Book description
Learn to transform your machine data into valuable IT and business insights all using this comprehensive and practical tutorial
- Learn to search, dashboard, configure, and deploy Splunk on one machine or thousands
- Start working with Splunk fast, with a tested set of practical examples and useful advice
- Step-by-step instructions and examples with a comprehensive coverage for Splunk veterans and newbies alike
In Detail
Splunk is a data collection, indexing, and visualization engine for operational intelligence. It's a powerful and versatile search and analysis engine that lets you investigate, troubleshoot, monitor, alert, and report on everything that's happening in your entire IT infrastructure from one location in real time. Splunk collects, indexes, and harnesses all the fast moving machine data generated by our applications, servers, and devices - physical, virtual, and in the cloud.
Given a mountain of machine data, this book shows you exactly how to learn to use Splunk to make something useful from it. Depending on your needs, you can learn to search, transform, and display data, or learn to administer your Splunk installation, large or small.
"Implementing Splunk: Big Data Reporting and Development for Operational Intelligence" will help you get your job done faster, whether you read from the beginning or jump to what you need to know today. New and experienced users alike will find nuggets of wisdom throughout.
This book provides you with valuable examples and step-by-step instructions, showing you how to take advantage of everything Splunk has to offer you, to make the most out of your machine data.
"Implementing Splunk: Big Data Reporting and Development for Operational Intelligence" takes you on a journey right from inception to a fully functioning implementation of Splunk. Using a real-world data walkthrough, you'll be shown how to search effectively, create fields, build dashboards, reports, and package apps, manage your indexes, integrate into the enterprise, and extend Splunk. This practical implementation guide equips you with high-level knowledge for configuring, deploying, extending, and integrating Splunk. Depending on the goal and skills of the reader, enough topics are covered to get you on your way to dashboard guru, app developer, or enterprise administrator. This book uses examples curates reference, and sage advice to help you make the most of this incredibly powerful tool.
Table of contents
-
Implementing Splunk: Big Data Reporting and Development for Operational Intelligence
- Table of Contents
- Implementing Splunk: Big Data Reporting and Development for Operational Intelligence
- Credits
- About the Author
- About the Reviewers
- www.PacktPub.com
- Preface
- 1. The Splunk Interface
- 2. Understanding Search
-
3. Tables, Charts, and Fields
- About the pipe symbol
- Using top to show common field values
- Using stats to aggregate values
- Using chart to turn data
- Using timechart to show values over time
- Working with fields
- Summary
- 4. Simple XML Dashboards
- 5. Advanced Search Examples
- 6. Extending Search
- 7. Working with Apps
- 8. Building Advanced Dashboards
-
9. Summary Indexes and CSV Files
- Understanding summary indexes
- When to use a summary index
- When to not use a summary index
- Populating summary indexes with saved searches
- Using summary index events in a query
- Using sistats, sitop, and sitimechart
- How latency affects summary queries
- How and when to backfill summary data
- Reducing summary index size
- Calculating top for a large time frame
- Storing raw events in a summary index
- Using CSV files to store transient data
- Summary
-
10. Configuring Splunk
- Locating Splunk configuration files
- The structure of a Splunk configuration file
- Configuration merging logic
-
An overview of Splunk .conf files
- props.conf
- inputs.conf
- transforms.conf
- fields.conf
- outputs.conf
- indexes.conf
- authorize.conf
- savedsearches.conf
- times.conf
- commands.conf
- web.conf
- User interface resources
- Summary
-
11. Advanced Deployments
- Planning your installation
- Splunk instance types
- Common data sources
- Sizing indexers
- Planning redundancy
- Working with multiple indexes
- Deploying the Splunk binary
- Using apps to organize configuration
-
Configuration distribution
- Using your own deployment system
-
Using Splunk deployment server
- Step 1 – Deciding where your deployment server will run
- Step 2 – Defining your deploymentclient.conf configuration
- Step 3 – Defining our machine types and locations
- Step 4 – Normalizing our configurations into apps appropriately
- Step 5 – Mapping these apps to deployment clients in serverclass.conf
- Step 6 – Restarting the deployment server
- Step 7 – Installing deploymentclient.conf
- Using LDAP for authentication
- Using Single Sign On
- Load balancers and Splunk
- Multiple search heads
- Summary
- 12. Extending Splunk
- Index
Product information
- Title: Implementing Splunk: Big Data Reporting and Development for Operational Intelligence
- Author(s):
- Release date: January 2013
- Publisher(s): Packt Publishing
- ISBN: 9781849693288
You might also like
book
Splunk: Enterprise Operational Intelligence Delivered
Demystify Big Data and discover how to bring operational intelligence to your data to revolutionize your …
book
Splunk Operational Intelligence Cookbook
Over 70 practical recipes to gain operational data intelligence with Splunk Enterprise In Detail This book …
book
Splunk Operational Intelligence Cookbook - Second Edition
Over 70 practical recipes to gain operational data intelligence with Splunk Enterprise About This Book This …
book
Splunk Operational Intelligence Cookbook - Third Edition
Leverage Splunk's operational intelligence capabilities to unlock new hidden business insights and drive successAbout This Book …