top of page


My First 3 Splunk Queries: Finding the Loudest IP on the Network
I loaded 109,864 events into Splunk and went hunting for the noisiest host on the network. My first query found a suspect. My next two proved it innocent — and somewhere in the middle I realized I'd been writing this query language for ten years without knowing its name.
Aug 37 min read


The Install That Fought Back: Setting Up Splunk on a Mac
I set out to install Splunk Free and write a tidy walkthrough. Instead I hit four errors, discovered the tutorial was built for a machine that isn't mine, and had to force-restart my laptop — and learned more than a clean install ever would have taught me.
Jul 318 min read
bottom of page