<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.thread@place:occasion</title>
    <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-5-8-24/ec-p/687777#M98</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;Seeing bottlenecks in forwarder getting data into Splunk Cloud from syslog server, should output be pointed to multiple ports?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Check maxKBps setting in limits.conf&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Bottlenecks can sometimes be an indication of a need for an interim layer of forwarders (UF or HF) to help balance the load, especially if it fluctuates. This also will differ if you’re using (or not using) &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4740/?_gl=1*xpqiv8*_ga*MTA0NDM5NjcwOS4xNzEzNDYxNTI3*_ga_GS7YF8S63Y*MTcxNTAwODMwNS4yOS4wLjE3MTUwMDgzMDUuNjAuMC4w*_ga_5EPM2P39FV*MTcxNTAxNDE4MC40Ny4xLjE3MTUwMTQ0OTMuMC4wLjE4MDU0OTE3MQ..&amp;amp;_ga=2.10895155.607030411.1715008059-1044396709.1713461527" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Connect for Syslog.&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;parallelIngestionPipelines could be leverage if output is the bottleneck.&amp;nbsp; For inputs, additional ports OR leveraging the forwarder reading local syslogs stored on the host can be leveraged for increasing throughput&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Syslog" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://lantern.splunk.com/Data_Descriptors/Syslog&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Pipelinesets#Forwarders_and_multiple_pipeline_sets" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Pipelinesets#Forwarders_and_multiple_pipeline_sets&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;How can I extract additional fields from the "properties.log" field from AKS events sent to an EH (Azure Event Hub?) being ingested via MSCS app?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For individual fields, you can use the rex command or EXTRACT in props.conf.&lt;/LI&gt;&lt;LI&gt;To extract all fields, use the spath command.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Rex" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Rex&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Propsconf#:~:text=yellow%2C%20blue%2C%20red-,EXTRACT,-%2D%3Cclass%3E%20%3D%20%5B%3Cregex%3E%7C%3Cregex" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;EXTRACT&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Spath" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Spath&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How do I get Syslog, SNMP traps, Streaming Telemetry, and non-standard formats in?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;See the &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/1537" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;SNMP Modular Input&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; app on splunkbase&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Common GDI methods: UF, API, DB Connect, or HTTP Event Collector&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Custom modular input or dedicated receiver&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;You probably will have to write your own props.conf settings&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Getting Data In manual&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Send syslog via UF: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=XnCEZTKOm90" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=XnCEZTKOm90&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;SC4S overview: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=7ZmVgy9NL3U" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=7ZmVgy9NL3U&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Splunk Connect for syslog (SC4S): &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=iJ1iBZdXt2o" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=iJ1iBZdXt2o&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;How to connect SC4S in 5 mins: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=1Ur3xDNaE4s" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=1Ur3xDNaE4s&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Preferred Getting Data In (GDI) method recommended by Splunk&lt;/LI&gt;&lt;LI&gt;Can we have master and slave Splunk Enterprise instances? Slave is connected always but master is connected only sometimes.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Syslog forwarder setup&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Splunk license saving tips&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Splunk in 2030: Getting Data In (GDI) experience&lt;/LI&gt;&lt;LI&gt;I’d like to hear/watch how to ingest logs from Cisco devices switches/routers with IOS, usage of sc4s with IOS or maybe not using sc4s?&lt;/LI&gt;&lt;LI&gt;I would like to hear your thoughts on potential root cause for duplicate data coming from a single endpoint however each duplicate event has a different timestamp. Using TA-microsoft-graph-security-add-on-for-splunk&lt;/LI&gt;&lt;LI&gt;How do you charge based on resources if it is 100% on prem owned by the customer?&lt;/LI&gt;&lt;LI&gt;Splunk docs talk about Hybrid-Cloud to mean Splunk manages infrastructure and application at the indexer and above level. What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?&lt;/LI&gt;&lt;LI&gt;What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 16 May 2024 18:13:02 GMT</pubDate>
    <dc:creator>adepp</dc:creator>
    <dc:date>2024-05-16T18:13:02Z</dc:date>
    <item>
      <title>Getting Data In: Platform - Wed 5/8/24</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-5-8-24/ec-p/681893#M90</link>
      <description>&lt;P&gt;&lt;A href="https://splunk.zoom.us/webinar/register/WN_Wlva1iIzTFa8C6aZ0DnBLA" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Register here.&lt;/STRONG&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;This thread is for the Community Office Hours session on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Getting Data In (GDI) to Splunk Platform&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;on&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Wed, May 8, 2024 at 1pm PT / 4pm ET.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Join our Office Hour series where technical Splunk experts answer questions and provide how-to guidance on a different topic every month! This is your opportunity to ask questions related to your specific GDI challenge or use case, including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;How to onboard common data sources (AWS, Azure, Windows, *nix, etc.)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Using forwarders&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Apps and add-ons to get data in&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Processing data with Edge Processor, Ingest Processor, and Ingest Actions&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Archiving your data&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Anything else you’d like to learn!&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please submit your questions at registration or as comments below.&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;You can also head to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;#office-hours&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;user Slack channel to ask questions (request access&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://splk.it/slack" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;here&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Pre-submitted questions will be prioritized&lt;/STRONG&gt;&lt;SPAN&gt;. After that, we will open the floor up to live Q&amp;amp;A with meeting participants.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Look forward to connecting!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2024 18:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-5-8-24/ec-p/681893#M90</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-05-16T18:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Getting Data In: Platform - Wed 5/8/24</title>
      <link>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-5-8-24/ec-p/687777#M98</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Here are a few questions from the session (get the full Q&amp;amp;A deck and live recording in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Q1:&amp;nbsp;Seeing bottlenecks in forwarder getting data into Splunk Cloud from syslog server, should output be pointed to multiple ports?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Check maxKBps setting in limits.conf&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Bottlenecks can sometimes be an indication of a need for an interim layer of forwarders (UF or HF) to help balance the load, especially if it fluctuates. This also will differ if you’re using (or not using) &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/4740/?_gl=1*xpqiv8*_ga*MTA0NDM5NjcwOS4xNzEzNDYxNTI3*_ga_GS7YF8S63Y*MTcxNTAwODMwNS4yOS4wLjE3MTUwMDgzMDUuNjAuMC4w*_ga_5EPM2P39FV*MTcxNTAxNDE4MC40Ny4xLjE3MTUwMTQ0OTMuMC4wLjE4MDU0OTE3MQ..&amp;amp;_ga=2.10895155.607030411.1715008059-1044396709.1713461527" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Splunk Connect for Syslog.&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;parallelIngestionPipelines could be leverage if output is the bottleneck.&amp;nbsp; For inputs, additional ports OR leveraging the forwarder reading local syslogs stored on the host can be leveraged for increasing throughput&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://lantern.splunk.com/Data_Descriptors/Syslog" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://lantern.splunk.com/Data_Descriptors/Syslog&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Pipelinesets#Forwarders_and_multiple_pipeline_sets" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Pipelinesets#Forwarders_and_multiple_pipeline_sets&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q2:&amp;nbsp;How can I extract additional fields from the "properties.log" field from AKS events sent to an EH (Azure Event Hub?) being ingested via MSCS app?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For individual fields, you can use the rex command or EXTRACT in props.conf.&lt;/LI&gt;&lt;LI&gt;To extract all fields, use the spath command.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Rex" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Rex&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Admin/Propsconf#:~:text=yellow%2C%20blue%2C%20red-,EXTRACT,-%2D%3Cclass%3E%20%3D%20%5B%3Cregex%3E%7C%3Cregex" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;EXTRACT&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Spath" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/SearchReference/Spath&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Q3:&amp;nbsp;How do I get Syslog, SNMP traps, Streaming Telemetry, and non-standard formats in?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;See the &lt;/SPAN&gt;&lt;A href="https://splunkbase.splunk.com/app/1537" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;SNMP Modular Input&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; app on splunkbase&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Common GDI methods: UF, API, DB Connect, or HTTP Event Collector&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Custom modular input or dedicated receiver&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;You probably will have to write your own props.conf settings&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Getstartedwithgettingdatain" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Getting Data In manual&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Send syslog via UF: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=XnCEZTKOm90" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=XnCEZTKOm90&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;SC4S overview: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=7ZmVgy9NL3U" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=7ZmVgy9NL3U&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Splunk Connect for syslog (SC4S): &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=iJ1iBZdXt2o" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=iJ1iBZdXt2o&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;How to connect SC4S in 5 mins: &lt;/SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=1Ur3xDNaE4s" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://www.youtube.com/watch?v=1Ur3xDNaE4s&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other Questions (check the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://splunk-usergroups.slack.com/archives/C0FRVF350" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;STRONG&gt;#office-hours&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Slack channel for responses):&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Preferred Getting Data In (GDI) method recommended by Splunk&lt;/LI&gt;&lt;LI&gt;Can we have master and slave Splunk Enterprise instances? Slave is connected always but master is connected only sometimes.&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Syslog forwarder setup&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Splunk license saving tips&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Splunk in 2030: Getting Data In (GDI) experience&lt;/LI&gt;&lt;LI&gt;I’d like to hear/watch how to ingest logs from Cisco devices switches/routers with IOS, usage of sc4s with IOS or maybe not using sc4s?&lt;/LI&gt;&lt;LI&gt;I would like to hear your thoughts on potential root cause for duplicate data coming from a single endpoint however each duplicate event has a different timestamp. Using TA-microsoft-graph-security-add-on-for-splunk&lt;/LI&gt;&lt;LI&gt;How do you charge based on resources if it is 100% on prem owned by the customer?&lt;/LI&gt;&lt;LI&gt;Splunk docs talk about Hybrid-Cloud to mean Splunk manages infrastructure and application at the indexer and above level. What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?&lt;/LI&gt;&lt;LI&gt;What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 16 May 2024 18:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Community-Office-Hours/Getting-Data-In-Platform-Wed-5-8-24/ec-p/687777#M98</guid>
      <dc:creator>adepp</dc:creator>
      <dc:date>2024-05-16T18:13:02Z</dc:date>
    </item>
  </channel>
</rss>

