Community Blog
Get the dispatch on the Splunk community!

This Week's Community Digest - Splunk Community Happenings [6.7.22]

sensitive-thug
Community Manager
Community Manager

Get the latest news and updates from the Splunk Community here!

This Week From Splunk Answers ✍️

Screen Shot 2022-02-18 at 2.21.47 PM.pngSplunk Answers is the place to get help, advice, and problems solved by your fellow community members. Starting topics takes a lot of work, time, and motivation - we totally get that! They create rich conversations and can lead to other related topics and information that help so many people learn more about using Splunk and solve critical issues with much less time. Guess how many members have started a whopping 100 topics just on their own? 52 people! Cheers to each and every one of you, as we give shout-outs below:

@canneebee13 , @vijaysri , @indeed_2000 , @sarit_s , @msarro , @hartfoml , @kteng2024 , @kiran331 , @yutaka1005 , @abhayneilam , @dbcase , @damode , @SamHTexas , @aditsss , @rakesh_498115 , @responsys_cm , @a212830 , @ips_mandar , @gcusello , @Jason , @melonman , @agoyal , @jiaqya , @realsplunk , @Hemnaath , @andrewtrobec , @zacksoft , @HeinzWaescher , @Lowell , @twinspop , @jwalzerpitt , @DataOrg , @harshal_chakran , @pavanae , @vrmandadi , @ddrillic , @nick405060 , @surekhasplunk , @sloshburch , @rbal_splunk , @jip31 , @maverick , @the_wolverine , @koshyk , @brent_weaver , @damucka , @robertlynch2020 , @daniel333 , @danielbb , @IRHM73 , @HattrickNZ , @ankithreddy777 

Upcoming User Group Events! 👏

Check out these upcoming user group events in June. Most meetings are hybrid or virtual, but we've got a bevy of in-person meetups going on now as well.

June Upcoming User Group Events:

  • Las Vegas User Group 6/15 - (In-person) [RSVPLIVE at .conf22- How to Start or Lead a Splunk User Group! For the first time, the community team will be offering an in-person session for those who want to start or lead a Splunk user group. In this session, formerly known as "Splunk User Group Leader Training," you will learn what it takes to be a Splunk User Group leader, along with the next steps in creating a Splunk User Group or joining an existing leadership team. This course is mandatory for anyone who intends to lead a Splunk User Group.
  • San Francisco User Group 6/16 - (Virtual) [RSVPIn this session, formerly known as "Splunk User Group Leader Training," you will learn what it takes to be a Splunk User Group leader, along with the next steps in creating a Splunk User Group or joining an existing leadership team. This course is mandatory for anyone who intends to lead a Splunk User Group, however, you are not required to become a leader after attending.
  • Pune User Group 6/23 - (Virtual) [RSVPPLA1446B- Data Onboarding: Best Practices and Troubleshooting Masterclass conf22 Session Review. Please join us on Thursday, June 23rd, 05:30 PM IST for Pune Splunk User Group meetup. We are going to talk about Data Onboarding: Best Practices and Troubleshooting. We would like to hear from you all about your experience during data on-boarding. 
  • Baltimore User Group 6/27 - (Virtual) [RSVP.conf Wrap Up! Let's review .conf, both virtual and in-person!

Search the full list of User Groups to find meetups in all locations. As we shift into more in-person meetups and/or hybrid, there are plenty of virtual opportunities for you to join!

ICYMI - New from the Community Blog & Product News & Announcements 🆕

Check out the most recent posts from the Community Blog:

  • What's Happening With Community @.conf22! Check out all that's going on with the Splunk Community at .conf22 this year!  .conf is our biggest event of the year and this time we're going hybrid! Learn what's happening at the Community Lounge, including BSides Splunk, our new community-driven video podcast "The SPLUG", the Splunk Love video booth, and highlights from SplunkTrust sessions, the BOSS games program, and more from the community.
  • Take the 2022 Splunk Career Survey for $25 in Amazon Cash! Help us learn about how Splunk has impacted your career by taking the 2022 Splunk Career Survey! This is a great opportunity for you to share insights into how you and/or your company use Splunk products to further business goals. 
  • New Resources for Upgrading Splunk Enterprise Time to upgrade your Splunk? Read the new “Upgrading Splunk Enterprise” Lantern how-to article in order to get help during your upgrade process.
  • Lighting Your way With This Month’s new Lantern Articles Hey Splunkers! Here’s your monthly Splunk Lantern update highlighting some of the top content we’ve published over the past month. 
  • How to create a Quick Highlighted map of States in Splunk Just enough SPL to highlight US states on a map! Learn about how the Blockchain & DLT team's project made a quick map of US States which would highlight their current location.

...And, the latest from Product News & Announcements:

Upcoming Tech Talk 🛠

On Thursday, June 9th, 10:00AM ET/ 3PM BST/ 4PM CEST, Splunk and Sens Consulting will be presenting this month's live Tech Talk: Security Edition titled, Maximize the value from Microsoft Defender with Splunk. See how to prepare the data in Microsoft Defender and collect and normalize it into the Vulnerability data model. Afterwards you will end up with a dashboard on a System Manager level - revealing the risks both in a specific system and across the organization. All of this is packed into a technical add-on which will be available for you. This talk will highly benefit Security Analysts & SOC Managers. Register here.

— Michelle Schlachta, Community + Content at Splunk

Get Updates on the Splunk Community!

Running multiple macros in the same search

Hi all!I'm trying to run multiple macros in the same search and eventually aggregate the results from each ...

tag as datamodel attribute

I'm confused a bit. I use CIM datamodels.The "tag" field is both a filter for choosing events applicable to a ...

Index with one sourcetype - search performance / best practices

Hello,I have created a few indexes, each containing data only from one source with one sourcetype.<BR />From a ...