Posts

Gitignore for Deployment Server

The First Time I Broke All the Dashboards: Lessons in Field Normalization

Best Practices for Keeping inputs.conf Organized in Shared Environments

Heavy Forwarders vs Indexers: Where Should Parsing Happen?

Managing Source Types Across Teams Without Losing Your Sanity

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

Using nullQueue to Drop Logs at Index Time Without Touching the Source

When to Use EVAL, EXTRACT, and REPORT: Field Extraction Demystified

Routing Logs to Multiple Indexes with props.conf and transforms.conf

Consolidating a Multisite Splunk Cluster into a Single Site

Building a Proving Grounds Environment for Splunk Candidates