<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Federated-Data-Management/ec-p/748754#M166</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Hi everyone! Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_blank" rel="nofollow noopener noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel -&amp;nbsp;&lt;SPAN&gt;request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here) :&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1: How does Splunk enable data federation across Amazon Security Lake and S3? What tools are available to me?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;FS-S3 + FA-ASL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Runs on Splunk Cloud&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Set up Federated Search for infrequent, ad-hoc quering&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Glue table + resource share from AWS&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;search using sdselect&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Set up Data Lake Indexing for frequent querying and ES use cases&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;How is the Amazon S3 data searched through Splunk?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;To access S3 data &lt;/SPAN&gt;&lt;STRONG&gt;today&lt;/STRONG&gt;&lt;SPAN&gt;, customers need to use the new SPL command ‘sdselect’, which follows a SQL-like syntax.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;In the &lt;/SPAN&gt;&lt;STRONG&gt;future&lt;/STRONG&gt;&lt;SPAN&gt;, ‘sdselect’ will be replaced with SPL2.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/Search/FSS3SearchGlueTable" target="_blank" rel="noopener"&gt;sdselect command syntax&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How do I forward my logs to Edge Processor once I’ve successfully configured it? Script is showing as healthy.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Edge Processor supports a variety of data sources including:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Forwards (Splunk2Splunk)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTP Event Collector (HEC)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Syslog&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-data-from-a-forwarder-into-an-edge-processor" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get data from a forwarder into an Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-data-into-an-edge-processor-using-http-event-collector" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get data into an Edge Processor using HTTP Event Collector&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-syslog-data-into-an-edge-processor" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get syslog data into an Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How do Data Management and Federation work together?&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;How can I optimize DSU consumption for&amp;nbsp; FS-S3 use case?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Datamodel Acceleration via Federated Search&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;AWS S3 Replay in Splunk Cloud&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Wed, 25 Jun 2025 20:40:46 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2025-06-25T20:40:46Z</dc:date>
    <item>
      <title>Platform: Federated Data Management</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Federated-Data-Management/ec-p/743122#M157</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://discover.splunk.com/Office-Hours-Platform-Federated-Data-Management.html" target="_blank" rel="noopener"&gt;Register/Watch OnDemand here. &lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;This thread is for the Community Office Hours session on&amp;nbsp;&lt;STRONG&gt;Platform: Federated Data Management&amp;nbsp;&lt;/STRONG&gt;on &lt;STRONG&gt;Wed, June 18, 2025 at 1pm PT / 4pm ET&lt;/STRONG&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What can I ask in this AMA?&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How do Data Management, Federated Search, and Federated Analytics work together? Can I get a demo?&lt;/LI&gt;
&lt;LI&gt;How can I optimize my data design according to its use case (detection, investigation, threat hunting, compliance, etc.)?&lt;/LI&gt;
&lt;LI&gt;How does Splunk enable data federation across Amazon Security Lake and S3? What tools are available to me?&lt;/LI&gt;
&lt;LI&gt;How can I onboard data from any data store or end points?&lt;/LI&gt;
&lt;LI&gt;How can I start filtering and routing data with Edge Processor or Ingest Processor?&lt;/LI&gt;
&lt;LI&gt;How can I optimize my Edge Processor or Ingest Processor pipelines?&lt;/LI&gt;
&lt;LI&gt;Anything else you’d like to learn!&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;You can also head to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel to ask questions (request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;After that, we will open the floor up to live Q&amp;amp;A with meeting participants.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look forward to connecting!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 19:51:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Platform-Federated-Data-Management/ec-p/743122#M157</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2026-03-23T19:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Platform: Federated Data Management</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Federated-Data-Management/ec-p/748754#M166</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi everyone! Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_blank" rel="nofollow noopener noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel -&amp;nbsp;&lt;SPAN&gt;request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here) :&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1: How does Splunk enable data federation across Amazon Security Lake and S3? What tools are available to me?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;FS-S3 + FA-ASL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Runs on Splunk Cloud&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Set up Federated Search for infrequent, ad-hoc quering&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Glue table + resource share from AWS&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;search using sdselect&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Set up Data Lake Indexing for frequent querying and ES use cases&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;How is the Amazon S3 data searched through Splunk?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;To access S3 data &lt;/SPAN&gt;&lt;STRONG&gt;today&lt;/STRONG&gt;&lt;SPAN&gt;, customers need to use the new SPL command ‘sdselect’, which follows a SQL-like syntax.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;In the &lt;/SPAN&gt;&lt;STRONG&gt;future&lt;/STRONG&gt;&lt;SPAN&gt;, ‘sdselect’ will be replaced with SPL2.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.0.2305/Search/FSS3SearchGlueTable" target="_blank" rel="noopener"&gt;sdselect command syntax&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How do I forward my logs to Edge Processor once I’ve successfully configured it? Script is showing as healthy.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Edge Processor supports a variety of data sources including:&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Forwards (Splunk2Splunk)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTP Event Collector (HEC)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Syslog&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-data-from-a-forwarder-into-an-edge-processor" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get data from a forwarder into an Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-data-into-an-edge-processor-using-http-event-collector" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get data into an Edge Processor using HTTP Event Collector&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://help.splunk.com/en/splunk-cloud-platform/process-data-at-the-edge/use-edge-processors/9.3.2411/get-data-into-edge-processors/get-syslog-data-into-an-edge-processor" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Get syslog data into an Edge Processor&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;How do Data Management and Federation work together?&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;How can I optimize DSU consumption for&amp;nbsp; FS-S3 use case?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Datamodel Acceleration via Federated Search&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;AWS S3 Replay in Splunk Cloud&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 25 Jun 2025 20:40:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Platform-Federated-Data-Management/ec-p/748754#M166</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2025-06-25T20:40:46Z</dc:date>
    </item>
  </channel>
</rss>

