Video description
Maybe you've heard about Splunk, but don't know how to use it to take control of big data? Have you used Splunk, but want to learn how to set it up and use it properly? If so, this course is for you.
In this course, you will work with Splunk from the ground up. You'll learn the basics of Splunk terminology, and how to use the Splunk web interface to find data. You'll also build your own Splunk environment, add data to the Common Information Model (CIM), create dashboards, and find events within data. Finally, you'll master advanced searching techniques that are especially useful to those in network, security, and system administration roles.
The course also covers the latest additions brought in for Splunk 8 and helps you quickly perform an upgrade. By the end of the course, you will be confident about using Splunk and will be well on the road to becoming a proficient Splunk architect and administrator as quickly as possible!
What You Will Learn
- Build your own Splunk development environment from scratch on a Linux server—and use it!
- Onboard and index multiple types of data into your Splunk instance
- Understand the importance of the Splunk Common Information Model (CIM), and why data models make Splunk a powerful tool for managing logs at volume
- Normalize data using Splunk apps
- Develop basic reports and dashboards using your new Splunk instance and the data from your Linux system
- Understand why leaving systems exposed to the internet is a bad idea
Audience
This course is for IT professionals and data analysts who want to get started with Splunk and rapidly take their skills to the point where they can get hands-on and fully proficient with its features and benefits.
Requirement: No prior knowledge of Splunk is needed for taking this course, but a Splunk account (free of charge) will be required for the lab activities. Knowledge of Unix/Linux command line will be helpful.
About The Author
Tom Kopchak: Tom Kopchak is the Director of Technical Operations at Hurricane Labs, where he pretends to manage a team of network and Splunk engineers but is still an engineer and technology geek at heart. Tom is a Splunk Certified Architect and Accredited Consultant and has several years' experience building, designing, and managing Splunk deployments; he also manages teams of Splunk engineers, designing Splunk deployment strategies, and developing Splunk training materials.
He holds a Masters degree in Computing Security from the Rochester Institute of Technology and has spoken at numerous Infosec conferences around the country (including Splunk .conf and DEFCON). You will often find him researching digital forensics topics or tinkering with any and all forms of computer hardware. When he is not working with computers, Tom enjoys composing, music improvisation (Acts of Music), and playing both the piano and organ.
Table of contents
- Chapter 1 : Introduction to Splunk
-
Chapter 2 : Splunk Terminology
- Splunk - Splexicon
- What Data Looks Like in Splunk - Events
- Getting Data Out of Splunk - Search
- Saved Searches - Report
- Visualizing Data - Dashboard
- Splunk's Search Language - Search Processing Language
- What Type of Data Do We Have - Sourcetype
- How is Data Stored - Index
- Making Data Useful with Knowledge Objects and Fields
- Enriching Data - Lookup Table
- Chapter 3 : Data Onboarding
-
Chapter 4 : Splunk Deployment Components
- Core Splunk Infrastructure - Indexes and Search Heads
- Supporting Infrastructure - Forwarders
- Supporting Infrastructure - Syslog Receiver
- Supporting Infrastructure - Deployment Server
- Splunk Licensing - How It Works and How to Investigate Your License Utilization
- Splunk Clustering - Building Splunk for Fault Tolerance
- Distributed Splunk Environments
- Splunk Apps - The Building Blocks of Any Splunk Deployment
- Chapter 5 : Data Normalization and Data Models
- Chapter 6 : Using Your Splunk Environment
-
Chapter 7 : Visualizing Data
- Reporting Log Data - Tables
- Hands-On Lab: Tables - Displaying Search Results
- Advanced Searching Concepts - Chart - Graphing Search Results
- Advanced Searching Concepts - Timechart - Results Over Time
- Advanced Searching Concepts - Geostats and IP Location
- Advanced Searching Concepts: Eval - Manipulating and Reformatting Data
- Advanced Searching Concepts: Rename – Making Table Headers More Accessible
- Advanced Searching Concepts: Relative Time Syntax
- Advanced Searching Concepts: Search Performance - Gotchas to Avoid
- Advanced Searching Concepts: Time to Experiment – Expanding Your Splunk Knowledge
- Creating Splunk Dashboards
- Hands-On Lab: Dashboards
- Chapter 8 : Upgrading Splunk
Product information
- Title: Learning Splunk
- Author(s):
- Release date: March 2020
- Publisher(s): Packt Publishing
- ISBN: 9781789801002
You might also like
video
Practical Splunk for Beginners
4+ Hours of Video Instruction Description Hands-on approach to learning the Splunk platform to search, report, …
video
Getting Started with Kubernetes LiveLessons, 2nd Edition
6+ Hours of Video Instruction An updated edition of this video title is available. Please go …
book
Practical Splunk Search Processing Language: A Guide for Mastering SPL Commands for Maximum Efficiency and Outcome
Use this practical guide to the Splunk operational data intelligence platform to search, visualize, and analyze …
book
Terraform: Up and Running, 3rd Edition
Terraform has become a key player in the DevOps world for defining, launching, and managing infrastructure …