Register here. This thread is for the Community Office Hours session on Splunk Search on Wed, Dec 13, 2023 at 1pm PT / 4pm ET.
This special 1-hour session is your opportunity to ask questions related to your specific Splunk Search challenge, use case, best practices, or any new features/capabilities in search. Including:
Please submit your questions at registration or as comments below. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!
Hi everyone! Here are a few questions from the session (get the full Q&A deck and live recording in the #office-hours Slack channel):
Q1: Best practice to track 100k Global assets and identities across multiple SAAS sources?
Q2: Can I make a Splunk index I own available to other orgs or even be public facing?
Q3: What is the best approach for dealing with/extracting nested JSON objects?
Other questions (check the #office-hours Slack channel for responses):