Splunk .Conf
Every year, UnshakeableSalt sends people to Splunk .conf — not just to learn about the platform, but because nowhere else puts the Splunk ecosystem, the wider cyber security world, and the data-infrastructure vendors we all depend on in the same building at the same time. Here's what that's looked like for us so far, and why we're particularly excited about Denver in 2026.
Our .conf history
Upto 2024: Las Vegas — building the foundation
Our first years at .conf were about attendance, networking and certification. We used the weeks to get hands-on with new features, sit exams on-site (cheaply), and expand our Splunk expertise that now underpins our client work. It's easy to underrate "just being in the room" — but the informal conversations across the various venues and between sessions shaped how we approach detection engineering as much as any single talk did.
2025: Boston — first time presenting
When .conf moved to Boston for .conf25, we went from attendees to presenters, speaking on data migration and data storage options. Presenting changes the value of the week: instead of only absorbing other people's thinking, you get direct feedback from practitioners solving the same storage and retention problems, and it opens doors to conversations you wouldn't get as a name badge in the crowd.
2026: Denver — back on familiar turf, cyber security this time
We're particularly excited about .conf26 in Denver. This year we're presenting twice, and — for the first time — on subjects much closer to our actual specialism: cyber security, rather than data platform mechanics. Talking about the problems we solve for clients every day, in front of the peer group best placed to challenge and improve our thinking, is exactly the kind of exposure that sharpens a consultancy.
Why one venue matters more than the sum of its sessions
Splunk .conf works because it's never really just about Splunk. The show floor and the sessions bring together SOC teams, detection engineers, platform vendors, and increasingly the broader telemetry and security-operations ecosystem, all in one place for a few days. That density is the actual value: a single conversation on the show floor can save weeks of vendor calls, and a hallway question to a practitioner from a completely different sector often reframes a problem we've been stuck on.
Cross-sector networking
Because .conf draws organisations from finance, healthcare, retail, manufacturing, and government alongside pure-play security vendors, we get exposure to detection and data problems well outside our usual client base. Seeing how a completely different sector handles the same underlying challenge — noisy alerting, data retention costs, air-gapped environments — is one of the fastest ways we've found to test whether our own approach actually holds up.
Overlapping events we're watching closely
CriblConnect
CriblConnect is especially important to us this cycle. We're closely following how Cribl is absorbing its acquisition of CardinalOps into its wider ecosystem — CardinalOps' agentic detection engineering, mapped against MITRE ATT&CK, is a genuinely relevant capability for the SIEM modernisation conversations we're already having with clients. Hearing directly from Cribl on how that integration is progressing, rather than piecing it together from press releases, is a big part of why we prioritise being in the room.
AWS and the broader cloud/security overlap
Events run by or alongside Amazon Web Services give us a parallel read on where cloud infrastructure is heading — particularly relevant given how much Splunk and Cribl deployment now happens on AWS. Catching these alongside .conf and CriblConnect means a single trip covers the SIEM, the telemetry layer, and the cloud infrastructure underneath it, rather than three separate trips spread across the year.
The takeaway
For a cyber security consultancy, the value of .conf week isn't a single keynote or a single stand — it's the density of the right people in one place, and the fact that Splunk, Cribl, and AWS' overlapping events let us keep pace with SIEM, telemetry, and cloud infrastructure in the same trip. We'll keep showing up, keep presenting closer to our specialism each year, and keep bringing back what we learn to our clients.
Curious what we're presenting on this year, or want to compare notes before or after .conf26? Get in touch with our team.