<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What to do after getting data in splunk cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757780#M4154</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new at splunk, i am a little stuck in my implementation...&lt;/P&gt;&lt;P&gt;I have configured the HF and i am receiving data in splunk cloud, i understand that i need to normalize the data i receive so i could get statistics and create dashboards, but i want to know if there are templates for normalizing data or something like this...&lt;/P&gt;&lt;P&gt;For example i have 2 cisco firepower NGFW and the logs are been received in spluk cloud, as you know there are hundreds of syslog ids, so if i have to do it manually i will take too much time to analize and normalize all the logs,,, so is there an automatic way to do this?.. and obviusly i need to do this is for all the infraestructure that i manage on my datacenter..&lt;/P&gt;&lt;P&gt;Hope somebody can guide me with this,&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jan 2026 20:00:57 GMT</pubDate>
    <dc:creator>jphvpichi</dc:creator>
    <dc:date>2026-01-29T20:00:57Z</dc:date>
    <item>
      <title>What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757780#M4154</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new at splunk, i am a little stuck in my implementation...&lt;/P&gt;&lt;P&gt;I have configured the HF and i am receiving data in splunk cloud, i understand that i need to normalize the data i receive so i could get statistics and create dashboards, but i want to know if there are templates for normalizing data or something like this...&lt;/P&gt;&lt;P&gt;For example i have 2 cisco firepower NGFW and the logs are been received in spluk cloud, as you know there are hundreds of syslog ids, so if i have to do it manually i will take too much time to analize and normalize all the logs,,, so is there an automatic way to do this?.. and obviusly i need to do this is for all the infraestructure that i manage on my datacenter..&lt;/P&gt;&lt;P&gt;Hope somebody can guide me with this,&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 20:00:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757780#M4154</guid>
      <dc:creator>jphvpichi</dc:creator>
      <dc:date>2026-01-29T20:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757785#M4155</link>
      <description>&lt;P&gt;There are apps for that.&amp;nbsp; Someone else has done the work for you and published it in apps.splunk.com.&amp;nbsp; Search for "Cisco Firepower" and check out the "add-on" offerings.&amp;nbsp; Add-ons perform field extraction and normalization (among other things).&amp;nbsp; Install the add-on of your choice on your stack and that should set the fields right.&lt;/P&gt;&lt;P&gt;Do the same for a Firepower app.&amp;nbsp; Apps contain dashboards and other analysis objects.&lt;/P&gt;&lt;P&gt;Be sure to read the docs for each add-on and app you install.&amp;nbsp; Each may make assumption about the data or your environment and you'll want to make sure to allow for those assumptions.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 20:50:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757785#M4155</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-01-29T20:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757786#M4156</link>
      <description>&lt;P&gt;Hi, thanks for your help,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only to confirm, the app will perform (normalization and field extraction) automatically or do i need to do something (besides install the app)?&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 20:53:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757786#M4156</guid>
      <dc:creator>jphvpichi</dc:creator>
      <dc:date>2026-01-29T20:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757787#M4157</link>
      <description>&lt;P&gt;Hi, thanks for your help,&lt;/P&gt;&lt;P&gt;Only to confirm, the app will perform (normalization and field extraction) automatically or do i need to do something (besides install the app)?&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 21:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757787#M4157</guid>
      <dc:creator>jphvpichi</dc:creator>
      <dc:date>2026-01-29T21:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757789#M4158</link>
      <description>&lt;P&gt;The add-on *should* do extraction and normalization automatically, but read the docs.&amp;nbsp; The add-on may expect a specific sourcetype name or may only be compatible with certain version of the vendor's product.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2026 21:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757789#M4158</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-01-29T21:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757804#M4159</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry to bother you!!&lt;/P&gt;&lt;P&gt;I am kind of lost with this... i have installed severall apps, but i don't know what to do...&lt;/P&gt;&lt;P&gt;for example right now i have firepower logs and windows dhcp logs, i do search for both of them and found some patterns,, but i don't know what to do next, i mean maybe i think this works automatically, and when i install the app it will do everything for me.. (there is no real documentacion for the apps that i have installed, it only says what is the purpose but no more details)..&lt;/P&gt;&lt;P&gt;I understand (maybe i am wrong) that everything is based on searchs.. but what can i done with the search results?.. and where i will go next..&lt;/P&gt;&lt;P&gt;i read several splunk docs, but maybe i didn't catch the steps/procedure after i got the data into splunk, i understand i need to normalize, but as you said the app will do it for me,, and i don't see that and obviusly i don't see any analitics, if i go to statistics i see "Your search isn't generating any statistic or visualization results." and have this options: pivot, quick reports, search commands.&lt;/P&gt;&lt;P&gt;hope you could help me guiding me...&lt;/P&gt;&lt;P&gt;best regards and thanks in advance..&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 13:55:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757804#M4159</guid>
      <dc:creator>jphvpichi</dc:creator>
      <dc:date>2026-01-30T13:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757805#M4160</link>
      <description>&lt;P&gt;Have you completed any of the free training offered by Splunk?&amp;nbsp; There are many, including an intro to Splunk, how to use fields, how to extract fields, and how to do statistical analysis.&amp;nbsp; Find them &lt;A href="https://www.splunk.com/en_us/training/course-catalog.html?sort=Newest&amp;amp;filters=filterGroup1FreeCourses" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp; They may help answer some of your questions.&lt;/P&gt;&lt;P&gt;Installing add-ons can help with automatic field extraction, but not always.&amp;nbsp; As I mentioned before, t&lt;SPAN&gt;he add-on may expect a specific sourcetype name or may only be compatible with certain version of the vendor's product.&amp;nbsp; If there is no documentation then you'll have to read the add-on's props.conf file to see what it's trying to do.&amp;nbsp; This could be a challenge for a neophyte, but at the very least, the stanza names in props.conf should match &lt;FONT face="courier new,courier"&gt;sourcetype&lt;/FONT&gt; settings in your inputs.conf files.&amp;nbsp; Without a match, the props settings will not be applied.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As for what to do with search results, the usual thing to do is refine the search.&amp;nbsp; A first search often returns too much information or doesn't correlate events as needed so additional SPL commands need to be added to get the desired output.&amp;nbsp; To use the Statistics tab, your query must contain a statistics command (stats, timechart, or chart).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may also find some of the Splunk documentation helpful&lt;BR /&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/search/search-tutorial/10.2/introduction/about-the-search-tutorial" target="_self"&gt;Search Tutorial&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.2/search-overview/get-started-with-search" target="_self"&gt;&lt;SPAN&gt;Search Manual&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 15:46:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757805#M4160</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-01-30T15:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: What to do after getting data in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757811#M4161</link>
      <description>&lt;P&gt;thank you very much for your help and guidance!!&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2026 17:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/What-to-do-after-getting-data-in-splunk-cloud/m-p/757811#M4161</guid>
      <dc:creator>jphvpichi</dc:creator>
      <dc:date>2026-01-30T17:23:40Z</dc:date>
    </item>
  </channel>
</rss>

