splunk / splunk-connect-for-syslog

Splunk Connect for Syslog
Apache License 2.0
152 stars 108 forks source link

docs: update getting-started-splunk-setup.md #2417

Closed jenworthington closed 4 months ago

jenworthington commented 5 months ago

I can't quite figure out how the customer is supposed to use this. It reads as steps but they don't seem like actual guided tasks. Is it more of a best practices topic or an overview? Or if it is numbered steps/process, then maybe we add links to each step? I'd love to get your thoughts and maybe we can discuss in our 1:1

mstopa-splunk commented 5 months ago

hi @jenworthington sure, that's what this section is about:

Topic: how to setup your Splunk instance to work with SC4S

Steps:

  1. Create default indexes in Splunk
  2. Set up the Splunk HTTP Event Collector

These are the two things that must be done to ensure SC4S-Splunk connection.

Ad 1 Indexes You can use your custom set of indexes. But make sure that all of them, as well as the default set, are created in Splunk, else you will miss events processed by SC4S

Ad 2 HTTP event collector

mstopa-splunk commented 5 months ago

partially solves https://github.com/splunk/splunk-connect-for-syslog/issues/2358

mstopa-splunk commented 5 months ago

@jenworthington can you work on the new file docs/gettingstarted/getting-started-splunk-setup-new.md ? I will replace the old one with this one when we finish

mstopa-splunk commented 5 months ago

@rjha-splunk I left the file that you saw for reference for Jen, but please check docs/gettingstarted/getting-started-splunk-setup-new.md instead. It will replace the old one completely

jenworthington commented 5 months ago

Thanks for the new suggestions for structure, it was really helpful. I think I've captured all of the requested changes, take a look and let me know, happy to work on this one some more as needed.

mstopa-splunk commented 5 months ago

@jenworthington ready for the next iteration

mstopa-splunk commented 4 months ago

@jenworthington something went wrong and your changes to docs/gettingstarted/getting-started-splunk-setup.md from the last pass were not commited. I opened all previous comments again, please go through them and commit the final pass, I'm sorry for that situation

mstopa-splunk commented 4 months ago

@jenworthington ready for the final pass

srv-rr-github-token commented 3 months ago

:tada: This PR is included in version 3.27.0 :tada:

The release is available on GitHub release

Your semantic-release bot :package::rocket: