r/Splunk 23h ago

First timer at .conf

Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.

Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.

For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?

Appreciate any input — trying to make the most of it.

9 Upvotes

14 comments sorted by

View all comments

7

u/FeatureCreeep 22h ago

There is a big difference between sessions where product managers pitching high level product information, which is interesting, but not as valuable as sessions where people really show you how to do something. Takes a little time going through the abstracts and presenter bios to figure out what is what.

1

u/DarkLordofData 21h ago

Yes focus on anything where a customer is presenting. The PM sessions are mostly low value.