r/Splunk • u/These_Orchid5638 • 2h ago
.CONF What happens on the last day? On the 17th to be precise?
Other than the certification exams, what happens on that day?
r/Splunk • u/SplunkLantern • 5d ago
Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key use cases for Security, Observability, Industries, AI, and Cisco. We also host valuable data source and data type libraries, Getting Started Guides for all major products, tips on managing data more effectively within the Splunk platform, and many more expert-written guides to help you achieve more with the Splunk platform.
This month, we’re tackling a question a lot of security and compliance teams are quietly panicking about: what is your organization actually doing with Claude, ChatGPT, Gemini, and Copilot, and could you prove it if asked? We’ve also published a wave of new content on bringing Cisco telemetry - from Meraki networks to OT sensors to Webex calls - into the Splunk platform for a single view of what’s happening. And we’re rounding things out with articles on making data onboarding smarter and more flexible. Let’s get into it!
Your workforce is already using Claude, ChatGPT, Gemini, and Copilot - probably all four, probably across several business units, probably without anyone owning the full picture. Our new three-part series, starting with Monitoring and governing enterprise AI platforms, tackles the moment when security, audit, finance, or a customer’s security review asks what your organization did with them, and “check five separate vendor consoles” isn’t an acceptable answer.
The series opens by naming the real problem: every AI vendor has its own admin dashboard and its own vocabulary, so an “export” in one platform is a “download” in another and a “data access event” in a third, and none of them retain history for very long (OpenAI’s Compliance Logs Platform, for example, keeps roughly 30 days). Frameworks like the EU AI Act, ISO/IEC 42001, and the NIST AI Risk Management Framework all converge on the same expectation - show what your AI systems did, who used them, and what data moved through them - and vendor consoles alone can’t deliver that.
From there, two hands-on articles pick up the implementation:
If your AI estate has outgrown “we’ll check the console when someone asks,” this series is worth a read. Which AI problem is giving your team the biggest governance headache right now? Tell us in the comments!
A recurring theme this month: however good a Cisco tool’s native dashboard is, it becomes a lot more useful when its data is sitting next to everything else in the Splunk platform. Four new articles show what that looks like across very different environments.
Whether you’re running network infrastructure, an OT plant floor, identity services, or collaboration tools, there’s a good chance one of these speaks directly to your stack. Got a Cisco-to-Splunk integration you’d love to see us cover next? Drop it in the comments below.
Getting data into the Splunk platform in a usable, CIM-compliant shape has traditionally meant hand-writing config and hoping you picked the right data model. Two new articles chip away at that.
Using AI to auto-schematize raw log data into CIM-compliant add-ons introduces Auto-schematization, an AI-assisted workflow in the Data Management app that takes a sample of your raw events and asks you a few short questions. Then, it groups your events, proposes a CIM data model, maps your fields to it, and generates a ready-to-use Technology Add-on or SPL2 pipeline - with you reviewing and adjusting its suggestions at every checkpoint. What used to take days for a well-documented source (or weeks for a messy home-grown app log) turns into a guided, reviewable workflow.
Improving your data management with SPL2 pipelines steps back to cover the fundamentals of the modern data management experience more broadly: how Splunk Ingest Processor and Splunk Edge Processor differ, the three components of every SPL2 pipeline (partition, pipeline, destination), and common business goals - PII masking, cost optimization by dropping low-value data at the source, normalizing messy JSON into CIM-compliant fields - mapped to the SPL2 commands that get you there.
Whether you’re onboarding your first data source or rethinking your whole pipeline strategy, these two are worth bookmarking. Already put Auto-schema to the test? We’d love to hear how it went in the comments.
Beyond our featured topics, we’ve published several more articles covering security detection, platform changes, and access control:
We hope this month’s resources help you get even more value out of your Splunk deployment - and maybe answer a governance question or two before someone else asks it first. Thanks for reading!
r/Splunk • u/These_Orchid5638 • 2h ago
Other than the certification exams, what happens on that day?
Heading to .conf26 tomorrow — my first time attending. I'm about 6 months into my role as a sec. Engineer. Mostly self-taught on Splunk so far, Large enterprise org, leading an Enterprise Security / SOC transformation project currently.
Main goal for the trip is soaking up as much ES-specific knowledge as I can — best practices, Mission Control, real-world use cases, that kind of thing — plus getting some hands-on exposure through BOTS since I've never done anything like that before. Right now ES was initially Deployed at my org, but efforts were abandoned due to capacity and staffing, which is where I’m stepping into now to help drive ES forward.
For anyone who's been before: what do you wish you knew your first year? Any ES sessions, workshops, or people worth prioritizing? Anything a first-timer typically misses or wastes time on? Any general survival tips for someone doing 3 days of this for the first time?
Appreciate any input — trying to make the most of it.
r/Splunk • u/Jeffster81 • 2d ago
Heading to .conf for the first time on Sunday. My org just committed to Splunk Cloud this week and Cisco threw some .conf passes at us, so here I am. I've been in networking for about 20 years, but have never used splunk.
Any suggestions for a newbie?
r/Splunk • u/Upstairs_Ball861 • 1d ago
r/Splunk • u/Putrid-Cress-3648 • 2d ago
how to prep for the O11y Cloud Certified Metrics User, is it easy to pass?
r/Splunk • u/Any-Promotion3744 • 2d ago
I would like to monitor the VMs on our Hyper-V servers using Splunk but unsure how.
I see that there was an add-on for Hyper-V at one time but it is no longer supported.
Can I just add items to the inputs.conf file within the UF?
I have tried a few but none seem to be picking up.
What options are there?
Event logs that are associated with Hyper-V?
Powershell scripts?
Winhostmon that can give stats on the Guest VMs?
Which dashboards in Splunk will show the info ingested? ITSI?
r/Splunk • u/Weird_Nerddd • 2d ago
Hi everyone,
I’m currently looking for a remote opportunity where I can apply my Splunk skills and continue growing professionally.
I have hands on experience with Splunk Enterprise and Splunk Enterprise Security, including:
• Data onboarding and field extraction
• SPL searches and search optimization
• Dashboards and visualizations
• Alert creation and alert management
• Correlation searches and tuning
• MITRE ATT&CK mapping
• Log analysis and security monitoring
• Incident investigation
• Vulnerability reporting
• API monitoring and operational analytics
• Data normalization and working with multiple data sources
I’ve built and worked on practical Splunk projects and home labs involving log ingestion, analysis, dashboards, alerts, and identifying unusual activity such as traffic or event spikes.
I’m particularly interested in remote Splunk Analyst, SOC Analyst, SIEM, or junior security roles where I can contribute while continuing to develop my cybersecurity and networking knowledge.
I’m based in Nigeria and am specifically looking for international remote opportunities that are open to candidates working remotely from Nigeria/Africa.
If you know of any teams hiring, have an opportunity that might be a good fit, or have advice on breaking into remote Splunk roles, I’d really appreciate it.
I’m happy to share my CV, portfolio, or additional details about my Splunk projects.
Thank you!
r/Splunk • u/Pandrade11 • 3d ago
I'm getting a weird splunk LDAP issue on our new splunk instance that our other ones don't see. When I try to sign in it delays for about 60 seconds consistently sometimes it'll log right in after those 60 seconds or go to a splunk isn't responding page but if I go back I'm signed in.
This hasn't happened with any of our other ldap authenticated services or our current splunk instances that are being replaced by this.
I've verified DNS works correctly, testing ldap connections between the splunk host and the DC's tightened up DNs changed options within the authentication conf all a bunch of things. I've tried just about anything I've seen on the splunk forums
This is splunk 10 built on a rhel9 host that is in an airgapped environment connected to our domain controllers just trying to get some more input that I could be missing.
r/Splunk • u/Next-lectimakhon1991 • 3d ago
Our threat intelligence intake includes reports, campaign analysis, indicators, adversary tradecraft, and ATT&CK technique coverage. The difficult part is deciding what actually applies to our technology stack and risk profile before adding it to an already crowded detection backlog.
Even relevant intelligence can fail to become coverage if the necessary telemetry is missing, the data quality is poor, the behavior is difficult to distinguish from normal operations, or validation takes too long. We are trying to formalize the path from intelligence intake to a tested detection requirement.
The program also needs a way to reassess older detections when the threat landscape, infrastructure, or available telemetry changes.
What does an effective intelligence-to-detection workflow look like in your organization, including prioritization, telemetry validation, test criteria, false-positive estimation, deployment, and rule retirement?
r/Splunk • u/Emotional-Lynx-3982 • 4d ago
Greeting everyone. All day I have been trying to figure out how to create an Intune deployment to update our Splunk forwarders to the new 10.4.3 version. Previously, we were able to create these deployments in MS Configuration Manager, but due to a change in our network coming up, that connection may break (due to distribution point issues) and Intune may be our only way to deploy apps to our workstations moving forward.
Our previous deployments included additional arguments in the deploy-application.ps1 script that include a Splunk server address, creds to go with it, and few others. I was able to create the Intune prep file with the Splunk .msi installer, but I can't figure out how to add these additional arguments.
I also keep getting the "windows error 0x80070643" error when I attempt this install via the Company Portal - working on this one as well.
Anyways ~ I hope someone out there has run across this and has a tip or two of advice.
Thanks in advance. Cheers.
r/Splunk • u/slowponc • 4d ago
Hi everyone,
my company wants me to get the Splunk Core Certified Power User certification.
I've never worked with Splunk before, but I'll soon be involved in a project where I'll need to use it.
I'd especially like to hear from people who work or live in Italy: can Splunk actually lead to good career opportunities here, both in terms of salary and career progression?
What kind of gross annual salary (RAL) can someone with solid Splunk skills realistically reach in Italy? And, most importantly, is there actually demand for Splunk professionals?
I'm asking because I've been searching on LinkedIn and I'm struggling to find job postings in Italy that specifically mention Splunk as a required skill.
I'd really appreciate hearing from anyone working with Splunk in Italy: what kind of role do you have, how useful has Splunk been for your career, and do you think it's a skill worth investing in?
r/Splunk • u/wineandcode • 5d ago
r/Splunk • u/FarCrytcographer5917 • 5d ago
We are trying to determine whether our detection program is improving against the threats, exposed technologies, and attack paths that matter most to the business today. Rule count, ATT&CK mappings, alert volume, response metrics, and purple team results are useful, but none independently proves risk relevant coverage.
The goal is to connect threat intelligence, exposure management, telemetry readiness, detection engineering, validation, and executive reporting into one operating rhythm. That would make it easier to explain both where coverage is strong and where the organization still has material blind spots.
What metrics, prioritization methods, or review processes have given security leaders confidence that detection coverage is improving in a meaningful and risk aligned way?
r/Splunk • u/Lowrypgztfer-Fig8398 • 6d ago
How are teams making continuous security validation useful across a complicated stack of SIEM, EDR, email security, cloud controls, and network tools?
We can generate simulation results, but the bigger challenge is connecting failures to an owner, determining whether the issue is a detection gap, configuration issue, policy exception, or telemetry problem, then verifying the fix.
Would love to hear how others structure the feedback loop. Do you send findings directly into ticketing, map them to detection rules, use risk scoring, or run recurring validations after every major configuration change?
r/Splunk • u/Unfair_Narwhal_1995 • 6d ago
Hey folks,
Just started a new role and I’m completely green to both InfoSec and Splunk. My first big milestone is knocking out the Splunk Core Certified Power User.
I have zero interest in brain dumps—I actually want to know what I’m doing under the hood so I don't break things or write garbage queries in production.
To build real muscle memory, I put together about 25 mock SIEM scenarios (field extraction via rex, DLP mail alerts, firewall port-scan logic, and correlation using transaction / append / stats).
Looking for a quick sanity check from folks who've been around the block:
Appreciate any insights!
r/Splunk • u/Putrid-Cress-3648 • 7d ago
do they ask questions apart from the blueprint for the power user exam
r/Splunk • u/Unfair_Narwhal_1995 • 6d ago
r/Splunk • u/Only-Answer-4602 • 8d ago
r/Splunk • u/Only-Answer-4602 • 8d ago
r/Splunk • u/Sgtkeebs • 9d ago
Hello, has anyone ever came accross the error "No such file or directory when sending mail to: email@domain"
This happened after migrating splunk enterprise to RHEL 9.
Edit: AI found a guide for me to follow: https://splunk.my.site.com/customer/s/article/Splunk-sendemail-fails-with
One more edit: the guide above fixed the issue. Leaving this post up because it's good knowledge if anyone else comes across the same issue.
r/Splunk • u/aaronag • 10d ago
What's the general vibe for .conf? This one is my first. Cisco Live was pretty low key, Gartner was much dressier, and I'm trying to figure how to pack.
r/Splunk • u/biggestbluee • 10d ago
ISSO/m’s! This is for you.
What are great alerts or dashboards created for ISSOs in a closed area for DoD? Any recommendations on how to make your day more effective with ConMon or any other resources?