Book description
Optimize your machine-generated data effectively by developing advanced analytics with Splunk
In Detail
Splunk is the definitive technology solution used to manage the ever-growing volumes of machine-generated data. This technology is indispensable for industries involved in big data analysis, online services, education, finance, healthcare, retail, and telecommunications. So, having Splunk experience will be relevant for a long time to come!
This book will first take you through the evolution of Splunk and how it fits into an organization's architectural roadmap. Master advanced search topics and explore in-depth methods to leverage Splunk tables, charts, fields, and other cases. As we advance through the chapters, you will master the best practices of values and lookups, indexes, business effective dashboards, and discover the cornerstones of how to evolve your current Splunk application and its monitoring capabilities. Finally, we round things off with the discussion of transactions from an enterprise perspective.
You'll now be able to apply and integrate advanced techniques of Splunk to optimize your data and meet your strategic organizational demands.
What You Will Learn
- Get started in the most efficient way, become proficient, and ultimately master Splunk
- Master the techniques to create advanced-level Splunk search strings
- Easily leverage advanced tables, charts, and fields to organize your data
- Understand Splunk lookups and how they relate to enterprise development
- Build practical dashboards with your data
- Acquire master-level understanding of Splunk indexes and indexing
- Build your own Splunk apps and learn why they are important
- Compare Splunk's abilities with other monitoring tools in terms of monitoring data and alerts
- Understand what Splunk transactions are and how to use them to optimize your corporate data
Table of contents
-
Mastering Splunk
- Table of Contents
- Mastering Splunk
- Credits
- About the Author
- About the Reviewers
- www.PacktPub.com
- Preface
-
1. The Application of Splunk
- The definition of Splunk
- Universal file handling
- Confidentiality and security
- Conventional use cases
-
Splunk – outside the box
- Customer Relationship Management
- Emerging technologies
- Knowledge discovery and data mining
- Disaster recovery
- Virus protection
- The enhancement of structured data
- Project management
- Firewall applications
- Enterprise wireless solutions
- Hadoop technologies
- Media measurement
- Social media
- Geographical Information Systems
- Mobile Device Management
- Splunk in action
- Summary
-
2. Advanced Searching
-
Searching in Splunk
- The search dashboard
- The new search dashboard
- The Splunk search mechanism
- The Splunk quick reference guide
- Please assist me, let me go
- Basic optimization
- Fast, verbose, or smart?
- The breakdown of commands
- Understanding the difference between sparse and dense
- Searching for operators, command formats, and tags
- The process flow
- Boolean expressions
- You can quote me, I'm escaping
- Tag me Splunk!
- Transactional searching
- Knowledge management
- Subsearching
- Searching with parameters
- Splunk macros
- Search results
- Summary
-
Searching in Splunk
- 3. Mastering Tables, Charts, and Fields
-
4. Lookups
- Introduction
-
Configuring a simple field lookup
- Defining lookups in Splunk Web
- Automatic lookups
- Configuration files
- Implementing a lookup using configuration files – an example
- Populating lookup tables
- Handling duplicates with dedup
- Dynamic lookups
- Using Splunk Web
- Using configuration files instead of Splunk Web
- Time-based lookups
- Seeing double?
- Command roundup
- Summary
-
5. Progressive Dashboards
- Creating effective dashboards
- Form searching
-
Going back to dashboards
- The Panel Editor
- The Visualization Editor
- Let's walk through the Dashboard Editor
-
Constructing a dashboard
- Constructing the framework
- Adding panels and panel content
- Specifying visualizations for the dashboard panel
- Adding panels to your dashboard
- Controlling access to your dashboard
- Cloning and deleting
- Keeping in context
- Some further customization
- Using panels
- Adding and editing dashboard panels
- Visualize this!
- Dashboards and XML
- Color my world
- More on searching
- Dynamic drilldowns
- Real-world, real-time solutions
- Summary
- 6. Indexes and Indexing
-
7. Evolving your Apps
- Basic applications
- BYO or build your own apps
- App FAQs
- The end-to-end customization of Splunk
- Preparation for app development
- Summary
-
8. Monitoring and Alerting
- What to monitor
- Advanced monitoring
- Location, location, location
- Leveraging your forwarders
- Can I use apps?
- Windows inputs in Splunk
- Getting started with monitoring
- What does Splunk do with the data it monitors?
- Splunk
- Viewing the Splunk Deployment Monitor app
- All about alerts
- Editing alerts
- Scheduled or real time
- Extended functionalities
- Summary
- 9. Transactional Splunk
- 10. Splunk – Meet the Enterprise
-
A. Quick Start
- Topics
- Where and how to learn Splunk
- Certifications
- The Splunk documentation
- www.splunk.com
- Splunk answers
- Splunkbase
- The support portal
- The Splexicon
- The "How-to" tutorials
- User conferences, blogs, and news groups
- Professional services
- Obtaining the Splunk software
- An environment to learn in
- Summary
- Index
Product information
- Title: Mastering Splunk
- Author(s):
- Release date: December 2014
- Publisher(s): Packt Publishing
- ISBN: 9781782173830
You might also like
video
Learning Splunk
Maybe you've heard about Splunk, but don't know how to use it to take control of …
video
Splunk for Beginners: Make the Most of Machine Data Using Splunk
Splunk offers extensive flexibility in the enterprise edition to help developers build robust applications. The development …
book
Advanced Splunk
Master the art of getting the maximum out of your machine data using Splunk About This …
video
Practical Splunk for Beginners
4+ Hours of Video Instruction Description Hands-on approach to learning the Splunk platform to search, report, …