Posts

Showing posts with the label splunk

Standard Deviation of Volume Ingestion for Alerting Historical Volatility (Z-Score Method)

Splunk TCP Routing to Multiple Destinations

Managing Precedence in Splunk: Input Routing When Multiple Teams Share Ownership

Securing Splunk End-to-End with Custom Certificates

Populating Splunk Asset Lookups with TA-LDAPSearch

Formatting LDAP Identity Data for Splunk Enterprise Security

First-Time Setup of Splunk Enterprise Security: Data Models, CIM, and Taming the Noise

Gitignore for Deployment Server

The First Time I Broke All the Dashboards: Lessons in Field Normalization

Best Practices for Keeping inputs.conf Organized in Shared Environments

Heavy Forwarders vs Indexers: Where Should Parsing Happen?

Managing Source Types Across Teams Without Losing Your Sanity

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

Using nullQueue to Drop Logs at Index Time Without Touching the Source

When to Use EVAL, EXTRACT, and REPORT: Field Extraction Demystified

Routing Logs to Multiple Indexes with props.conf and transforms.conf

Consolidating a Multisite Splunk Cluster into a Single Site

Building a Proving Grounds Environment for Splunk Candidates

Modular Inputs That Don’t Make a Mess