<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Data-Management-amp-Federation/ec-p/755820#M191</link>
    <description>&lt;P class=""&gt;&lt;STRONG&gt;Hi everyone! Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&amp;nbsp;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_self" rel="nofollow noopener noreferrer"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;Slack channel)&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q1:&amp;nbsp;How can Edge Processor relieve ingestion work for a heavy forwarder?​&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Too much data:​ noisy or verbose data sources​&lt;/LI&gt;
&lt;LI&gt;Pre-Parsing:​ Event Breaking&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="TextRun MacChromeBold SCXP117373714 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP117373714 BCX0"&gt;Mask sensitive data&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP117373714 BCX0"&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="EOP SCXP117373714 BCX0"&gt;&lt;SPAN class="TextRun MacChromeBold SCXP258753200 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP258753200 BCX0"&gt;Data Transformation &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun MacChromeBold SCXP258753200 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP258753200 BCX0"&gt;&amp;amp; Enrichment &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q2:&amp;nbsp;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;What are some use &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;case for Edge &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Processor, Ingest &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Processor and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Ingest Actions?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP226036505 BCX0"&gt;​&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class=""&gt;
&lt;LI&gt;
&lt;P data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:120,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.14999,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Ingest Processor (Cloud)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ SPL2 User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="2" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Reduce noise/volume &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Redact sensitive data &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="4" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Send to indexes / s3&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Example: Cloud stack w/no infrastructure Masking and Anonymizing Data &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Edge Processor (Cloud/On-Prem)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ SPL2 User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="9" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Enrich data via real-time threat detection w/KV Store lookups&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="1380" data-aria-posinset="10" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Modify raw events to remove fields and reduce storage &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="11" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Convert complex data into metrics&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="12" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Route user events to a special index &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="13" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Mask PII&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:120,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.14999,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Ingest Actions (Cloud/On-Prem)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="15" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ Props and Transform User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="16" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Simple to medium use cases (simple routing) through a UI &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="17" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Redact sensitive data with rulesets &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="18" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Send to indexes / s3 / s3 Compatible &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="19" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Masking PII &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How to optimize Federated Search queries?​&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.15,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;FS-S3 DSU Optimization Best Practices:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;S3 Partitioning Tip:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Partition data by time (e.g., year/month/day) and other &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;common fields like &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;sourcetype&lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; or host to minimize the amount of data &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;scanned.&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;Search Practices:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Limit time ranges, specify federated index names, and &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;use the partition attribute keys and right filters in the searches&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;Monitoring &amp;amp; Troubleshooting:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Use Job Inspector to identify bottlenecks, &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;and the drill-down feature in the CMC license monitoring dashboard to find &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;the top 10 apps, users, or searches for query-level optimization.&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Documentation: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;​&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Amazon/Partitioning_data_in_S3_for_the_best_FS-S3_experience" data-hyperlinktype="0" target="_blank"&gt;&lt;STRONG&gt;&lt;SPAN data-scheme-color="@FF0F7B,4," data-usefontface="true" data-hyperlinkhascustomcolor="true" data-contrast="none"&gt;Lantern article for partitioning best practices and guidelines&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Other Questions (check the&amp;nbsp;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_self" rel="nofollow noopener noreferrer"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What new capabilities are available across Data Management &amp;amp; Federation today?​&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Federated Search &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;for Amazon S3 vs &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;data in Splunk. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Which one is more &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;taxing for scheduled &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;alerts and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Dashboards?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP91336423 BCX0"&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.15,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:12,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;I have difficulties &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;ingesting&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/splunk/botsv3" data-hyperlinktype="0" target="_blank"&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;https://github.com/splunk/botsv3&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&amp;nbsp;into &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;cloud.&lt;/SPAN&gt;&lt;SPAN&gt;​&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;I found &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;journal.gz&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt; data files in &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;rawdata&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt; folders of &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;the archive, but when I use them to add data, &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;parsing looks off.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;I would like to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;understand how &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;logs get parsed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;There are so many &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;different vendors. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;What schema &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;Splunk uses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;Is it possible to show a sample query to enrich on S3?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;​When setting up S3 integration, one has to map timestamp field in case one wants to correlate logs in splunk and logs in S3 bucket on time? If so, how is this correlation optimized if there is no index for S3 data?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;What are the indexes that are used for various types of logs?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 24 Nov 2025 23:37:02 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2025-11-24T23:37:02Z</dc:date>
    <item>
      <title>Platform: Data Management &amp; Federation</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Data-Management-amp-Federation/ec-p/754422#M180</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://discover.splunk.com/Splunk-Community-Office-Hours-Data-Management-Federation.html" target="_blank" rel="nofollow noopener noreferrer"&gt;Register here.&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;This thread is for the Community Office Hours session on&amp;nbsp;&lt;STRONG&gt;Platform:&amp;nbsp;Data Management &amp;amp; Federation&amp;nbsp;&lt;/STRONG&gt;on&amp;nbsp;&lt;STRONG&gt;Thurs, November 20, 2025 at 11am PT / 2pm ET&lt;/STRONG&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What can I ask in this AMA?&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How do Edge Processor/Ingest Processor and Federated Search for Amazon S3 work together? Can I get a demo?&lt;/LI&gt;
&lt;LI&gt;How can I configure Edge Processor in Splunk Enterprise (on-prem)?&lt;/LI&gt;
&lt;LI&gt;How can I onboard data from any data store or end points?&lt;/LI&gt;
&lt;LI&gt;How does Splunk enable data federation across Amazon Security Lake (ASL) and S3? What tools are available to me?&lt;/LI&gt;
&lt;LI&gt;How can I optimize my Edge Processor or Ingest Processor SPL2 pipelines?&lt;/LI&gt;
&lt;LI&gt;Anything else you’d like to learn!&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;You can also head to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_blank" rel="nofollow noopener noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel to ask questions&amp;nbsp;(sign in with SSO&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="nofollow noopener noreferrer"&gt;here&lt;/A&gt;).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;After that, we will open the floor up to live Q&amp;amp;A with meeting participants.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Look forward to connecting!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 19:57:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Platform-Data-Management-amp-Federation/ec-p/754422#M180</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2026-03-23T19:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Platform: Data Management &amp; Federation</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Platform-Data-Management-amp-Federation/ec-p/755820#M191</link>
      <description>&lt;P class=""&gt;&lt;STRONG&gt;Hi everyone! Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&amp;nbsp;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_self" rel="nofollow noopener noreferrer"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;Slack channel)&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q1:&amp;nbsp;How can Edge Processor relieve ingestion work for a heavy forwarder?​&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Too much data:​ noisy or verbose data sources​&lt;/LI&gt;
&lt;LI&gt;Pre-Parsing:​ Event Breaking&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="TextRun MacChromeBold SCXP117373714 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP117373714 BCX0"&gt;Mask sensitive data&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP117373714 BCX0"&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="EOP SCXP117373714 BCX0"&gt;&lt;SPAN class="TextRun MacChromeBold SCXP258753200 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP258753200 BCX0"&gt;Data Transformation &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun MacChromeBold SCXP258753200 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP258753200 BCX0"&gt;&amp;amp; Enrichment &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q2:&amp;nbsp;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;What are some use &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;case for Edge &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Processor, Ingest &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Processor and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP226036505 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP226036505 BCX0"&gt;Ingest Actions?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP226036505 BCX0"&gt;​&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL class=""&gt;
&lt;LI&gt;
&lt;P data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:120,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.14999,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Ingest Processor (Cloud)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ SPL2 User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="2" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Reduce noise/volume &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Redact sensitive data &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="4" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Send to indexes / s3&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Example: Cloud stack w/no infrastructure Masking and Anonymizing Data &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Edge Processor (Cloud/On-Prem)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ SPL2 User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="9" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Enrich data via real-time threat detection w/KV Store lookups&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="1380" data-aria-posinset="10" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Modify raw events to remove fields and reduce storage &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="11" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Convert complex data into metrics&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="12" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Route user events to a special index &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="13" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Mask PII&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:120,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.14999,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Ingest Actions (Cloud/On-Prem)&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL style="font-weight: 400;"&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="15" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Data Admin/ Props and Transform User&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="8226" data-font="Arial,Sans-Serif" data-buautonum="8" data-margin="660" data-aria-posinset="16" data-aria-level="1"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Simple to medium use cases (simple routing) through a UI &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="17" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Redact sensitive data with rulesets &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="18" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Send to indexes / s3 / s3 Compatible &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-charcodes="111" data-font="Courier New,monospace" data-buautonum="8" data-margin="1380" data-aria-posinset="19" data-aria-level="2"&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Masking PII &lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How to optimize Federated Search queries?​&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.15,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:0,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;STRONG style="font-family: inherit;"&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;FS-S3 DSU Optimization Best Practices:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;S3 Partitioning Tip:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Partition data by time (e.g., year/month/day) and other &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;common fields like &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;sourcetype&lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; or host to minimize the amount of data &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;scanned.&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;Search Practices:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Limit time ranges, specify federated index names, and &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;use the partition attribute keys and right filters in the searches&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;Monitoring &amp;amp; Troubleshooting:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt; Use Job Inspector to identify bottlenecks, &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;and the drill-down feature in the CMC license monitoring dashboard to find &lt;/SPAN&gt;&lt;SPAN data-usefontface="true" data-contrast="none"&gt;the top 10 apps, users, or searches for query-level optimization.&lt;/SPAN&gt;&lt;SPAN&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;SPAN data-scheme-color="@000000,13," data-usefontface="true" data-contrast="none"&gt;Documentation: &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;​&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Amazon/Partitioning_data_in_S3_for_the_best_FS-S3_experience" data-hyperlinktype="0" target="_blank"&gt;&lt;STRONG&gt;&lt;SPAN data-scheme-color="@FF0F7B,4," data-usefontface="true" data-hyperlinkhascustomcolor="true" data-contrast="none"&gt;Lantern article for partitioning best practices and guidelines&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;&lt;STRONG&gt;Other Questions (check the&amp;nbsp;&lt;/STRONG&gt;&lt;A href="https://splunkcommunity.slack.com/archives/C0FRVF350" target="_self" rel="nofollow noopener noreferrer"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What new capabilities are available across Data Management &amp;amp; Federation today?​&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Federated Search &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;for Amazon S3 vs &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;data in Splunk. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Which one is more &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;taxing for scheduled &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;alerts and &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP91336423 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP91336423 BCX0"&gt;Dashboards?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="EOP SCXP91336423 BCX0"&gt;​&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-ccp-props="{&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559683&amp;quot;:0,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559731&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335562764&amp;quot;:2,&amp;quot;335562765&amp;quot;:1.15,&amp;quot;335562766&amp;quot;:4,&amp;quot;335562767&amp;quot;:12,&amp;quot;335562768&amp;quot;:4,&amp;quot;335562769&amp;quot;:0}"&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;I have difficulties &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;ingesting&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://github.com/splunk/botsv3" data-hyperlinktype="0" target="_blank"&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;https://github.com/splunk/botsv3&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&amp;nbsp;into &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;cloud.&lt;/SPAN&gt;&lt;SPAN&gt;​&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;I found &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;journal.gz&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt; data files in &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;rawdata&lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt; folders of &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;the archive, but when I use them to add data, &lt;/SPAN&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;parsing looks off.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;I would like to &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;understand how &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;logs get parsed. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;There are so many &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;different vendors. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;What schema &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="TextRun SCXP46469933 BCX0" data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="NormalTextRun SCXP46469933 BCX0"&gt;Splunk uses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;Is it possible to show a sample query to enrich on S3?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;​When setting up S3 integration, one has to map timestamp field in case one wants to correlate logs in splunk and logs in S3 bucket on time? If so, how is this correlation optimized if there is no index for S3 data?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-usefontface="false" data-contrast="none"&gt;&lt;SPAN class="EOP SCXP46469933 BCX0"&gt;What are the indexes that are used for various types of logs?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 24 Nov 2025 23:37:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Platform-Data-Management-amp-Federation/ec-p/755820#M191</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2025-11-24T23:37:02Z</dc:date>
    </item>
  </channel>
</rss>

