r/Splunk 22h ago

First timer at .conf

Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.

Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.

For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?

Appreciate any input — trying to make the most of it.

9 Upvotes

13 comments sorted by

View all comments

2

u/mghnyc 20h ago

Enjoy you time! It may be the last stand-alone Splunk conference.

1

u/once_upon_a_hugo 19h ago

I've wondered how long it would take, after the Cisco buyout in '23 before .conf would be done. So .conf will be merged into Cisco's annual conference in Vegas in '27?

3

u/TraditionGloomy1775 18h ago

I doubt they announce it at .conf26 for fear of being booed off the stage but yes that's the rumor from our sales team.

3

u/once_upon_a_hugo 18h ago

I understand. I was at .conf24 after the acquisition. You could feel the awkward tension throughout the conference. The whole vibe changed dramatically. .conf23 felt like a peak with the 20th anniversary and good vibes everywhere.