March 2018
Beginner to intermediate
576 pages
13h 29m
English
Some fictitious events are given as follows. Assuming that this is a busy server, there might be a huge number of events occurring between requests from this particular session:
2012-04-27T03:14:31 user=mary GET /foo?q=1 uid=abcdefg ...hundreds of events... 2012-04-27T03:14:46 user=mary GET /bar?q=2 uid=abcdefg ...hundreds of thousands of events... 2012-04-27T06:40:45 user=mary GET /foo?q=3 uid=abcdefg ...hundreds of events... 2012-04-27T06:41:49 user=mary GET /bar?q=4 uid=abcdefg
The definition of huge depends on the infrastructure that you have dedicated to Splunk. See Chapter 12, Advanced Deployments, for more information about sizing your installation, or contact Splunk support.
Let's build ...
Read now
Unlock full access