Linked e-resources
Details
Table of Contents
Intro
Table of Contents
About the Author
About the Technical Reviewer
Acknowledgments
Introduction
Part I: Splunk Architecture, Splunk SPL (Search Processing Language), and Splunk Knowledge Objects
Chapter 1: An Overview of Splunk
Overview of the Splunk Admin Exam
Structure
Requirements
Blueprint
An Introduction to Splunk
The History of Splunk
The Benefits of Splunk
The Splunk Architecture
Installing Splunk
Installing Splunk on macOS
Installing Splunk on Windows
Adding Data in Splunk
Summary
Multiple-Choice Questions
Further Reading
Chapter 2: Splunk Search Processing Language
The Pipe Operator
Time Modifiers
Understanding Basic SPL
Search Language Syntax
Boolean Operators in Splunk
Syntax Coloring in SPL
Sorting Results
Sort
Filtering Commands
where
dedup
head
tail
Reporting Commands
top
rare
history
table
stats
Aggregate Functions
Event Order Functions
Multivalue stats and chart Functions
Timechart Functions
untable
chart
timechart
Filtering, Modifying, and Adding Fields
eval
Comparison and Conditional Functions
Conversion Functions
Cryptographic Functions
Date and Time Functions
Informational Functions
Mathematical Functions
Multivalue eval Functions
Statistical eval Functions
Text Functions
Trigonometric and Hyperbolic Functions
Rex
lookup
Input Lookup
Output Lookup
Field
Grouping Results
Transaction
Summary
Multiple-Choice Questions
References
Chapter 3: Macros, Field Extraction, and Field Aliases
Field Extraction in Splunk
Regular Expressions
Regular Expression Using Field Extraction
Inline Regular Expression Using Field Extraction
Delimiters
Delimiters Using Field Extraction
Macros
Create a Macro Using Splunk Web
Create a Macro Using the .conf File
Field Aliases in Splunk
Setting up Field Aliases
Splunk Search Query
Summary
Multiple Choice Test Questions
References
Chapter 4: Tags, Lookups, and Correlating Events
Splunk Lookups
Looking up Table Files
Lookup Definitions
Automatic Lookups
Splunk Tags
Create Tags in Splunk Using Splunk Web
Tag Event Types in Splunk Web
Reporting in Splunk
Creating Reports in Splunk Web
Report Acceleration in Splunk
Creating Report Acceleration
Scheduling a Report in Splunk
Alerts in Splunk
Create Alerts in Splunk Using Splunk Web
Cron Expressions for Alerts
Summary
Multiple-Choice Questions
References
Chapter 5: Data Models, Pivot, and CIM
Understanding Data Models and Pivot
Datasets and Data Models
Creating Data Models and Pivot in Splunk
Creating New Datasets
Predicting a Sales Pattern
Event Actions in Splunk
GET Workflow Actions
Defining a GET Workflow Action
Search Workflow Action
Defining Search Workflow Action
Common Information Model in Splunk
Table of Contents
About the Author
About the Technical Reviewer
Acknowledgments
Introduction
Part I: Splunk Architecture, Splunk SPL (Search Processing Language), and Splunk Knowledge Objects
Chapter 1: An Overview of Splunk
Overview of the Splunk Admin Exam
Structure
Requirements
Blueprint
An Introduction to Splunk
The History of Splunk
The Benefits of Splunk
The Splunk Architecture
Installing Splunk
Installing Splunk on macOS
Installing Splunk on Windows
Adding Data in Splunk
Summary
Multiple-Choice Questions
Further Reading
Chapter 2: Splunk Search Processing Language
The Pipe Operator
Time Modifiers
Understanding Basic SPL
Search Language Syntax
Boolean Operators in Splunk
Syntax Coloring in SPL
Sorting Results
Sort
Filtering Commands
where
dedup
head
tail
Reporting Commands
top
rare
history
table
stats
Aggregate Functions
Event Order Functions
Multivalue stats and chart Functions
Timechart Functions
untable
chart
timechart
Filtering, Modifying, and Adding Fields
eval
Comparison and Conditional Functions
Conversion Functions
Cryptographic Functions
Date and Time Functions
Informational Functions
Mathematical Functions
Multivalue eval Functions
Statistical eval Functions
Text Functions
Trigonometric and Hyperbolic Functions
Rex
lookup
Input Lookup
Output Lookup
Field
Grouping Results
Transaction
Summary
Multiple-Choice Questions
References
Chapter 3: Macros, Field Extraction, and Field Aliases
Field Extraction in Splunk
Regular Expressions
Regular Expression Using Field Extraction
Inline Regular Expression Using Field Extraction
Delimiters
Delimiters Using Field Extraction
Macros
Create a Macro Using Splunk Web
Create a Macro Using the .conf File
Field Aliases in Splunk
Setting up Field Aliases
Splunk Search Query
Summary
Multiple Choice Test Questions
References
Chapter 4: Tags, Lookups, and Correlating Events
Splunk Lookups
Looking up Table Files
Lookup Definitions
Automatic Lookups
Splunk Tags
Create Tags in Splunk Using Splunk Web
Tag Event Types in Splunk Web
Reporting in Splunk
Creating Reports in Splunk Web
Report Acceleration in Splunk
Creating Report Acceleration
Scheduling a Report in Splunk
Alerts in Splunk
Create Alerts in Splunk Using Splunk Web
Cron Expressions for Alerts
Summary
Multiple-Choice Questions
References
Chapter 5: Data Models, Pivot, and CIM
Understanding Data Models and Pivot
Datasets and Data Models
Creating Data Models and Pivot in Splunk
Creating New Datasets
Predicting a Sales Pattern
Event Actions in Splunk
GET Workflow Actions
Defining a GET Workflow Action
Search Workflow Action
Defining Search Workflow Action
Common Information Model in Splunk