Splunk documentation team gets motivation & energy from Splunk community, feedback makes it great & better; now announcing docs.splunk.com with new design & nav
Using Splunk Light (free up to 500MB), to monitor docker environments w/o cloud, 2 Data Volume Containers, ports: 8000 web access, 9997 data fm forwarders.
Splunk App for ES has Content Profile Audit dashboard that compares knowledge objects to data models, which Add-ons prepare data for; Reports use REST query.
Use Splunk to track Case Objects & metrics like case time to closure, open cases, use Splunk App for Salesforce & Salesforce SOQL query, poll 500-1000 records
Define use cases for fraud-categorize & prioritize; data & its threshold & algorithm rules, index data using Splunk SPL (search processing language) in realtime
Separate content w/ tabs in dashboards, activate tabs for searches by clicking-preventing over-showing or executing too much content at once, faster load times
New twist to extract/translate/load process (ETL) is Splunk & DB Connect, moving data fm DB to Splunk to Indexer machines; Create reports w/o knowing SQL & more