6 min read
Share This Review
Splunk Best Practices by Travis Marlette Review: A Practical Field Guide for Splunk Professionals
Published by Packt Publishing in September 2016, Splunk Best Practices by Travis Marlette is a technically focused guide designed to help Splunk practitioners design, implement, and publish custom Splunk applications more efficiently, drawing on Marlette's deep hands-on background integrating Splunk across a wide range of enterprise technologies.
LuvemBooks Verdict
Best for
Working Splunk practitioners — admins, infosec engineers, or data engineers already fluent in the platform — who want to sharpen their approach to app development, data ingestion, and enterprise integration rather than learn Splunk from scratch.
Worth it if
You are an experienced Splunk user looking for a structured, scenario-driven reference to tackle recurring pain points more efficiently, particularly in heterogeneous enterprise environments spanning security, networking, or finance.
Skip if
Skip it if you are new to Splunk and need foundational instruction, or if you are running a significantly newer version of the platform and cannot afford to cross-check whether 2016-era recommendations still apply.
What readers & critics say
Reader responses retrieved from Packt Publishing's own product page include praise for the book's depth, with one reader noting it is "more for someone that has been doing this a while and would like to enhance their best practices on the job," while a reviewer on Amazon Australia calls it "Excellent. Highly recommendable" and describes it as a "good book for Splunk admin."
Sources: Packt Publishing, Amazon AustraliaLook inside the book
Preview the actual pages, via Google BooksIn This Review
- What Works & What Doesn't
- What the Book Is and What It Covers
- Author Expertise and Practical Grounding
- Scope, Structure, and Intended Audience
- Strengths Worth Noting
- Limitations and Audience Fit
What Works & What Doesn't
What Works
- Authored by a practitioner with documented experience working with Splunk since version 4.0 and across a wide range of complex enterprise integrations
- Covers a broad technical surface including data models, indexer clusters, deployment servers, field extractions, dashboards, and multi-source data ingestion
- Structured around step-by-step instructions and real-world scenarios designed to address both common and non-obvious Splunk pain points
- Targets practitioners looking to improve efficiency and find better approaches, making it a focused upgrade resource rather than a general overview
- Published by Packt Publishing, a specialist technical publisher with a track record in platform-specific guides
What Doesn't
- Published in 2016 against a specific version of Splunk, so practitioners on significantly newer releases will need to verify the continued applicability of specific recommendations
- Explicitly designed for existing Splunk users, not for newcomers who need foundational instruction before tackling best practices
What the Book Is and What It Covers

Author Expertise and Practical Grounding
Scope, Structure, and Intended Audience
Strengths Worth Noting
Limitations and Audience Fit
Frequently Asked Questions
Sources & Further Reading
The key facts and claims in this review are grounded in the retrieved, verified sources listed below.
- Cited in this review
- 1
- Further reading
- 2
booksamillion.com
- 3
packtpub.com
- 4
- 5
barnesandnoble.com
- 6
books.google.com
Reader Comments
No comments yet
Be the first to share your thoughts!