Amazon EMR & Splunk Analytics How-To guide for machine data in all kinds of sources & forms-sys logs, metrics, sensors, app logs, stored in Amazon S3 or Hadoop.
Splunk AppInspect available at .conf2016, an Apps tool for static & dynamic analysis, certification testing in s/w dev, available standalone or as RESTful API.
Custom searches for drilling down into data in your Splunk Cloud service; Total Ingestion Volume search over time, usage, volume by sourcetype & forwarder.
Hadoop, Hunk or Splunk users have a choice in time field settings, can pull data from csv files, use specific searches & filters to achieve usable data subsets.
Assisting customers with pre-req & integration steps for setting up ADFS-Active Directory Federation Services-SAML for Single Sign On with Splunk Cloud.
Splunk 6.3 users can use API to write modular alerts for apps-notifications, automation, info-gathering. See apps.splunk.com & the official docs for more info.
Answer for dealing with HTTP Event Collector (HEC) error message 413 content too large: reset configurable pre-defined limit for max content using limits.conf.