Getting Data In: Platform - Wed 5/8/24

Community Office Hours

Getting Data In: Platform - Wed 5/8/24

1 Comment
Cover Images - Office Hours (11) copy.png
Published on ‎03-25-2024 11:49 AM by Splunk Employee | Updated on ‎05-16-2024 11:13 AM

Register here. This thread is for the Community Office Hours session on Getting Data In (GDI) to Splunk Platform on Wed, May 8, 2024 at 1pm PT / 4pm ET.

 

Join our Office Hour series where technical Splunk experts answer questions and provide how-to guidance on a different topic every month! This is your opportunity to ask questions related to your specific GDI challenge or use case, including:

  • How to onboard common data sources (AWS, Azure, Windows, *nix, etc.)
  • Using forwarders
  • Apps and add-ons to get data in
  • Processing data with Edge Processor, Ingest Processor, and Ingest Actions
  • Archiving your data
  • Anything else you’d like to learn!

 

Please submit your questions at registration or as comments below. You can also head to the #office-hours user Slack channel to ask questions (request access here)

 

Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.

 

Look forward to connecting!



0 Karma
adepp
Splunk Employee

Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel):

 

Q1: Seeing bottlenecks in forwarder getting data into Splunk Cloud from syslog server, should output be pointed to multiple ports?

Q2: How can I extract additional fields from the "properties.log" field from AKS events sent to an EH (Azure Event Hub?) being ingested via MSCS app?

Q3: How do I get Syslog, SNMP traps, Streaming Telemetry, and non-standard formats in?

 

Other Questions (check the #office-hours Slack channel for responses):

  • Preferred Getting Data In (GDI) method recommended by Splunk
  • Can we have master and slave Splunk Enterprise instances? Slave is connected always but master is connected only sometimes.
  • Syslog forwarder setup
  • Splunk license saving tips
  • Splunk in 2030: Getting Data In (GDI) experience
  • I’d like to hear/watch how to ingest logs from Cisco devices switches/routers with IOS, usage of sc4s with IOS or maybe not using sc4s?
  • I would like to hear your thoughts on potential root cause for duplicate data coming from a single endpoint however each duplicate event has a different timestamp. Using TA-microsoft-graph-security-add-on-for-splunk
  • How do you charge based on resources if it is 100% on prem owned by the customer?
  • Splunk docs talk about Hybrid-Cloud to mean Splunk manages infrastructure and application at the indexer and above level. What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?
  • What is the definition of a full cloud environment (not Hybrid). Can everything from the UF all the way be managed in the cloud by Splunk for large org?