[EMEA-friendly: 10am ET / 3pm GMT] - Register here and ask questions below. This thread is for the special 1-hour Community Office Hours session on Getting Data In (GDI) to Splunk Platform on Wed, December 6, 2023 at 7am PT / 10am ET / 3pm GMT
This is your opportunity to ask questions related to your specific GDI challenge or use case, including:
Please submit your questions at registration or as comments below. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!
Hi everyone! Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel):
Q1: Is there any best practice to reduce firewall logs drastically? There are options with other tools, but what Splunk can do?
Q2: Splunk forwarder with more than one outputs: when one of the outputs becomes unavailable, all outputs stop working. Is this bad config?
Experts also cover some troubleshooting suggestions, important things to keep in mind, and other important question to address before answering this question
Q3: Is it possible to send masked data to an index in Splunk, and unmasked data to another destination?