> initializing blog_feed...

SPLUNKY BREWSTER

Technical dispatches from the trenches of Splunk, security, AI, and infrastructure.

33 posts // 79 tags // 2026 — 2014
PINNED

I Got Rick Rolled by Claude (And Here's the Proof)

I was live-streaming on TikTok, building out a content automation tool with Claude, when it dropped a helpful-looking link into our chat. I clicked it. Cue music…

ai fun rickroll claude livestream
WATCH THE VIDEO →
ai

ML Social: An AI-Powered Content Generation Platform

Check out more Machine Learning shorts on the Need-to-Nerd YouTube channel and subscribe for updates on AI, security, and data engineering content. ML Social is an AI content generation platform...

READ →
splunk

Threat Detection Automation

Overview This project automates threat detection instantiation or overhaul by first learning the unique data lake schema (all client environments are unique) and correlating that schema against a TTP framework...

READ →
splunk

So You're Connected to Splunk's MCP Server - Now What?

You got the proxy running. The green checkmark appeared. splunk_get_info came back with your instance version and a healthy status. Now you’re staring at a blinking cursor wondering what exactly...

READ →
gcp

Shrinking a GCP Boot Disk the Hard Way (Because There Is No Easy Way)

You can’t shrink a persistent disk in GCP. You can grow one in about 3 seconds, but shrinking? Google basically says “lol no.” So when I needed to take a...

READ →
splunk

Splunk MCP Server Setup and Troubleshooting

READ →
splunk

Connecting Splunk's MCP Server to Claude Code CLI: What Actually Worked (and What Didn't)

READ →
splunk

Migrating Splunk to SmartStore with GCP: A Field Guide

Migrating Splunk to SmartStore with GCP: A Field Guide After spending way too long troubleshooting a SmartStore migration that “should have been working,” I figured I’d document what actually happened...

READ →
splunk

Standard Deviation of Volume Ingestion for Alerting

READ →
python

Boots on the Ground: End-to-End MCP Discovery with Shodan and Python

READ →
ai

Why Non-Coders are Winning in the Synthetic Renaissance

READ →
docker

Boosting Docker on Windows with Experimental autoMemoryReclaim

Introduction Docker Desktop on Windows has come a long way since its WSL 2 integration debut. Yet, one persistent pain point has been RAM management under heavy container workloads. In...

READ →
claude

Claude Code on Windows Inside of Cursor

READ →
splunk

Splunk Process Crash

READ →
routing

Splunk TCP Routing to Multiple Destinations

READ →
splunk

Managing Precedence in Splunk: Input Routing When Multiple Teams Share Ownership

READ →
splunk

Securing Splunk End-to-End with Custom Certificates

READ →
splunk

Populating Splunk Asset Lookups with TA-LDAPSearch

READ →
splunk

Formatting LDAP Identity Data for Splunk Enterprise Security

READ →

Tuning Assets and Identities in Enterprise Security

READ →
splunk

First-Time Setup of Splunk Enterprise Security: Data Models, CIM, and Taming the Noise

READ →
splunk

Gitignore for Deployment Server

READ →
splunk

The First Time I Broke All the Dashboards: Lessons in Field Normalization

READ →
splunk

Best Practices for Keeping inputs.conf Organized in Shared Environments

READ →
splunk

Heavy Forwarders vs Indexers: Where Should Parsing Happen?

READ →
splunk

Managing Source Types Across Teams Without Losing Your Sanity

READ →
splunk

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

READ →
splunk

Using nullQueue to Drop Logs at Index Time Without Touching the Source

READ →
splunk

When to Use EVAL, EXTRACT, and REPORT: Field Extraction Demystified

READ →
splunk

Routing Logs to Multiple Indexes with props.conf and transforms.conf

READ →
splunk

Consolidating a Multisite Splunk Cluster into a Single Site

READ →
splunk

Building a Proving Grounds Environment for Splunk Candidates

READ →
splunk

Modular Inputs That Don’t Make a Mess

READ →