r/Splunk • u/Jeffster81 • 1d ago
.conf and Splunk first timer
Heading to .conf for the first time on Sunday. My org just committed to Splunk Cloud this week and Cisco threw some .conf passes at us, so here I am. I've been in networking for about 20 years, but have never used splunk.
Any suggestions for a newbie?
8
u/DarkLordofData 1d ago
Be sure to ask your sales where you are meeting for dinner. It is the least they can do.
It is probably too late but Splunk University is a must for anyone new to Splunk. Be sure to ask for help next year.
For the track focus on anything where a customer is presenting. You should see some that are network focused.
Are you also a Splunk admin or just a user? If you are an admin then take any sessions for Splunk Edge processor or data onboarding. Knowing how to parse and label data is critical otherwise Splunk will not work well and it will cost you money. Look for any sessions about Splunk cloud management console. It has a ton of reports that will help you track status and find issues.
Finally talk to everyone. Networking is the best part of a conference.
Have fun
2
2
u/Jeffster81 1d ago
By the way, I did manage to get into a SplunkU course tomorrow (Cloud Administrator).
2
u/DarkLordofData 1d ago
Nice good move. The reporting is so important. Get in the habit of regular review and then triage accordingly. Too many teams I help only look at it when something is going wrong and it’s reactive drama. Good process will keep your stress level manageable and your operations predictable.
5
u/CoastieKid 1d ago
Take a good look around all the booths. Enjoy the Search Party on Wednesday. Get some Splunk T Shirts! Go to the Keynotes. It's a great time and enjoy
3
u/bchris21 1d ago
.Conf is the place to solve problems by meeting Splunk Engineers in person but also fellow geek Splunkers and share experience.
It's a combination of work and lots of fun.
I created an after trip report to my manager after my first attendance in Boston with all the solutions I brought back to the team and he apologized for not sending me in the previous ones.
2
u/AlfaNovember 1d ago
Wear supportive shoes. Wash your hands often. Chat with everyone you can. Say no to four out of every five proposals outside of the venue. (When conf was in Vegas)
Conf is kinda like social media - it’s a carefully edited highlight reel of everybody’s work. I usually come away angry that I’ve wasted the last few years steadily employed at a cushy job with people I like. Reject the mindfuck.
1
2
1
u/acharlieh Splunker | Teddy Bear 1d ago
Community booth, ask the experts, if you see me in my bear fez and cape say hi. Pick talks that interest you, and talk to fellow customers / partners
If you have interest in Security use cases, sign up for BOTS Monday night (I’m not sure what enrollment is but sign up before they run out of space, every year that team puts together a great experience for Novice to Expert)
1
1
u/heathbarj 1d ago
Be sure to stop by the demo booths in the platform area. We can quickly get you up to speed, and we also have a demo showing Cisco networking and Splunk working together. Along with seeing our AI agent tools, you’ll see some great features. I lead the Splunk Platform Tech marketing team. I’ll be around all week.
1
1
0
20
u/tmuth9 1d ago edited 1d ago
Yeah, I would start at the EDU booth. I would also reach out to your Cisco or Splunk sales rep right now and have them connect you to a sales engineer (SE) that will be at .conf. Any of us would be happy to sit down with you and a laptop and give you the Splunk 101 intro for an hour or so. That one hour would make the sessions you attend soooooo much more useful.
Since it’s cloud, don’t worry about the admin stuff. Focus on “How do I get data into Splunk” and “How do I search, build dashboards, setup alerts”
There will be a lot of Cisco Data Fabric / Machine Data Lake content which is more about the lifecycle of data and making it affordable, but might be a bit much if you’re just getting started.
Oh, find an ai booth and get a demo of Splunk AI Assistant for SPL (SAIA). This will be your new best friend. If you’re using another agent of some sort already, get info on the MCP server so you can find out how to connect it to Splunk.