Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

iamryan
Community Manager
Community Manager

Xnip_07-02-2025_02-26-PM.jpg

Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 offers a wealth of opportunities to sharpen your skills and streamline your workflows. From platform upgrades and data federation to AI assistants and SPL mastery, there's something here for every admin at every level.

With over 200 sessions in the full catalog, we’ve handpicked six standout sessions tailored specifically for Splunk Platform Administrators—organized by experience level to help you focus on what matters most.

 

Novice-Level Sessions: Start with Strong Fundamentals

 

PLA1317 – Splunk AI Assistants in Action: A Hands-On Deep Dive
September 9 | 12:30–1:30 PM EDT
Come get hands-on experience with all three of Splunk’s AI Assistants! In this workshop, we'll provide real-world use cases you can plug into your daily workflows, streamlining your operations and helping you become a Splunk Ninja. Curious how these assistants work? In addition to practical use cases, we’ll also peek under the hood to see how they operate and why we believe they outperform other AI tools. Walk away ready to put Splunk AI to work!

Note: This is an Interactive Workshop Session. Please bring your own laptop to dive into product use cases, walk through real scenarios and demo as you go. Attendance is capped based on content and sessions will not be recorded.

PLA1271 – 30 SPL Commands in 90(ish) Minutes
September 10 | 2:30–4:30 PM EDT
For anyone who writes or edits searches, one of the hardest problems is just having basic familiarity with the various commands available. Also, knowing when not to use a specific command can save a lot of headaches. From "append" to "xyseries," we’ll take a quick tour around the 30 most common and useful commands in SPL. We’ll show you what each one does, when to use it, and when to avoid certain commands. If time permits, we'll also cover some bonus material!

Note: This is an Interactive Workshop Session. Please bring your own laptop to dive into product use cases, walk through real scenarios and demo as you go. Attendance is capped based on content and sessions will not be recorded.

Intermediate Sessions: Boost Efficiency and Stay Ahead

 

PLA1270 – Administrator's Anonymous Speed Run: Improve Your Splunk Experience in 15 Minutes or Less
September 9 | 10:30–10:50 AM EDT
You're a busy admin who demands the most from your Splunk environment. Join this no-nonsense talk led by one of our SplunkTrust experts and learn three Splunk tips to improve the performance, efficiency, and health of your Splunk environment in less than the time it takes to order lunch.

PLA1535 – Upgrading to Splunk Platform 10
September 9 | 4:15–5:00 PM EDT
Have you been putting off upgrading to 10? We get it, but you gotta. In this session, we’ll go over the great new features in this version of Splunk Enterprise and Splunk Cloud 10, how to tell if you’re impacted by any major changes, and what to do to prepare for a seamless update.

PLA1275 – A Deep Dive Into SPL2: How Does It Actually Compare to SPL?
September 10 | 1:30–2:15 PM EDT
"""SPL + scripting language concepts + (optional) SQL = SPL2!"" Sure, that's a nice catchphrase. But how does SPL2 actually compare to SPL? What's in SPL2 that isn't in SPL, and why should you care? Join this session to go deep into SPL2 and its capabilities for everyone from analysts to developers. Learn about its syntax modes (SPL and SQL), functions, data types, imports and namespaces, lambda expressions, and the problems they solve across multiple Splunk streaming and search tools.

PLA1968 – Edge Processor on Splunk Enterprise 101
September 9 | 2:15–3:15 PM EDT
Whitepapers and docs can only take you so far when evaluating potential solutions — eventually, you'll have to get your hands dirty. Come experiment with the various out-of-the-box metrics that Edge Processor emits and see how it can address your data management needs.

Note: This is an Interactive Workshop Session. Please bring your own laptop to dive into product use cases, walk through real scenarios and demo as you go. Attendance is capped based on content and sessions will not be recorded.

Explore More

Want the full list of admin-focused sessions?
These six picks are just the beginning. There are several sessions curated specifically for the Admin Learning Path—covering everything from upgrades and SPL to data federation and AI.
View all Admin Learning Path sessions

Ready to build your full agenda?
Check out the full .conf25 session catalog and filter by role, product, or learning level to find even more content that’s right for you.

Looking to grow beyond .conf?
Explore the Admin Community Learning Path to access curated year-round content and keep your Splunk skills sharp long after the conference ends.

Let’s make .conf25 your most impactful conference yet.

Security threats won’t wait—and neither should you.

Register Now

Contributors
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...