Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

What's Happening With Community @.conf22!

Splunk Employee
Splunk Employee

.conf is our biggest event of the year and this time we're going hybrid! You can either join remotely (June 14-15) or see us in Las Vegas (June 13-16). Visit to register for .conf22 and check out the Session Scheduler to make your best plan to hit all of your favorite sessions. We've got 256 to choose from this year, along with keynotes and super sessions!

conf blog post 1.jpg

New This Year at the Community Lounge!

The Community Lounge is going hybrid so you can connect with the community in Vegas or online.

BSides Splunk will be returning to .conf with a "Best of BSides Splunk", which will have its own mini-theater in the Community Lounge! While it is not all reruns, we will be hosting two new talks. One on Tuesday, 6/14 at 11 am ("Maximizing Splunk: Let's Build a Data Source Monitoring Utility" with Ryan Wood and the other on Wednesday, 6/15 at 10:30 am ("Using API calls Maps+ to more quickly locate and compare Supports to Bad Actors inside of PATCh"). Come see live streams and live presentations of technical deep dives ("all tech, no fluff.") given by members of the Splunk Community. There will also be a few fun, new features during BSides breaks. Is your brain a little fried from hard-core .conf-ing? Stay tuned for a schedule of some quick mindfulness sessions! Oh, and BSides Splunk will open their Call for Papers as .conf22 ends. Check them out at

A new community-driven video podcast will also be started at .conf22. The SPLUG Podcast is hosted by Caroline McGee, Michael Camp Bentley, and Tony Reinke. Their first episode will feature Bryan Jennewein.  

And, don't miss the Splunk Love video booth at the lounge. Step inside and share your #splunklove by telling us what you love about Splunk and why, your favorite Splunk hero moment, or your best piece of advice to help newbies nail it. We'd love to know it all, including your favorite .conf22 moment thus far. We'll also have some snazzy Splunk pillows and beach balls to give away there, too 😀.

Connect at .conf22 With Community Events

Community Slack

  • Chat in real-time with other community members in our Splunk Community Slack and network with other .conf22 attendees in the #conf22 channel!


  • The members of the SplunkTrust are our top contributors to the Splunk Community, and we are excited for their 26 SplunkTrust-led sessions at .conf22! These sessions are ideal for the Splunk builders - the people using Splunk products every day to turn visibility into action.
  • Are you ready to get your data in? SplunkTrust member Rohit Joshi, along with Gauri Bansode, will share best practices and troubleshooting tips to onboard your data in PLA1446B. Add in PLA1107B from SplunkTrust member Steve Koelpin and colleague Konrad Biegaj to learn ways to automate your log onboarding.
  • Now you can get visibility by analyzing your data! New to Splunk? SplunkTrust member Rich Mahlerwein will get you started exploring your data with PLA1422B. Looking for ways to expand visualizations beyond Splunk? Learn about getting your data to where your executives live in SplunkTrust member Mary Cordova’s session, PLA1122B.
  • Are you automating your tasks in response to security incidents? SplunkTrust member Greg Rivas will help you apply container lifecycle techniques to your Splunk SOAR playbook creation in session SEC1266B.  SplunkTrust member Mhike Funderburk will help you build your Splunk SOAR playbooks faster with strategies to manage custom code and a few tools available on Splunkbase in session SEC1216B.

BOSS: BOO & BOTS Competitions at .conf22!

  • Check out our BOSS games program at .conf22 and learn how you can improve your Splunk game with experts! Played individually or in teams of up to four, Boss of Ops and Observability (BOO) and Boss of the Security Operations Center (BOTS) require participants to pivot through realistic data sets using Splunk Enterprise and the entire Splunk product portfolio. Boss of Ops and O11y (BOO) and Boss of the SOC (BOTS) are the best places to put your skills to the test and learn from Splunk experts. Regardless of your Splunk ability, whether you're new to Splunk or a self-appointed expert, you’ll spend time working through fun problems while networking with your peers. For BOTS, register here, and for BOO register here. The competition date is June 13th, 6 pm PST (doors open at 6 pm, kick-off is 6:30 pm, and the competitions start at 7 pm). To participate in BOSS onsite you must be registered for .conf22 Las Vegas. The competitions are open to anyone who registers and are able to be played anywhere you are located. You will connect with the live participants and coaches via Twitch and Slack.

Community Programs for you to Join


  • Check out our Answers section of the Splunk Community, where our members support each other, share knowledge, help each other learn, and connect through all of our community programs. Splunk Answers is a core community product and is the place to get help, advice, and problems solved by your fellow community members.

Splunk User Groups

  • Stay engaged with your local Splunk Community throughout the year by starting or leading a Splunk User Group. Stop by the Community Lounge for an info session to learn more. Share your learnings, build your networks, learn from peers, and find mentors in User Groups! Wherever you are, there’s a group nearby to lift you up and carry you off to Splunk success. Meetings are currently virtual, hybrid, and in-person so you can join a user group in any part of the world!


  • Your ideas come to life with Splunk’s Ideas program. Customers and partners can submit feedback and ideas related to new and improved Splunk features that actually become a part of the product! We are continually releasing updates addressing new ideas, and also have more improvements currently in development or on the roadmap.
We can't wait to see you at .conf22, especially this year being so unique in that you can choose to join virtually or in-person!
— The Splunk Community Team
Tags (1)
Get Updates on the Splunk Community!

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...