Getting Data In

What are the best practices for Onboarding new machine data to ensure APM KPIs are captured and measured?

davebo1896
Communicator

Often when users want to bring their machine data into Splunk, they just want access to their logs so they don't have to (or are not allowed to) grep through them from the command line.

What are the best practices to drive the data onboarding interview process toward having these users identify the KPI metrics that can be obtained from the data?

Tags (1)
0 Karma
1 Solution

sloshburch
Ultra Champion

I say look at the work we've put into Data onboarding best practices for a Splunk deployment.

Step two may be what you're looking for. The key is to have everyone think about the use case, not just the data.

View solution in original post

sloshburch
Ultra Champion

I say look at the work we've put into Data onboarding best practices for a Splunk deployment.

Step two may be what you're looking for. The key is to have everyone think about the use case, not just the data.

davebo1896
Communicator

That is very helpful, thank you.

I've been thinking about trying to open up the conversation, moving away from just working through the data sources they are presenting to asking "What business decisions will you be making with this data?" This, in order to prompt more of a conversation about performance indicators and possibly bringing in associated data in order to tell more of a story. Less "This is a log I need to find things in it", More "Here is information that affects the business".
So yes, craft the Use Case, but spin it to get a deeper understanding of possibilities.

0 Karma

sloshburch
Ultra Champion

Yaay - thanks for the feedback!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...