You can create your Splunk reports without having to use the Splunk Enterprise Search Processing Language (SPL) by utilizing the Splunk pivot tool.

Splunk pivot is a simple drag-and-drop interface that uses (predefined) data models and data model objects. These data models (designed by the knowledge managers in an organization and discussed later in this book) are used by the pivot tool to define, subdivide, and set attributes for the event data you are interested in.

You can create a Splunk pivot table by following these steps:

  1. Go to the Splunk Home page and click on Pivot for the app workspace you want to use:
  2. Next, from the Select a Data Model ...

Get Mastering Splunk now with the O’Reilly learning platform.

O’Reilly members experience live online training, plus books, videos, and digital content from nearly 200 publishers.