Dataonboarding
Dataonboarding
Starting Your
Splunk Journey –
Get Your Data In
PLA1906C
Ben Marcus
Sr. Staff IT Engineer | Qualcomm
Forward- During the course of this presentation, we may make forward‐looking statements regarding
future events or plans of the company. We caution you that such statements reflect our
Looking current expectations and estimates based on factors currently known to us and that actual
events or results may differ materially. The forward-looking statements made in the this
Statements presentation are being made as of the time and date of its live presentation. If reviewed after
its live presentation, it may not contain current or accurate information. We do not assume
any obligation to update any forward‐looking statements made herein.
In addition, any information about our roadmap outlines our general product direction and is
subject to change at any time without notice. It is for informational purposes only, and shall
not be incorporated into any contract or other commitment. Splunk undertakes no obligation
either to develop the features or functionalities described or to include any such feature or
functionality in a future release.
Splunk, Splunk>, Data-to-Everything, D2E and Turn Data Into Doing are trademarks and registered trademarks of Splunk Inc. in the United States
and other countries. All other brand names, product names or trademarks belong to their respective owners. © 2020 Splunk Inc. All rights reserved
© 2020 SPLUNK INC.
Ben Marcus
Sr. Staff IT Engineer | Qualcomm
https://www.linkedin.com/in/heybigben
© 2020 SPLUNK INC.
6. Modular Inputs
What are you going to do with the data Max length (truncation)
Remote Syslog
Easiest for appliances and devices where you can’t run the Universal Forwarder directly
Check
Timezones
© 2020 SPLUNK INC.
Indexers
Windows Data
Splunk UF on Windows Splunk Docs - Windows UF
App has special input to pull/obtain data from cloud or via app API
REST API modular input – obtain data via remote application REST endpoint.
Cloud Connectors
AWS Azure GCP
Splunk app AWS Splunk Add-on for Microsoft Splunk Add on for Google
Kinesis Firehose Cloud Services, Cloud
(sends directly to Splunk HEC) Splunk Add-on for Office 365 Splunk HEC
Splunk Universal Forwarder Splunk HEC
Any
Machine
Data
© 2020 SPLUNK INC.
SESSION SURVEY