- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
I was wondering if any of you knew of a Splunk simulator (where I could upload a CSV and check my searches without having to create an entire testing environment/run tests on production data).
Thank you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Splunk is very versatile and configurable, so a universal simulator might not work for every case. There is a data preview available within Splunk to make sure events get broken correctly before you add a new input. Other than that, I'd setup a test instance with a dev license that has the same apps as your production, that way you know if it will work or not.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Splunk is very versatile and configurable, so a universal simulator might not work for every case. There is a data preview available within Splunk to make sure events get broken correctly before you add a new input. Other than that, I'd setup a test instance with a dev license that has the same apps as your production, that way you know if it will work or not.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks a lot, I'll try to do a data preview tonight!
