更新时间:2021-07-08 11:47:57
封面
版权页
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Why subscribe?
Preface
What this book covers
What you need for this book
Who this book is for
Conventions
Reader feedback
Customer support
Chapter 1. Splunk in Action
Your Splunk.com account
Installing Splunk on Windows
Creating a Splunk app
Populating data with Eventgen
Controlling Splunk
Configuring Eventgen
Viewing the Destinations app
Creating your first dashboard
Summary
Chapter 2. Bringing in Data
Splunk and big data
Splunk data sources
Creating indexes
Buckets
Data inputs
Splunk events and fields
Extracting new fields
Chapter 3. Search Processing Language
Anatomy of a search
Time modifiers
Filtering search results
Search command - stats
Search command - top/rare
Search commands - chart and timechart
Search command - eval
Search command - rex
Chapter 4. Data Models and Pivot
Creating a data model
Data model acceleration
Rearranging your dashboard
Chapter 5. Data Optimization Reports Alerts and Accelerating Searches
Data classification with event types
Data normalization with tags
Data enrichment with lookups
Creating reports
Creating alerts
Search and report acceleration
Scheduling best practices
Summary indexing
Chapter 6. Panes of Glass
Creating effective dashboards
Types of dashboard
Form inputs
Creating a time range input
Creating a radio input
Creating a dropdown input
Static Real-Time dashboard
Creating a map called a choropleth
Chapter 7. Splunk SDK for JavaScript and D3.js
Introduction to Splunk SDKs
Practical applications of Splunk's SDK
Creating the final dashboard\jobs.js
Chapter 8. HTTP Event Collector
What is the HEC?
How does the HEC work?
How data flows to the HEC?
Chapter 9. Best Practices and Advanced Queries
Temporary indexes and oneshot indexing
Searching within an index
Search within a limited time frame
Quick searches via fast mode
Using event sampling
Splunk Universal Forwarders
Advanced queries
How to improve logs