Yorkshire Splunk User Group - Splunk Health & The Importance of Use Case SIEM Onboarding.

Pre- and Post- event discussions for November's Meetup: Splunk Health & The Importance of Use Case SIEM Onboarding

As we prepare for November's exciting Yorkshire Splunk User Group event, featuring two talks on "Splunk Health" and "The Importance of Use Case SIEM Onboarding," let's gather our thoughts and experiences to enrich our upcoming discussions!

For those who have attended similar events or are familiar with Splunk's capabilities, what challenges have you faced in maintaining and monitoring Splunk health in your organisation? How have you successfully onboarded data to support SIEM use cases? Please share your insights, best practices, and any hurdles you've encountered along the way.

And if you're new to Splunk or considering deploying it within your systems, what are you hoping to learn from this event? Are there particular areas of Splunk or SIEM that intrigue you or that you're eager to understand better?

Feel free to share your thoughts, questions, and expectations. Let's engage in a conversation that will not only prepare us for the meetup but also help us grow as a community of Splunk enthusiasts!

2 comments

Hi, I'm relatively new to Splunk, and I'm keen to explore more about its capabilities on the SIEM side. I'm also looking to improve my skills in crafting effective search queries within Splunk. I thoroughly enjoyed meeting you and everyone else at the event. I'm already looking forward to attending the next one!

Thanks for coming everyone! Here are the links to the searches and other useful references from my talk:

All of the searches shown in the slides - https://docs.google.com/document/d/1mbIZ9maGnStu6oSh7zJP6Pdfr9VpHQNDhZINlFLVHo8/edit?usp=sharing 

What Splunk Logs About Itself - https://docs.splunk.com/Documentation/Splunk/9.3.2/Troubleshooting/WhatSplunklogsaboutitself 

tstats command - https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Tstats 

Splunk REST Endpoints Doc - https://docs.splunk.com/Documentation/Splunk/9.3.2/RESTREF/RESTlist