BOOKS
Published

Read Time

6 min read

Curated & edited by

LuvemBooks Editorial

How we create our reviews →
Share This Review

Splunk Best Practices by Travis Marlette Review: A Practical Field Guide for Splunk Professionals

Published by Packt Publishing in September 2016, Splunk Best Practices by Travis Marlette is a technically focused guide designed to help Splunk practitioners design, implement, and publish custom Splunk applications more efficiently, drawing on Marlette's deep hands-on background integrating Splunk across a wide range of enterprise technologies.

LuvemBooks Verdict

Best for

Working Splunk practitioners — admins, infosec engineers, or data engineers already fluent in the platform — who want to sharpen their approach to app development, data ingestion, and enterprise integration rather than learn Splunk from scratch.

Worth it if

You are an experienced Splunk user looking for a structured, scenario-driven reference to tackle recurring pain points more efficiently, particularly in heterogeneous enterprise environments spanning security, networking, or finance.

Skip if

Skip it if you are new to Splunk and need foundational instruction, or if you are running a significantly newer version of the platform and cannot afford to cross-check whether 2016-era recommendations still apply.

Reader responses retrieved from Packt Publishing's own product page include praise for the book's depth, with one reader noting it is "more for someone that has been doing this a while and would like to enhance their best practices on the job," while a reviewer on Amazon Australia calls it "Excellent. Highly recommendable" and describes it as a "good book for Splunk admin."

Sources: Packt Publishing, Amazon Australia

Look inside the book

Preview the actual pages, via Google Books
In This Review
  • What Works & What Doesn't
  • What the Book Is and What It Covers
  • Author Expertise and Practical Grounding
  • Scope, Structure, and Intended Audience
  • Strengths Worth Noting
  • Limitations and Audience Fit

What Works & What Doesn't

What Works
  • Authored by a practitioner with documented experience working with Splunk since version 4.0 and across a wide range of complex enterprise integrations
  • Covers a broad technical surface including data models, indexer clusters, deployment servers, field extractions, dashboards, and multi-source data ingestion
  • Structured around step-by-step instructions and real-world scenarios designed to address both common and non-obvious Splunk pain points
  • Targets practitioners looking to improve efficiency and find better approaches, making it a focused upgrade resource rather than a general overview
  • Published by Packt Publishing, a specialist technical publisher with a track record in platform-specific guides
What Doesn't
  • Published in 2016 against a specific version of Splunk, so practitioners on significantly newer releases will need to verify the continued applicability of specific recommendations
  • Explicitly designed for existing Splunk users, not for newcomers who need foundational instruction before tackling best practices
A technically grounded, practitioner-authored guide, this book is built for Splunk users who already know the platform and want to work smarter within it.

What the Book Is and What It Covers

Splunk Best Practices by Travis Marlette front cover
Splunk Best Practices by Travis Marlette front cover
Splunk Best Practices is a technical guide published by Packt Publishing on September 21, 2016. Its stated mission is to help practitioners design, implement, and publish custom Splunk applications by following established best practices. The book addresses both common and less common pain points in working with Splunk environments, and is structured around step-by-step instructions, examples, and real-world scenarios. Topics covered span a broad technical surface: data inputs, field extractions, data models, indexer clusters, deployment servers, Heavy Forwarders, dashboard creation, DB Connect, correlation IDs, and integration with data sources including Active Directory, Common Log Format systems, firewalls, Hadoop, and JSON-based pipelines.

Author Expertise and Practical Grounding

Travis Marlette brings substantial real-world credentials to the subject. He has been working with Splunk since version 4.0 and carries more than seven years of statistical and analytical experience across Splunk and complementary technologies. His background in finance has required integrating Splunk with some of the most complex enterprise stacks available, including SAS, HIVE, TerraData (Data Warehouse), Oozie, EMC Xtreme IO, Datameer, ZFS, Platfora, Juniper security and network systems, IBM WebSphere, Cisco Call Manager, Java Management Systems (JVM), Cisco UCS, and IBM platforms. That breadth of integration experience is directly reflected in the scope of scenarios the book addresses, lending the guidance a practitioner authority that purely theoretical texts lack.

Scope, Structure, and Intended Audience

The book is explicitly not an introduction to Splunk. Its publisher positioning targets readers who are already working with Splunk and want to move faster, avoid common mistakes, and find better approaches to recurring challenges. The step-by-step structure is designed to make guidance actionable: readers dealing with multi-source data ingestion, infosec monitoring, or complex search optimization can navigate to relevant scenarios rather than reading cover-to-cover. The index terms visible in the book's record — covering everything from `inputs.conf` configuration to `eval` commands, event types, and data routers — confirm that the book operates at a genuinely technical depth, not a surface-level overview.

Strengths Worth Noting

The book's primary strength, as reflected in its publisher description, is its practical orientation toward pain points practitioners actually encounter. Rather than reproducing Splunk's own documentation, the book is designed to surface shortcuts, non-obvious solutions, and best-practice patterns that accelerate day-to-day work. The scenario-based approach — grounding guidance in examples readers are designed to recognize from their own environments — is a deliberate structural choice that distinguishes it from reference-only manuals. For practitioners integrating Splunk into heterogeneous enterprise environments (finance, infosec, network operations), Marlette's cross-technology experience makes the guidance particularly relevant.

Limitations and Audience Fit

Because the book was published in 2016 and covers Splunk at a specific point in its evolution, practitioners working with substantially newer versions of the platform will need to assess which recommendations remain current and which have been superseded by changes to Splunk's architecture or feature set. The book is also explicitly pitched at existing Splunk users; those new to the platform will find it does not serve as an on-ramp. Readers seeking conceptual or theoretical grounding in data engineering more broadly, rather than Splunk-specific applied guidance, are likewise outside its intended scope.

Sources & Further Reading

The key facts and claims in this review are grounded in the retrieved, verified sources listed below.

  1. Cited in this review
  2. 1
  3. Further reading
  4. 2
  5. 3
  6. 4
  7. 5
  8. 6