> initializing blog_feed...

SPLUNKY BREWSTER

Technical dispatches from the trenches of Splunk, security, AI, and infrastructure.

32 posts // 77 tags // 2026 — 2014
PINNED

I Got Rick Rolled by Claude (And Here's the Proof)

I was live-streaming on TikTok, building out a content automation tool with Claude, when it dropped a helpful-looking link into our chat. I clicked it. Cue music…

ai fun rickroll claude livestream
WATCH THE VIDEO →
ai

ML Social: An AI-Powered Content Generation Platform

Check out more Machine Learning shorts on the Need-to-Nerd YouTube channel and subscribe for updates on AI, security, and data engineering content. ML Social is an AI content generation platform...

READ →
splunk

So You're Connected to Splunk's MCP Server - Now What?

You got the proxy running. The green checkmark appeared. splunk_get_info came back with your instance version and a healthy status. Now you’re staring at a blinking cursor wondering what exactly...

READ →
gcp

Shrinking a GCP Boot Disk the Hard Way (Because There Is No Easy Way)

You can’t shrink a persistent disk in GCP. You can grow one in about 3 seconds, but shrinking? Google basically says “lol no.” So when I needed to take a...

READ →
splunk

Splunk MCP Server Setup and Troubleshooting

Splunk’s MCP Server exposes your instance to AI tooling over port 8089. Run SPL, pull metadata, query indexes, interact with the AI Assistant, all through the management API via Model...

READ →
splunk

Connecting Splunk's MCP Server to Claude Code CLI: What Actually Worked (and What Didn't)

READ →
splunk

Migrating Splunk to SmartStore with GCP: A Field Guide

READ →
splunk

Standard Deviation of Volume Ingestion for Alerting

Splunk License Usage Anomaly Report (Z-Score Method) — Full Detailed Breakdown Purpose You asked for the very detailed explanation of what the SPL does, plus tuning guidance to cut false...

READ →
python

Boots on the Ground: End-to-End MCP Discovery with Shodan and Python

READ →
ai

Why Non-Coders are Winning in the Synthetic Renaissance

READ →
docker

Boosting Docker on Windows with Experimental autoMemoryReclaim

READ →
claude

Claude Code on Windows Inside of Cursor

You want Claude Code in your Cursor Application on Windows. There is no exception. I don’t have enough metrics for a cost comparison yet but I think it will be...

READ →
splunk

Splunk Process Crash

READ →
routing

Splunk TCP Routing to Multiple Destinations

READ →
splunk

Managing Precedence in Splunk: Input Routing When Multiple Teams Share Ownership

READ →
splunk

Securing Splunk End-to-End with Custom Certificates

READ →
splunk

Populating Splunk Asset Lookups with TA-LDAPSearch

READ →
splunk

Formatting LDAP Identity Data for Splunk Enterprise Security

READ →

Tuning Assets and Identities in Enterprise Security

READ →
splunk

First-Time Setup of Splunk Enterprise Security: Data Models, CIM, and Taming the Noise

READ →
splunk

Gitignore for Deployment Server

READ →
splunk

The First Time I Broke All the Dashboards: Lessons in Field Normalization

READ →
splunk

Best Practices for Keeping inputs.conf Organized in Shared Environments

READ →
splunk

Heavy Forwarders vs Indexers: Where Should Parsing Happen?

READ →
splunk

Managing Source Types Across Teams Without Losing Your Sanity

READ →
splunk

How to Mask Sensitive Data at Index Time (Without Breaking Your Regexes)

READ →
splunk

Using nullQueue to Drop Logs at Index Time Without Touching the Source

READ →
splunk

When to Use EVAL, EXTRACT, and REPORT: Field Extraction Demystified

READ →
splunk

Routing Logs to Multiple Indexes with props.conf and transforms.conf

READ →
splunk

Consolidating a Multisite Splunk Cluster into a Single Site

READ →
splunk

Building a Proving Grounds Environment for Splunk Candidates

READ →
splunk

Modular Inputs That Don’t Make a Mess

READ →