cloud customer&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processes data locally, before it is sent to indexers&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest Processor&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available in Splunk Cloud only&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processes data in Splunk Cloud,&amp;nbsp; before shipping to destination(s)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest Actions&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Available to all&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Unlike transforms, can process cooked data&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;&lt;SPAN&gt;OpenTelemetry Collector (CNCF, second largest project after Kubernetes)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Open source&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Supports HEC, OTLP&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/IngestProcessor/AboutIngestProcessorSolution" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;About Ingest Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2406/EdgeProcessor/AboutEdgeProcessorSolution" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;About Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://opentelemetry.io" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;OpenTelemetry.io&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;I am very new to Edge and Ingest Processor. Could you please walk-through with an example from a beginner's perspective?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Resources:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/resources/videos/edge-processor-demo-video.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Edge Processor Demo video&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; - live example of how to create a pipeline to filter, enrich, and route data.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.splunk.com/en_us/customer-success/adopt-splunk/adoption-boards.html?board=data-management" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Data Management Pipeline Builders Resource Hub&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Documentation:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Lantern step-by-step guide: &lt;/SPAN&gt;&lt;A href="https://lantern.splunk.com/Splunk_Platform/Getting_Started/Getting_started_with_Splunk_Data_Management_Pipeline_Builders" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Getting started with Splunk Data Management Pipeline Builders&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;First-time setup instructions for:&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.2.2403/EdgeProcessor/Firsttimesetup" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2312/IngestProcessor/Firsttimesetup" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Ingest Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions/Topics (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How can I start routing and filtering with the ingest processor after it has been enabled in the Cloud Stack?&lt;/LI&gt;&lt;LI&gt;Splunk licence saving tips&lt;/LI&gt;&lt;LI&gt;AWS S3 data ingestion through SQS&lt;/LI&gt;&lt;LI&gt;Let's talk about Hybrid landscape&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Commvault storage data?&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Dell Unity data?&lt;/LI&gt;&lt;LI&gt;How to efficiently GDI Microsoft System Center VM Manager (SCVMM) and System Center Operations Manager (SCOM) data?&lt;/LI&gt;&lt;LI&gt;Best services to use for best practice for S3 data lakes and Splunk?&amp;nbsp; Security, anomaly detection, scanning of logs, etc.&lt;/LI&gt;&lt;LI&gt;GDI and Auto-discovery of entities from BMC Helix/ADMM and auto creation and dependency mapping of related services, entities in ITSI&lt;/LI&gt;&lt;LI&gt;Testing custom apps with splunk cloud. IE testing in prod because it’s cloud.&lt;/LI&gt;&lt;LI&gt;I am sending data via HEC to a stand alone Indexer, how can I send data via HEC to an Indexer Cluster instead? Best practice ?&lt;/LI&gt;&lt;LI&gt;When Edge processor and Ingest Processor will be available for Splunk onprem ?&lt;/LI&gt;&lt;LI&gt;I have an indexer cluster where an IDX is getting more activity that others? how can i fix it ?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 19:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Splunk-Platform-Wed-9-11-24/ec-p/699717#M116</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-09-20T19:43:11Z</dc:date>
    </item>
  </channel>
</rss>

