
Splunk Series: Feeding Data to Splunk
How Splunk ingests data — input, parsing, and indexing phases — plus supported sources: files, network data, scripts, Windows logs, and HTTP events.
Posts

How Splunk ingests data — input, parsing, and indexing phases — plus supported sources: files, network data, scripts, Windows logs, and HTTP events.

Run Splunk field searches using key/value pairs, AND/OR/NOT operators, meta fields, and the Selected vs Interesting Fields sidebar to narrow results.

What Splunk does and the data sources it ingests — logs, configs, network devices, scripts — so security and ops teams can analyze machine data.

Save and share Splunk search jobs: default 10-minute lifetime, extending to 7 days, scheduling reports, and setting Private vs Everyone permissions.
Splunk SPL syntax breakdown — search terms, commands, functions, arguments, and clauses — plus the search pipeline and how to build tables from fields.

Splunk deployment models — standalone vs distributed — plus the supporting components: Deployment Server, Cluster Master, and License Master.

Build a PCNSE study lab — get a PA-VM auth code, download the OVA, deploy on ESXi, and wire it into an existing home network alongside an ASA edge.

Palo Alto PCNSE exam breakdown — the five domain weights, recommended EDU-210/EDU-220 training, and what to expect on the 75-question certification.

Hands-on Cisco Viptela SD-WAN video lab covering Zero-Touch Provisioning (ZTP) with vManage, vBond, and vSmart controllers onboarding a vEdge router.

Cisco SD-WAN (Viptela) components explained — vManage, vSmart, and the path from IWAN to a software-defined WAN with overlay and underlay networks.