Posts

Managing Source Types Across Teams Without Losing Your Sanity

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

Using nullQueue to Drop Logs at Index Time Without Touching the Source

When to Use EVAL, EXTRACT, and REPORT: Field Extraction Demystified

Routing Logs to Multiple Indexes with props.conf and transforms.conf

Consolidating a Multisite Splunk Cluster into a Single Site

Building a Proving Grounds Environment for Splunk Candidates

Modular Inputs That Don’t Make a Mess