<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112655#M7403</link>
    <description>&lt;P&gt;Hello Experts,&lt;/P&gt;

&lt;P&gt;I know very little about splunk :(. Our only splunk expert decided to quit and i have been asked to take the responsibility starting with enterprise administration. Is referring to splunk admin manuals/documentation enough to start? &lt;BR /&gt;
I mean is it 100% knowledge base or just to get you to speed?&lt;BR /&gt;
Sorry if it sounds silly . I am running in 1000 directions right now &lt;/P&gt;

&lt;P&gt;Any help is much appreciated.&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2014 04:50:01 GMT</pubDate>
    <dc:creator>Raghav2384</dc:creator>
    <dc:date>2014-09-05T04:50:01Z</dc:date>
    <item>
      <title>What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112655#M7403</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;

&lt;P&gt;I know very little about splunk :(. Our only splunk expert decided to quit and i have been asked to take the responsibility starting with enterprise administration. Is referring to splunk admin manuals/documentation enough to start? &lt;BR /&gt;
I mean is it 100% knowledge base or just to get you to speed?&lt;BR /&gt;
Sorry if it sounds silly . I am running in 1000 directions right now &lt;/P&gt;

&lt;P&gt;Any help is much appreciated.&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 04:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112655#M7403</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-09-05T04:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112656#M7404</link>
      <description>&lt;P&gt;Hi @Raghav2384&lt;/P&gt;

&lt;P&gt;How little is little exactly? If you haven't really used Splunk before, going straight into the admin manual might be a big jump. I'd suggest going through the Search Tutorial on the Splunk documentation page (&lt;A href="http://docs.splunk.com/Documentation"&gt;http://docs.splunk.com/Documentation&lt;/A&gt; ) first which will help you get started with understanding Splunk and its many features, just to touch the surface. &lt;/P&gt;

&lt;P&gt;Do you know what version of Splunk you are running?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 05:10:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112656#M7404</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-09-05T05:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112657#M7405</link>
      <description>&lt;P&gt;Hi ppablo, i have experience in building reports,dashboards, alerts, knowledge objects and installed splunk free and edited conf files on a tiny scale setup (used 4 laptops - 2 having forwarders etc) . i haven't done administration at all. Example: I know indexer and how it  is a full splunk ent version but don't know how to disable features like 'use it only for indexing but not searching'. Basically, i am reading all different manuals without knowing the practical way of doing it. Any help would be great. My ADHD situation is making it worse :(.Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 05:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112657#M7405</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-09-05T05:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112658#M7406</link>
      <description>&lt;P&gt;Additionally to ppablo_splunk comment my second step would be to check my splunk health status using different apps:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;&lt;A href="http://apps.splunk.com/app/748/"&gt;SOS&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;&lt;A href="http://apps.splunk.com/app/1632/"&gt;Fire brigade app&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;&lt;A href="http://apps.splunk.com/app/1850/"&gt;Forwarder health app&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;&lt;A href="http://apps.splunk.com/app/1848/"&gt;Data curator app&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If you have a large distributed deployment i would have a dedicated search head only for those apps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 05:37:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112658#M7406</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2014-09-05T05:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112659#M7407</link>
      <description>&lt;P&gt;it sounds like you need to get an understanding of what your current deployment looks like, and to review this manual, starting with this topic:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/LearnhowtoadministerSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/LearnhowtoadministerSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;once you have reviewed this, you can move on to learning about the different roles/components of Splunk:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;at that point, you should be able to start asking specific questions (after first searching in the docs of course :)). this site (Answers) is much better suited to specific questions. &lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 06:02:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112659#M7407</guid>
      <dc:creator>piebob</dc:creator>
      <dc:date>2014-09-05T06:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112660#M7408</link>
      <description>&lt;P&gt;Hi @Raghav2384&lt;/P&gt;

&lt;P&gt;In that case, I think going through the suggested documentation referenced by @piebob would be a good place to start since you're familiar with the basics. The apps suggested by @MarioM (and many other apps) will definitely be worth checking out once you have a better grasp on your role and knowledge as an admin. Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 06:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112660#M7408</guid>
      <dc:creator>ppablo</dc:creator>
      <dc:date>2014-09-05T06:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112661#M7409</link>
      <description>&lt;P&gt;Thank you!!!! Really appreciate your help.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 14:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112661#M7409</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-09-05T14:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112662#M7410</link>
      <description>&lt;P&gt;Thank you ppablo! Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 14:31:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112662#M7410</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-09-05T14:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112663#M7411</link>
      <description>&lt;P&gt;Thank you Mario!Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 14:32:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112663#M7411</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2014-09-05T14:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112664#M7412</link>
      <description>&lt;P&gt;You know more than I did when I became Splunk in-house "expert" (as I say to people I "went from zero to SME in the space of 5 days").  This is not to dismiss your concerns.  Quite the contrary.  I want to give you confidence that it is achievable very quickly.  For the most part I would (as the others have said) learn the shape of your actual Splunk infrastructure.  I had help, in that I was guided through a new set of installations by one of the previous admins, and I would say that a test installation (which you can afford to break and start from scratch), and a bit of tinkering will get you a long way.&lt;/P&gt;

&lt;P&gt;Other than that I would suggest that you use the &lt;A href="http://docs.splunk.com/"&gt;documentation&lt;/A&gt; (the online manual), the &lt;A href="http://wiki.splunk.com/"&gt;Wiki&lt;/A&gt;, and &lt;A href="http://answers.splunk.com/"&gt;"Answers"&lt;/A&gt; as reference material, and for anything else you genuinely cannot find solutions for or which confuse you ask here.  It's not as daunting as it may seem.&lt;/P&gt;

&lt;P&gt;(Personally I don't recommend Splunk-on-Splunk, but that is because I have a personal prejudice about adding secondary packages like the third-party side utils SoS is dependent on.  If you can frame a Splunk query, you can understand pretty much everything you need to from Splunks own "_*" indexes for yourself, and besides it is a good didactic exercise doing so and learning what you can find in there.)&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2014 21:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112664#M7412</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-09-05T21:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: What resources are recommended if I've been made a Splunk administrator, but know very little about Splunk?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112665#M7413</link>
      <description>&lt;P&gt;I went through same phase with 1 hour introduction to Splunk by manager, he sent me an e-mail to access splunk web, logs locations related to oracle Middleware WebLogic SOA suite, database and operations document(runbook).&lt;BR /&gt;
After that I came home and installed splunk 5. Read Splunk docs to understand it better.&lt;BR /&gt;
Splunk quickly expanded all over the world.&lt;BR /&gt;
Reading Splunk answers helped me a lot.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Dec 2015 22:23:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/What-resources-are-recommended-if-I-ve-been-made-a-Splunk/m-p/112665#M7413</guid>
      <dc:creator>koppolu17</dc:creator>
      <dc:date>2015-12-28T22:23:45Z</dc:date>
    </item>
  </channel>
</rss>

