Posts

Populating Splunk Asset Lookups with TA-LDAPSearch

Formatting LDAP Identity Data for Splunk Enterprise Security

Tuning Assets and Identities in Enterprise Security

First-Time Setup of Splunk Enterprise Security: Data Models, CIM, and Taming the Noise

Gitignore for Deployment Server

The First Time I Broke All the Dashboards: Lessons in Field Normalization

Best Practices for Keeping inputs.conf Organized in Shared Environments

Heavy Forwarders vs Indexers: Where Should Parsing Happen?

Managing Source Types Across Teams Without Losing Your Sanity

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

Using nullQueue to Drop Logs at Index Time Without Touching the Source