Book description
A comprehensive guide to making machine data accessible across the organization using advanced dashboards
About This Book
- Enrich machine-generated data and transform it into useful, meaningful insights
- Perform search operations and configurations, build dashboards, and manage logs
- Extend Splunk services with scripts and advanced configurations to process optimal results
Who This Book Is For
This book is intended for data analysts, business analysts, and IT administrators who want to make the best use of big data, operational intelligence, log management, and monitoring within their organization. Some knowledge of Splunk services will help you get the most out of the book
What You Will Learn
- Focus on the new features of the latest version of Splunk Enterprise 7
- Master the new offerings in Splunk: Splunk Cloud and the Machine Learning Toolkit
- Create efficient and effective searches within the organization
- Master the use of Splunk tables, charts, and graph enhancements
- Use Splunk data models and pivots with faster data model acceleration
- Master all aspects of Splunk XML dashboards with hands-on applications
- Create and deploy advanced Splunk dashboards to share valuable business insights with peers
In Detail
Splunk is the leading platform that fosters an efficient methodology and delivers ways to search, monitor, and analyze growing amounts of big data. This book will allow you to implement new services and utilize them to quickly and efficiently process machine-generated big data.
We introduce you to all the new features, improvements, and offerings of Splunk 7. We cover the new modules of Splunk: Splunk Cloud and the Machine Learning Toolkit to ease data usage. Furthermore, you will learn to use search terms effectively with Boolean and grouping operators. You will learn not only how to modify your search to make your searches fast but also how to use wildcards efficiently. Later you will learn how to use stats to aggregate values, a chart to turn data, and a time chart to show values over time; you'll also work with fields and chart enhancements and learn how to create a data model with faster data model acceleration. Once this is done, you will learn about XML Dashboards, working with apps, building advanced dashboards, configuring and extending Splunk, advanced deployments, and more. Finally, we teach you how to use the Machine Learning Toolkit and best practices and tips to help you implement Splunk services effectively and efficiently.
By the end of this book, you will have learned about the Splunk software as a whole and implemented Splunk services in your tasks at projects
Style and approach
An easy-to-follow, step-by-step guide to help you get to grips with real-world applications of Splunk 7.
Table of contents
- Title Page
- Copyright and Credits
- Packt Upsell
- Contributors
- Preface
-
The Splunk Interface
- Logging in to Splunk
- The home app
- The top bar
- The Search & Reporting app
- Using the time picker
- Using the field picker
- The settings section
- Splunk Cloud
- Try before you buy
- A quick cloud tour
- The top bar in Splunk Cloud
- Splunk reference app – PAS
- Universal forwarder
- eventgen
- Next steps
- Summary
-
Understanding Search
- Using search terms effectively
- Boolean and grouping operators
- Clicking to modify your search
- Using fields to search
- Using wildcards efficiently
- All about time
- Making searches faster
- Sharing results with others
- Searching job settings
- Saving searches for reuse
- Creating alerts from searches
- Event annotations
- Summary
-
Tables, Charts, and Fields
- About the pipe symbol
- Using top to show common field values
- Using stats to aggregate values
- Using chart to turn data
- Using timechart to show values over time
- Working with fields
- Chart enhancements in version 7.0
- Summary
- Data Models and Pivots
- Simple XML Dashboards
- Advanced Search Examples
- Extending Search
- Working with Apps
- Building Advanced Dashboards
-
Summary Indexes and CSV Files
- Understanding summary indexes
- When to use a summary index
- When to not use a summary index
- Populating summary indexes with saved searches
- Using summary index events in a query
- Using sistats, sitop, and sitimechart
- How latency affects summary queries
- How and when to backfill summary data
- Reducing summary index size
- Calculating top for a large time frame
- Using CSV files to store transient data
- Summary
-
Configuring Splunk
- Locating Splunk configuration files
- The structure of a Splunk configuration file
- The configuration merging logic
-
An overview of Splunk.conf files
- props.conf
- inputs.conf
- transforms.conf
- fields.conf
- outputs.conf
- indexes.conf
- authorize.conf
- savedsearches.conf
- times.conf
- commands.conf
- web.conf
- User interface resources
- Summary
-
Advanced Deployments
- Planning your installation
- Splunk instance types
- Common data sources
- Sizing indexers
- Planning redundancy
- Working with multiple indexes
- Deploying the Splunk binary
- Using apps to organize configuration
-
Configuration distribution
- Using your own deployment system
-
Using the Splunk deployment server
- Step 1 – deciding where your deployment server will run
- Step 2 - defining your deploymentclient.conf configuration
- Step 3 - defining our machine types and locations
- Step 4 - normalizing our configurations into apps appropriately
- Step 5 - mapping these apps to deployment clients in serverclass.conf
- Step 6 - restarting the deployment server
- Step 7 - installing deploymentclient.conf
- Using LDAP for authentication
- Using single sign-on
- Load balancers and Splunk
- Multiple search heads
- Summary
- Extending Splunk
- Machine Learning Toolkit
Product information
- Title: Implementing Splunk 7 - Third Edition
- Author(s):
- Release date: March 2018
- Publisher(s): Packt Publishing
- ISBN: 9781788836289
You might also like
book
Splunk 7 Essentials - Third Edition
Transform machine data into powerful analytical intelligence using Splunk About This Book Analyze and visualize machine …
book
Advanced Splunk
Master the art of getting the maximum out of your machine data using Splunk About This …
book
Splunk 7.x Quick Start Guide
Learn how to architect, implement, and administer a complex Splunk Enterprise environment and extract valuable insights …
book
Mastering Splunk
Optimize your machine-generated data effectively by developing advanced analytics with Splunk In Detail Splunk is the …