<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-EMEA-Wed-9-6-23/ec-p/657239#M55</link>
    <description>&lt;P class=""&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q1: How to get a python script that run REST API calls to work with python3 on the HF in case python2 is withdrawn&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;How to make Python 2 compatible Splunk app a python 3 compatible&lt;/LI&gt;&lt;UL class=""&gt;&lt;LI&gt;Rewrite app so that it’s Python 3 compatible only (e.g. in Splunk 9.x)&lt;/LI&gt;&lt;LI&gt;Rewrite app so that it’s “dual-compatible” to support both Python 2.x and Python 3.x.&amp;nbsp;&lt;/LI&gt;&lt;UL class=""&gt;&lt;LI&gt;Suggested for all developers&lt;/LI&gt;&lt;LI&gt;You can use Splunk provided dual-compatibility libraries: &lt;I&gt;six, python-future, 2to3&lt;/I&gt; (in this order)&lt;/LI&gt;&lt;LI&gt;Caveat - using libraries above might not help in all cases (manual fixes necessary)&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q2: In case we have a lot of scheduled saved searches and not so many adhoc what we can fine tune to not have the searches delayed?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Maximize search slots on SH - see Splunk .conf17 slide deck: &lt;A href="https://conf.splunk.com/files/2017/slides/splunk-enterprise-security-health-check.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;https://conf.splunk.com/files/2017/slides/splunk-enterprise-security-health-check.pdf&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Optimize SPL code&lt;/LI&gt;&lt;LI&gt;Optimize resource usage during indexing on IDX&lt;/LI&gt;&lt;LI&gt;Optimize resource usage during searching on IDX&lt;/LI&gt;&lt;LI&gt;Spread your scheduled searches over the time&lt;/LI&gt;&lt;LI&gt;Boost resources (CPU, RAM, IOPS) - Add more cores (both to SH and possibly to IDX) if you hit search-slots limit. Splunk reference server hardware specs.&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q3: Splunk Edge Processor - is it possible to both filter data A and send A' to Splunk Cloud and simultaneously send A to S3 bucket?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Yes. This is a standard use case and one that customers asked for. All data (A) goes to S3 (unfiltered) to be searched later only if necessary. And filtered (more relevant) data (A’) goes to Splunk Cloud.&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Other Questions (check the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;What are the different options to get data in?&lt;/LI&gt;&lt;LI&gt;Swift alliance log integration with Splunk. We were collecting the log from Swift application using SNMP V2 but is stopped.&lt;/LI&gt;&lt;LI&gt;Edge Processor demo&lt;/LI&gt;&lt;LI&gt;GDI resources for Observability (Azure, server less functions, K8 micro services, etc.)&lt;/LI&gt;&lt;LI&gt;Additional GDI resources (free courses, .conf sessions, tech talks, etc.)&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 11 Sep 2023 22:28:42 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2023-09-11T22:28:42Z</dc:date>
    <item>
      <title>Getting Data In: Platform (EMEA) - Wed 9/6/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-EMEA-Wed-9-6-23/ec-p/652953#M42</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[EMEA-friendly: 8am PT / 4pm UK time] - &lt;/SPAN&gt;&lt;A href="https://splunk.zoom.us/meeting/register/tJEsdOysrTsqG9zT_w1g70FwscZSi4mO80xG" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Register here&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt; and ask questions below. This thread is for the Community Office Hours session on &lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI) to Splunk Platform&lt;/STRONG&gt;&lt;SPAN&gt; on &lt;/SPAN&gt;&lt;STRONG&gt;Wed, September 6, 2023 at 8am PT / 11am ET / 4pm UK time&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is your opportunity to ask questions related to your specific GDI challenge or use case, including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;How to onboard common data sources (AWS, Azure, Windows, *nix, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Using forwarders&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apps to get data in&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Data Manager (Splunk Cloud Platform)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Ingest actions, archiving your data, and anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration or as comments below.&lt;/STRONG&gt;&lt;SPAN&gt; You can also head to &lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; user Slack channel to ask questions (request access &lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will go in order of the questions posted below, then will open the floor up to live Q&amp;amp;A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 22:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-EMEA-Wed-9-6-23/ec-p/652953#M42</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-09-11T22:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Platform (EMEA) - Wed 9/6/23</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-EMEA-Wed-9-6-23/ec-p/657239#M55</link>
      <description>&lt;P class=""&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q1: How to get a python script that run REST API calls to work with python3 on the HF in case python2 is withdrawn&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;How to make Python 2 compatible Splunk app a python 3 compatible&lt;/LI&gt;&lt;UL class=""&gt;&lt;LI&gt;Rewrite app so that it’s Python 3 compatible only (e.g. in Splunk 9.x)&lt;/LI&gt;&lt;LI&gt;Rewrite app so that it’s “dual-compatible” to support both Python 2.x and Python 3.x.&amp;nbsp;&lt;/LI&gt;&lt;UL class=""&gt;&lt;LI&gt;Suggested for all developers&lt;/LI&gt;&lt;LI&gt;You can use Splunk provided dual-compatibility libraries: &lt;I&gt;six, python-future, 2to3&lt;/I&gt; (in this order)&lt;/LI&gt;&lt;LI&gt;Caveat - using libraries above might not help in all cases (manual fixes necessary)&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q2: In case we have a lot of scheduled saved searches and not so many adhoc what we can fine tune to not have the searches delayed?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;&lt;SPAN class=""&gt;Maximize search slots on SH - see Splunk .conf17 slide deck: &lt;A href="https://conf.splunk.com/files/2017/slides/splunk-enterprise-security-health-check.pdf" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;https://conf.splunk.com/files/2017/slides/splunk-enterprise-security-health-check.pdf&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Optimize SPL code&lt;/LI&gt;&lt;LI&gt;Optimize resource usage during indexing on IDX&lt;/LI&gt;&lt;LI&gt;Optimize resource usage during searching on IDX&lt;/LI&gt;&lt;LI&gt;Spread your scheduled searches over the time&lt;/LI&gt;&lt;LI&gt;Boost resources (CPU, RAM, IOPS) - Add more cores (both to SH and possibly to IDX) if you hit search-slots limit. Splunk reference server hardware specs.&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Q3: Splunk Edge Processor - is it possible to both filter data A and send A' to Splunk Cloud and simultaneously send A to S3 bucket?&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Yes. This is a standard use case and one that customers asked for. All data (A) goes to S3 (unfiltered) to be searched later only if necessary. And filtered (more relevant) data (A’) goes to Splunk Cloud.&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;STRONG&gt;Other Questions (check the &lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt; Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;What are the different options to get data in?&lt;/LI&gt;&lt;LI&gt;Swift alliance log integration with Splunk. We were collecting the log from Swift application using SNMP V2 but is stopped.&lt;/LI&gt;&lt;LI&gt;Edge Processor demo&lt;/LI&gt;&lt;LI&gt;GDI resources for Observability (Azure, server less functions, K8 micro services, etc.)&lt;/LI&gt;&lt;LI&gt;Additional GDI resources (free courses, .conf sessions, tech talks, etc.)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 11 Sep 2023 22:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-EMEA-Wed-9-6-23/ec-p/657239#M55</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2023-09-11T22:28:42Z</dc:date>
    </item>
  </channel>
</rss>

