<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706688#M135</link>
    <description>&lt;P&gt;Zoom link?&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 21:00:43 GMT</pubDate>
    <dc:creator>jason2</dc:creator>
    <dc:date>2024-12-12T21:00:43Z</dc:date>
    <item>
      <title>Awesome Admins: Running a Healthy Splunk Platform Environment - 12/12/24</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/702742#M126</link>
      <description>&lt;P&gt;&lt;A href="https://discover.splunk.com/Office-Hours-Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment.html" target="_blank" rel="nofollow noopener noreferrer"&gt;&lt;STRONG&gt;Register here.&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This thread is for the Community Office Hours session on &lt;STRONG&gt;Awesome Admins: Running a Healthy Splunk Platform Environment&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Thurs, Dec 12, 2024 at 1pm PT / 4pm ET.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What can I ask in this AMA?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What should I be looking at as a Splunk Cloud or Splunk Enterprise Admin, and why?&lt;/LI&gt;&lt;LI&gt;What are some best practices for using&amp;nbsp;workload management?&lt;/LI&gt;&lt;LI&gt;How can I set up a scalable architecture?&lt;/LI&gt;&lt;LI&gt;What are some best practices for monitoring system health with the Cloud Monitoring Console?&lt;/LI&gt;&lt;LI&gt;What are some tips for managing and balancing disaster recovery?&lt;/LI&gt;&lt;LI&gt;Any best practices for managing large numbers of users?&lt;/LI&gt;&lt;LI&gt;Which admin tasks should I be streamlining with ACS?&lt;/LI&gt;&lt;LI&gt;Anything else you'd like to learn!&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;You can also head to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel to ask questions (request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;After that, we will open the floor up to live Q&amp;amp;A with meeting participants.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Look forward to connecting!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 21:32:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/702742#M126</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2025-01-15T21:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Awesome Admins: Running a Healthy Splunk Platform Environment</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706688#M135</link>
      <description>&lt;P&gt;Zoom link?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 21:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706688#M135</guid>
      <dc:creator>jason2</dc:creator>
      <dc:date>2024-12-12T21:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Awesome Admins: Running a Healthy Splunk Platform Environment</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706813#M137</link>
      <description>&lt;P&gt;Hello Splunk community,&lt;BR /&gt;&lt;BR /&gt;I unfortunately missed the session. Is there a recording available? I’m really interested and would love to catch up on it.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Dec 2024 10:18:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706813#M137</guid>
      <dc:creator>MeWoW</dc:creator>
      <dc:date>2024-12-15T10:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Awesome Admins: Running a Healthy Splunk Platform Environment</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706943#M139</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269534"&gt;@MeWoW&lt;/a&gt;! If you registered for the session you should have received a recap email from me with the link. You can also&amp;nbsp;get the full Q&amp;amp;A deck and live recording in the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;Slack channel&amp;nbsp;&lt;SPAN&gt;(request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp; Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2024 19:42:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706943#M139</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-12-16T19:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Awesome Admins: Running a Healthy Splunk Platform Environment</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706944#M140</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;Which admin tasks should I be streamlining with ACS?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Index Management&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Access Management&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Limits Management&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;App Management&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Managing HEC tokens&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Adding IP AllowListing to the infrastructure&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Additional Resources:&amp;nbsp;&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSIntro" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSIntro&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Usage: &lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSusage" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSusage&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Reference: &lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSREF" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Config/ACSREF&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;What's the best way to make changes to apps' local directories on search head clusters, since these can't be pushed from the deployer?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Use &lt;/SPAN&gt;&lt;SPAN&gt;local_only&lt;/SPAN&gt;&lt;SPAN&gt; Push Mode designed specifically for modifying existing apps&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Perfect for updating built-in apps like the Search app&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Member's existing configurations are preserved during merge&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Docs: &lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.2/DistSearch/PropagateSHCconfigurationchanges#Mode:_local_only" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Deployer push mode: local_only&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;What are some good resources for capacity planning? (Splunk Enterprise)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;ODS (On Demand Services) - they are a team in Splunk who can assist with some capacity planning tasks.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q4:&amp;nbsp;Is there any way to limit SVC usage by role, apps, index?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Only way is to control the searches happening in the environment. The SVC usage dashboard data is delayed and Splunk does not reveal how this is calculated.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions/Topics (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;What should I be looking at as a Splunk Cloud or Splunk Enterprise Admin, and why?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;What are your favorite best practices for running a healthy Splunk Platform environment?&lt;/LI&gt;&lt;LI&gt;What are the best practices for avoiding and resolving bucket issues? Can we manually schedule bucket rebuild to increase search performance?&lt;/LI&gt;&lt;LI&gt;What are best practices for implementing and using Splunk Security Essentials?&lt;/LI&gt;&lt;LI&gt;How to best get logs from a Kubernetes cluster?&lt;/LI&gt;&lt;LI&gt;Advanced admin/architect topics&lt;/LI&gt;&lt;LI&gt;Any approaches to use workload management if your OS only supports cgroups v2 anymore?&lt;/LI&gt;&lt;LI&gt;How to size a splunk environment when you know what to expect (outside of ingest volume).&lt;/LI&gt;&lt;LI&gt;How often do you check the DMC for the health of the environment? Do you just set up alerts for various thresholds?&lt;/LI&gt;&lt;LI&gt;Is there a way to know if someone is using an index for searching. Reason I am asking is sometimes over the course of time we have data coming in but no one is using them. So these would be good candidates for removing the source for ingestion. I am also looking to see macros being covered&lt;/LI&gt;&lt;LI&gt;Is there any app similar to cmc that we can use for splunk enterprise in search head instead of accessing monitor console in cluster manager?&lt;/LI&gt;&lt;LI&gt;Is there a way to share dashboard for anonymous users, sometimes the data for example is good for inventory and not confidential. I wonder if you had this kind of use cases before?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 16 Dec 2024 19:48:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Awesome-Admins-Running-a-Healthy-Splunk-Platform-Environment-12/ec-p/706944#M140</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-12-16T19:48:20Z</dc:date>
    </item>
  </channel>
</rss>

