<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/652954#M43</link>
    <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;Post add your questions/comments here for any topics you'd like to see discussed in the Community Office Hours session&amp;nbsp;&lt;EM&gt;(&lt;/EM&gt;&lt;EM&gt;you can also head to&amp;nbsp;the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;user Slack channel to ask questions and join the discussion - request access&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;here&lt;/A&gt;).&lt;/EM&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 20:18:22 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2023-08-02T20:18:22Z</dc:date>
    <item>
      <title>Getting Data In: Platform - Wed 8/9/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/651964#M40</link>
      <description>&lt;P&gt;[1pm PT / 4pm ET] -&amp;nbsp;&lt;A href="https://splunk.zoom.us/meeting/register/tJ0of-mhrzIqHNcqKzRkU0Az55RdJk6aaqXM" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Register here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and ask questions below. This thread is for the Community Office Hours session on &lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI) to Splunk Platform&lt;/STRONG&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;STRONG&gt;Wed, August 9, 2023 at 1pm PT / 4pm ET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Join our bi-weekly Office Hour series where technical Splunk experts answer questions and provide how-to guidance on a different topic every month! This is your opportunity to ask questions related to your specific GDI challenge or use case, including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;How to onboard common data sources (AWS, Azure, Windows, *nix, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Using forwarders&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apps to get data in&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Data Manager (Splunk Cloud Platform)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest actions, archiving your data, and anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions below as comments in advance.&lt;/STRONG&gt;&lt;SPAN&gt; You can also head to &lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; user Slack channel to ask questions (request access &lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will go in order of the questions posted below, then will open the floor up to live Q&amp;amp;A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 17:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/651964#M40</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-21T17:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Platform - Wed 8/9/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/652954#M43</link>
      <description>&lt;P&gt;Hey Everyone!&lt;/P&gt;&lt;P&gt;Post add your questions/comments here for any topics you'd like to see discussed in the Community Office Hours session&amp;nbsp;&lt;EM&gt;(&lt;/EM&gt;&lt;EM&gt;you can also head to&amp;nbsp;the&amp;nbsp;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;#office-hours&lt;/A&gt;&amp;nbsp;user Slack channel to ask questions and join the discussion - request access&amp;nbsp;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;here&lt;/A&gt;).&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 20:18:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/652954#M43</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-02T20:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Platform - Wed 8/9/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/655068#M48</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Here are some questions from the session (full Q&amp;amp;A and live recording posted in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel)&lt;/SPAN&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;How to bring data in from VMWare and VCenter and how to get the Hydra Gateway to work.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/VMW/About" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Add-on for VMware&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/VMWmetrics/About" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Add-on for VMware Metrics&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="adepp_0-1692640349786.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26914iA5D4A131100B4067/image-size/medium?v=v2&amp;amp;px=400" role="button" title="adepp_0-1692640349786.png" alt="adepp_0-1692640349786.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;How can I troubleshoot common issues when using HEC (e.g., data not being ingested, missing HEC tokens)?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;It’s testing connectivity similar to any web service.&amp;nbsp; Something like this is a good start.&amp;nbsp; curl -k &lt;/SPAN&gt;&lt;SPAN&gt;&lt;A href="https://hostnameofhecreciever:8088/services/collector/health" target="_blank" rel="noopener"&gt;https://hostnameofhecreciever:8088/services/collector/health&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;Are there ways to monitor the usage and health of HEC endpoints to ensure proper data ingestion?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;The MC has a panel for HEC. If you can’t find this, this can be found with some Splunk searches.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;This page also gives a great breakdown of the logging and additional troubleshooting:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/TroubleshootHTTPEventCollector" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/TroubleshootHTTPEventCollector&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q4:&amp;nbsp;Can you tell me about OTel as a TA? What are the benefits and why would I use this vs. staying on UF?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;A streamlined GDI experience that allows you to adopt Observability Cloud in a familiar way&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest metrics and traces and send to O11y Cloud without deploying a standalone OTel Collector&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Deploy OTel TA just like how you deploy other TAs, through Deployment Server, 3rd party tools or directly onto UFs&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Start/stop OTel TA in tandem with Universal Forwarder start/stop&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;No change to your existing log ingestion via UF deployment&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;LI&gt;1st time deployment instructions &lt;A href="https://docs.google.com/presentation/d/1zB-RBh7WcSrEJgf2WM1kt0VEBwf68g_mib1IHqt_vFc/edit#slide=id.g206872c39a5_3_941" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q5:&amp;nbsp;Can you configure forwarders to communicate to an indexer outside the network? &lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Intermediate Forwarding (Good Option)&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Universal Forwarder will send to another Forwarder before leaving network&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Intermediate Forwarder will need remote network access, endpoint will not&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Difficult to manage and can cause issues with data quality and performance&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Configureanintermediateforwarder" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Link to doc&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Splunk Universal Forwarder can send data over HTTP (Better Option)&lt;/SPAN&gt;&lt;/LI&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Best used when unable to open network traffic to use the Splunk to Splunk (S2S) Service.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Load Balancing Supported&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Indexers will need to have HEC configured&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Event Breaker settings Important!&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Configureforwardingwithoutputs.conf#Configure_the_universal_forwarder_to_send_data_over_HTTP" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Link to doc&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 21 Aug 2023 17:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-8-9-23/ec-p/655068#M48</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-08-21T17:56:22Z</dc:date>
    </item>
  </channel>
</rss>

