Learn Data Onboarding with Splunk? Start with the Conf Archive!

So today in the Splunk Facebook group I was asked a fair enough question. "how do I get data in". It's funny how simple this question can seem to someone starting with Splunk but as you gain experience how loaded this question is.

Rather than try and write a 100 page blog about data management in Splunk, what I'd rather due is

Two talk that have been outstanding for my ability as a Splunk admin are here

Data Curator Here we see gamification and monitoring of the quality of your data. I am shocked not more people do this. Creates an outstanding checklist for doing it right.

Data Settings Here we go into details on managing the props.conf/transforms.conf and getting the data in. He makes it so simple.

But over thew years I've found these talks as well to be great.

Retention and Data Rolling Data Obfuscation Using Data Stream Processor Data Transformation with DSP Oh and by the way I got one of those fancy Twitters the kids have been talking about lately. Trying to keep that infosec oriented and my posts here Splunk oriented.

