Activity Feed
- Posted Mastering Data Pipelines: Unlocking Value with Splunk on Splunk Tech Talks. Thursday
- Posted The Latest Cisco Integrations With Splunk Platform! on Splunk Tech Talks. Thursday
- Posted Holistic Visibility and Effective Alerting Across IT and OT Assets on Splunk Tech Talks. Wednesday
- Posted Re: SOC Modernization: How Automation and Splunk SOAR are Shaping the Next-Gen Security Team on Splunk Tech Talks. Wednesday
- Posted Re: Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud on Splunk Tech Talks. Wednesday
- Tagged Leverage Cisco Talos Threat Intelligence Across Splunk Security Products on Splunk Tech Talks. 2 weeks ago
- Tagged Unlock the Power of Your Splunk Data on Splunk Tech Talks. 2 weeks ago
- Tagged Get More Out of Your Security Practice With a SIEM on Splunk Tech Talks. 2 weeks ago
- Posted Re: What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience on Splunk Tech Talks. 3 weeks ago
- Tagged Take Your Breath Away with Splunk Risk-Based Alerting (RBA) on Splunk Tech Talks. 4 weeks ago
- Tagged Generative AI for SPL -- Faster Results on Splunk Tech Talks. 4 weeks ago
- Tagged Adoption of RUM and APM at Splunk on Splunk Tech Talks. 4 weeks ago
- Tagged Streamline Data Ingestion With Deployment Server Essentials on Splunk Tech Talks. 4 weeks ago
- Tagged Introducing Edge Processor on Splunk Tech Talks. 4 weeks ago
- Tagged New Enhancements with Splunk Enterprise 9.1 on Splunk Tech Talks. 4 weeks ago
- Tagged Admin Your Splunk Cloud, Your Way on Splunk Tech Talks. 4 weeks ago
- Tagged Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security 7.2 on Splunk Tech Talks. 4 weeks ago
- Tagged Enhancing Security Operations With Automated Threat Analysis on Splunk Tech Talks. 4 weeks ago
- Tagged Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework and Splunk on Splunk Tech Talks. 4 weeks ago
- Tagged Understanding Generative AI Techniques and Their Application in Cybersecurity on Splunk Tech Talks. 4 weeks ago
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 | |||
0 | |||
0 | |||
0 | |||
0 | |||
0 |
Thursday
In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with mitigating costs related to processing, storing, and accessing it. Join this Tech Talk to learn how Splunk can help you unlock the value of your security and observability data by building an effective data management strategy. Understand how Splunk’s approach to federated data management can help you maximize the value of data. Build effective pipelines using our latest SPL2-powered data processing capabilities to collect, transform and route data based on your business needs. Run effective searches on data in Amazon S3 without having to ingest or index data into Splunk. Happening on Thursday, May 8, 2025 | 11AM PDT / 2PM EDT. Enroll here.
... View more
Thursday
Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve been working on solutions for integrating product lines like Meraki and UCS, as well as tools like ThousandEyes and Catalyst Center, helping organizations enhance visibility, strengthen security, and drive resilience. In this session will provide insights into optimizing performance, streamlining operations, and gaining deeper insights into your infrastructure. Don't miss out on this opportunity to learn how Cisco and Splunk are revolutionizing IT and security operations. Event Date: Thursday, April 24, 2025 | 11AM PDT / 2PM EDT Register here.
... View more
Wednesday
Instead of effective and unified solutions, they’re left with tool fatigue, disjointed alerts and siloed teams. By leveraging Tenable and Splunk, organizations can achieve a more proactive and resilient security posture across their entire IT and OT infrastructure. Join this Tech Talk to learn how to gain complete visibility into all hosts and their potential vulnerabilities, misconfigurations and unpatched components in a single analytics platform, adding Tenable asset and exposure risk context improves alert prioritization and joint customers use Splunk for Centralized Reporting. Happening on Monday, April 21, 2025 | 11AM PDT / 2PM EDT. Register here.
... View more
Wednesday
Wondering What's next? Watch the SOC Modernization: How Automation and SOAR are Shaping Next-Gen Security Teams Tech Talk Here are a few more resources you might find helpful: Training Courses: Splunk SOAR Evolved: A Unified TDIR Approach to Automation Blog Introducing Wayfinder: Simplify Your Navigation in Splunk SOAR Blog The Essential Guide to SOAR Splunk SOAR Guided Product Tour
... View more
Wednesday
What's next? Watch the Ask It, Fix It: Faster Investigations with AI Assistant in Observability Cloud Tech Talk Here are a few more resources you might find helpful: Web Page REPAY Customer Story From Chaos to Clarity - GenAI E-book Blog Technical Blog - Building an AI Assistant.
... View more
3 weeks ago
Here are a few top of mind questions from the live Tech Talk: Q: How do I test compatibility of my apps with Python 3.9? A: The Splunk beta containing Python 3.9 connected with OpenSSL3 is out. Please sign up for the Beta and access the Splunk binary that you can use to test your apps against the Python 3.9 runtime environment. Q: Will this Splunk base app for forwarder upgrade work with older versions of Splunk enterprise? A: Yes, you can use all supported DS versions. Please note that the version of UF matters. The Remote Upgrader for Linux Universal Forwarders is supported on Universal Forwarder version 9.0 and higher. The oldest version from which you can upgrade your Universal Forwarder using the Remote Upgrader is 8.0. Q: Where can I learn more about the Remote UF upgrade feature? A: You can learn more by checking out these resources: https://docs.splunk.com/Documentation/Forwarder/1.0.0/ForwarderRemoteUpgradeLinux/About https://splunkbase.splunk.com/app/7699 Q: Can we run Splunk Enterprise 9.4 in Container/Kubernetes cluster? Meaning running Search Head and Indexer cluster in Kubernetes cluster? A: Yes. Splunk Operator for Kubernetes 2.7.0 is the first version to support Splunk 9.4.0. For more details please refer to the SOK documentation and the release compatibility matrix. Q: How is the new persistent queuing different from the existing persistent queue mechanism? A: It is the same mechanism but in output, which makes it much easier to work with scenarios like connectivity loss to cloud without blocking ingestion (when the collection design doesn't allow to block it) and routing to multiple destinations where one destination fails but not the other). Q: How will automated rolling upgrades work with Splunk Operator for k8s and its containers? A: The Operator will be upgraded one pod at a time in a rolling fashion. It might have some performance impact, but Splunk will be online all the time. There's no need for a maintenance window. Please refer to this document for more details. Q: Since we just deployed Splunk 9.2 can we expect the python automatic installation along with the Splunk version? A: Yes, on deploying Splunk 9.2, you can expect the Python runtime environment getting automatically installed. With Splunk Enterprise 9.2, Python 3.7 is the default Python interpreter. Q: According to the documentation: stats command v1 is deprecated, so, do I need to modify all my existing searches that are using stats command? A: You do not need to modify any existing searches. Stats v2 was activated by default after ensuring parity with stats v1. Q: Is SPL2 available in on-premise deployments? A: The SPL2 for app development is in public beta in Splunk Enterprise, and is available in the Edge Processor on-prem beta. Q: Is there any movement on dashboards that require no login? A: Yes, we call it “view” dashboard without login and it is already shipped in the Splunk Cloud v9.3.2411 release. It will be available in Splunk Enterprise v9.5. Q: Is there anything new with the SOC operations with this version of enterprise, meant for more under the security posture option? A: Please review Splunk Enterprise Security 8.0.2 Release Notes. Q: AI-powered suggestions to help you write SPL queries more effectively? A: Write SPL is one of the most used skills in Splunk AI Assistant for SPL. This skill allows you to specify the intent of your query in natural language and have it converted to an SPL query that is ready to execute. We even have a personalization option, that if turned on, understands your environment and writes queries that are tailor made to your environment. Q: Is there a roadmap to support Splunk enterprise for ARM based instances? A: We are exploring this capability and are partnering closely with a select group of design partner customers, but do not have any announcements to make at this time. If this is something you are looking for in your environment, please raise this with your account team and ask them to bring to the Product leads. Q: Why is it a difficult issue to install Splunk Enterprises on any OS with ARM64, aarch64? A: Beyond needing builds that are compiled for ARM, the larger issue is the 3rd-party application ecosystem. Many apps have dependencies on x86-based libraries and packages. So there is work to do to make the 3rd-party app ecosystem ARM-ready. Q: What is the plan for metrics indexes? I have heard that they are being deprecated. Are they a viable option long term? A: While there are currently no plans for deprecation, no new updates are planned in the near term for metrics indexes. Q: Splunk remote upgrader is a great feature. Do we have any idea on when it will also be available for Windows (Only Linux right now)? A: Splunk Remote Upgrader for Windows is in progress, stay tuned for more information very soon. Q: Are there any improvements for the license manager for large scale deployments? A: The licensing team is currently investigating a number of LM performance improvements, especially in large deployments, however none are available as of 9.4 or the following release. Q: Is this just for App Development still or is SPL2 available for search as well? A: It is only App Development for now. Stay tuned for more updates on use for general search & reporting, that is on the roadmap. Q: When will the KV store upgrade support custom certificates? A: We are currently working on a fix and planning to release the fix in a Splunk 9.4.x maintenance release soon. Q: Will dashboard studio support JS / Custom visualizations? A: We are currently developing the custom visualizations feature for Dashboard Studio. Feel free to post any additional questions or comments.
... View more
03-06-2025
11:50 AM
Now Available on Microsoft Azure On Demand Now Step boldly into the AI revolution with enhanced security and visibility for your hybrid cloud environments with Splunk on Azure. We are excited by the benefits of adding greater flexibility to how our customers deploy Splunk and bring unified security and observability solutions to keep your mission-critical systems secure and reliable. In this Tech Talk we will explore how Splunk’s Unified Security and Observability Platform on Microsoft Azure accelerates detection, investigation, and response enabling digital resilience. We’ll dive into the top use cases of Splunk on Azure cloud migration and Splunk AI integrations with Microsoft Co-pilot – helping customers successfully navigate the ever-increasing threat landscape. On Demand here
... View more
Labels
03-04-2025
12:10 PM
Security automation is no longer a luxury but a necessity. Join us to learn how Splunk ES and SOAR empower SecOps to automate time-consuming workflows, orchestrate investigations, enhance threat detection, and speed up response times. Discover how an automation-first approach to security operations helps teams stay ahead of sophisticated adversaries and adapt to evolving techniques and threats. Watch Tech Talk here:
... View more
Labels
03-04-2025
12:07 PM
Join us in this Tech Talk and learn about the recently launched AI Assistant in Observability Cloud. With this new GenAI-powered experience, Splunk users can easily extract insights in Splunk Observability Cloud and accelerate their investigations simply by asking questions using natural language. Watch On Demand In this session, we’ll go over: An overview of the AI Assistant and its main functionalities Best Practices for AI Assistant: when and how to use it effectively A demo covering monitoring and troubleshooting examples Dial in and discover how to unleash the power of your data, reduce mean time to resolution, and drive operational excellence with Splunk AI Assistant in Observability Cloud.
... View more
Labels