January 2013
Beginner to intermediate
448 pages
9h 16m
English
To augment the built-in commands, Splunk provides the ability to write commands in Python and Perl. You can write the commands to modify events, replace events, or even dynamically produce events.
While external commands can be very useful, if the number of events to be processed is large, or if performance is a concern, it should be considered a last resort. You should make every effort to accomplish the task at hand using the search language built into Splunk, or other built-in features. For instance, if you need:
rex, regex, and extracted fieldseval (search for splunk eval functions with your favorite search ...Read now
Unlock full access