Quickstart — hands-on walkthroughs

Guided walkthroughs of TrackMe, captured live on the product: every page is a slide deck with a description of what each slide shows — read it top to bottom, present it, or download it.

Suggested order for a first contact with the product: the introduction, then the three parts of the series (a first tenant, classification, alerting), then the walkthroughs of the components you plan to use.

Product introduction

What TrackMe is, what it tracks, how it decides, how it tells you — the vocabulary before the live product. 16 slides · 20 min.

Product introduction
Part 1 — Your first DSM tenant

Create a Virtual Tenant, let the hybrid tracker discover the feeds, read the first entity in alert and why. 16 slides · 20 min.

Part 1 — Your first DSM tenant
Part 2 — Classify with policies

Priority and tags from a CMDB lookup, simulated before saving; the on-call and ownership views. 12 slides · 15 min.

Part 2 — Classify with policies
Part 3 — Stateful alerting

One alert scoped to critical and high; the incident lifecycle, the email with charts and the AI report. 16 slides · 20 min.

Part 3 — Stateful alerting
Topology Studio

A map generated from a tenant, one authored from scratch, Topology Alerts, and a map built with AI. 39 slides · 40 min.

Topology Studio
Field Quality Monitoring

CIM and custom dictionaries, sampling, the field-quality advisors. 35 slides · 40 min.

Field Quality Monitoring
Volume Outliers

Licensed volume per index, ML outliers on drops and spikes, the ML Advisor. 30 slides · 30 min.

Volume Outliers
User Activity Monitoring (Beta)

Who is doing what on your Splunk: accounts, findings, the investigation workflow. 31 slides · 30 min.

User Activity Monitoring (Beta)

Reference white papers

The former quickstart tutorials remain available as reference material.