Of course there are different approaches to support. I haven't used Splunk's support myself (I work for a partner and usually it's the customer who contacts the support if all else fails) so can't share my experiences with it. But. Well, Splunk Enterprise as such is a platform. A platform that can be used for many different things. By comparison, you can't expect to set up a MSSQL server, give access to an SQL client to your employers and expect that they fully utilize its capacities, you can't expect that people who don't understand SPL and how the apps work and so on will be proficient Splunk power users. That's why it's typical for Splunk installation to have power users who can do many things on their own and also ordinary users who use preinstalled apps to get predefined reports and that's it. Just as with your typical RDBMS your users don't interact with the database itself but have some applications on top of it. If you want to learn, there's plenty of resources out there. The forum users here are helpful if they can answer the question. But as with any such voluntarily-provided help, you won't get far with demanding attitude 😉 But if your local Splunk environment doesn't have anyone to properly take care of it... well, that's mostly your internal problem and I'd strongly advise that you get some help from either Splunk's PS or your local Splunk partner if you don't have skilled people in-house. For the bugs, there's support. And no, end user is not the same as customer. Sorry, but that's how it works. As with practically every IT solution I know and I've ever deployed, you have a pre-defined list of people who are entitled to call the support. Why? Because support costs money. I suppose Splunk could offer your company a service with virtually unlimited number of people entitled to call support and file cases but that would cost so much that noone in their sane mind would pay it.
... View more