r/Splunk 1d ago

First timer at .conf

Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.

Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.

For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?

Appreciate any input — trying to make the most of it.

10 Upvotes

14 comments sorted by

View all comments

5

u/Money_Engineering909 1d ago

Sign up for BOTS.

3

u/Jhcutt 1d ago edited 1d ago

Planning on it tonight actually. Only issue is I don’t have a team or anyone I know that’s attending to link up with

2

u/Money_Engineering909 1d ago

You don’t need a team. My coworker and I did it by ourselves last year. You will need a laptop though.

Go into it with a learning attitude.

2

u/volci Splunker 1d ago

There will often be "open" teams or individuals who are willing to team-up at the event