I am looking for ideas from Splunk users who provide services of Splunk to their internal customers in the organization.
Do you have/can you share an on-boarding form/document/excel template that covers input parameters needed for -
- simple log on-boarding
- DB Connect
- HTTP Event Collector
- or any other apps.
With this document, you will have persistent on-boarding data that you get from your internal customers.
Thank you in advance!
-Data Gov (is it usefull, what is the coast)
-Writing to twiki SMEs, Owner, etc
-Sending sample data
-Chosing index, sourcetype, entitlements
-Applying best practice to onboard
-Pushing to prod
-Monitoring
File monitoring is the easiest and very good. HTTP collector is good but not as mature. If possible stay away from syslog unless you know what you are doing
Feel free to ask details