Converging data sources

Context is everything when it comes to building successful Operational Intelligence, and when you are stuck analyzing events from a single data source at a time, you might be missing out on rich contextual information that other data sources can provide. With Splunk's ability to converge multiple data sources using the join or append search commands and search across them as if they are a single source, you can easily enrich the single data source and understand events from other sources that occurred at, or around, the same time.

For example, you might notice there are more timeouts than usual on your website, but when you analyze the website access log, everything appears normal. However, when you look at the application ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.