To avoid distractions in the previous sections of this chapter and in Chapter 4, Getting Data into Splunk, I've reserved a few additional comments on topics you will want to consider for establishing some best practices as you administer your Splunk environment, understanding of course that these have to be tailored to your particular organization's culture, needs, and IT environment.
Let's first talk about developing a naming convention for indexes and source types. A search of the web will provide a number of discussions and ideas on the topic; here are a few options I've settled on.