<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241472#M46839</link>
    <description>&lt;P&gt;Y'all need to put more smileys in your posts to help us old geezers know you were joking.  Geez.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Plus I am cleaning up a duplicate comment and am slightly rearranging the remaining, since they were responses to one another.&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2016 14:20:15 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2016-11-18T14:20:15Z</dc:date>
    <item>
      <title>What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241464#M46831</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I am trying to build a workflow for our new Splunk product and want to know what top three regular daily tasks you may do in Splunk Enterprise. This includes anything in regards to ES administration as well and maintenance tasks.&lt;/P&gt;

&lt;P&gt;If anyone has suggestions, I would certainly appreciate your feedback. This new environment has 5 indexers in a cluster, three search heads in a cluster and several heavy forwarders with a ton of data sent via forwarders. Comments anyone?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 18:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241464#M46831</guid>
      <dc:creator>brian1_tate</dc:creator>
      <dc:date>2016-11-17T18:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241465#M46832</link>
      <description>&lt;P&gt;@brian1_tate - When you say "ES" are you referring to the app "&lt;A href="https://splunkbase.splunk.com/app/263/"&gt;Splunk Enterprise Security&lt;/A&gt;"? Because that is usually what "ES" refers to. Please clarify, thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 18:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241465#M46832</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-11-17T18:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241466#M46833</link>
      <description>&lt;P&gt;That's correct but in general, I wanted to get people's feedback on what daily/weekly tasks they perform as I am transitioning from ArcSight to Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 19:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241466#M46833</guid>
      <dc:creator>brian1_tate</dc:creator>
      <dc:date>2016-11-17T19:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241467#M46834</link>
      <description>&lt;P&gt;Answer questions on why shouldn't we use ELK/open-source...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 20:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241467#M46834</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-11-17T20:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241468#M46835</link>
      <description>&lt;P&gt;That's not relevant here. All I'm looking for is general procedural steps for those that use Splunk Enterprise with ES as a SIEM. I have those for ArcSight but after working with a larger Splunk environment, frankly the largest I have ever encountered - one would have them or develop them. So in this case, I am developing them based upon my own experiences and based upon those that others may use in day to day operations. &lt;/P&gt;

&lt;P&gt;If you just say, I use Splunk - best wishes in justification of your career...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 22:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241468#M46835</guid>
      <dc:creator>brian1_tate</dc:creator>
      <dc:date>2016-11-17T22:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241469#M46836</link>
      <description>&lt;P&gt;It's a joke.  Lighten up Francis. &lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 03:42:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241469#M46836</guid>
      <dc:creator>a212830</dc:creator>
      <dc:date>2016-11-18T03:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241470#M46837</link>
      <description>&lt;P&gt;So, most of what I do is set up alerts to advise me about potential issues, for ES this has included:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Sources no longer sending data ( &lt;CODE&gt;| tstats max(_indextime) where ...&lt;/CODE&gt; or similar is very useful here)&lt;/LI&gt;
&lt;LI&gt;Users exceeding there quota (disk quota, search quota), often this is harmless but sometimes I review the limits to see if they are   appropriate.&lt;/LI&gt;
&lt;LI&gt;Check for badly written/long running searches via the monitoring console (this one is more a manual task for now).&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;There would be many other potential things on a daily basis, one thing I do try to do is review the error logs...&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 07:19:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241470#M46837</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-11-18T07:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241471#M46838</link>
      <description>&lt;P&gt;Don't call me Francis . &lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=IMtvnAmfuf8"&gt;https://www.youtube.com/watch?v=IMtvnAmfuf8&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 14:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241471#M46838</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-11-18T14:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: What do Splunk Ninjas think are the top three daily Splunk tasks in a large distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241472#M46839</link>
      <description>&lt;P&gt;Y'all need to put more smileys in your posts to help us old geezers know you were joking.  Geez.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Plus I am cleaning up a duplicate comment and am slightly rearranging the remaining, since they were responses to one another.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 14:20:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-Splunk-Ninjas-think-are-the-top-three-daily-Splunk-tasks/m-p/241472#M46839</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-11-18T14:20:15Z</dc:date>
    </item>
  </channel>
</rss>

