In Chapter 1, you learned about Splunk’s architecture, history, inception, and salient features. You saw a roadmap for the Splunk Enterprise Certified Admin exam and were introduced to Splunk in a nutshell. You installed Splunk on macOS or Windows and went through the process to add data to it. In this chapter, you take a deep dive into the Splunk Search Processing Language and the methods to analyze data using Splunk.
Splunk’s Search Processing Language (SPL) is a user-friendly language developed to search data that has been indexed in Splunk. The language is based on Unix ...