This thread is for the Office Hours session Awesome Admins: Managing Your Splunk Cloud Deployment on Wed, June 14, 2023 at 1pm PT / 4pm ET.
Register Here to level up your Cloud Admin Chops! Join our new bi-weekly Office Hours zoom series where technical Splunk experts answer questions and provide how-to guidance on a different topic every month. This session is dedicated to Splunk Cloud Admins and will cover any topics or questions related to:
Please submit your questions below as comments in advance. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will go in order of the questions posted below, then will open the floor up to live Q&A with meeting participants. If there’s a quick answer available, we’ll post as a direct reply.
Look forward to connecting!
Hi Everyone!
Make sure you drop your questions/comments here for any topics you'd like to see discussed in the Community Office Hours session (you can also head to the #office-hours user Slack channel to ask questions and join the discussion - request access here).
Hi,
With the upcoming Splunk Cloud Developer edition, can you share any upcoming features upon release which will help with testing any admin changes or custom apps/add-ons before making the changes in a Splunk Cloud production environment? Are you able to share any information, such as the amount of test data we'd be allowed to ingest?
Many thanks,
Sam Clark
Hi Sam! Here's the Expert Solution from the session:
Here are some of the questions from the session:
Q1: I recently enabled and configured ACS, but I’m not sure the best way to get started from here. What are the different ACS tools/features I should look into that will give me the highest ROI on the time it’ll take me to configure?
Q2: So if the graph is showing as red during a specific time frame, will we know exactly what is being impacted if the performance is degraded? For example, would it be ingestion? Would it be search runtime? Would it be any specific things? Or is it just performance in general? It's kind of a um difficult thing to interpret.
Q3: Are there any best practices for managing large numbers of users in Splunk Cloud? E.g., if I want to grant varying access permissions to specific indexes, apps, and data sources?