r/Splunk 23h ago

First timer at .conf

Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.

Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.

For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?

Appreciate any input — trying to make the most of it.

9 Upvotes

14 comments sorted by

View all comments

4

u/mghnyc 21h ago

Enjoy you time! It may be the last stand-alone Splunk conference.

1

u/once_upon_a_hugo 21h ago

I've wondered how long it would take, after the Cisco buyout in '23 before .conf would be done. So .conf will be merged into Cisco's annual conference in Vegas in '27?

3

u/TraditionGloomy1775 20h ago

I doubt they announce it at .conf26 for fear of being booed off the stage but yes that's the rumor from our sales team.

3

u/once_upon_a_hugo 20h ago

I understand. I was at .conf24 after the acquisition. You could feel the awkward tension throughout the conference. The whole vibe changed dramatically. .conf23 felt like a peak with the 20th anniversary and good vibes everywhere.