Limit search to available items
Book Cover
E-book
Author Contreras, J-P, author

Title Splunk 7 essentials : demystify machine data by leveraging datasets, building reports, and sharing powerful insights / J-P Contreras, Erickson Delgado, Betsy Page Sigman
Edition Third edition
Published Birmingham, UK : Packt Publishing, 2018
©2018

Copies

Description 1 online resource (1 volume) : illustrations
Contents Cover; Title Page; Copyright and Credits; Packt Upsell; Contributors; Table of Contents; Preface; Chapter 1: Splunk -- Getting Started; Your Splunk account; Obtaining a Splunk account; Installing Splunk on Windows; Installing Splunk on Linux; Logging in for the first time; Running a simple search; Creating a Splunk app; Populating data with Eventgen; Using the CLI to configure Eventgen; Installing the Eventgen add-on (Windows and Linux); Controlling Splunk; Configuring Eventgen; Viewing the Destinations app; Creating your first dashboard; Summary; Chapter 2: Bringing in Data
Splunk and big dataStreaming data; Analytical data latency; Sparseness of data; Splunk data sources; Machine data; Web logs; Data files; Social media data; Relational database data; Other data types; Creating indexes; Buckets; Log files as data input; Splunk events and fields; Extracting new fields; Summary; Chapter 3: Search Processing Language; Anatomy of a search; Search pipeline; Time modifiers; Filtering search results; Search command -- stats; Search command -- top/rare; Search commands -- chart and timechart; Search command -- eval; Search command -- rex; Summary
Chapter 4: Reporting, Alerts, and Search OptimizationData classification with Event Types; Data normalization with Tags; Data enrichment with Lookups; Creating and scheduling reports; Creating alerts; Search and Report acceleration; Scheduling options; Summary indexing; Summary; Chapter 5: Dynamic Dashboarding; Creating effective dashboards; Types of dashboards; Gathering business requirements; Dynamic form-based dashboard; Creating a Status Distribution panel; Creating the Status Types Over Time panel; Creating the Hits vs Response Time panel; Arrange the dashboard; Panel options
Pie chart -- Status DistributionStacked area chart -- Status Types Over Time; Column with overlay combination chart -- Hits vs Response Time; Form inputs; Creating a time range input; Creating a radio input; Creating a drop-down input; Static real-time dashboard; Single-value panels with color ranges; Creating panels by cloning; Single-value panels with trends; Real-time column charts with line overlays; Creating a choropleth map; Summary; Chapter 6: Data Models and Pivot; Creating a data model; Adding attributes to objects; Creating child objects
Creating an attribute based on a regular expressionData model acceleration; The Pivot editor; Creating a Pivot and a chart; Creating an area chart; Creating a pie chart; Single value with trending sparkline; Rearranging your dashboard; Summary; Chapter 7: HTTP Event Collector; What is the HEC?; How does the HEC work?; How data flows to the HEC; Logging data; Using a token with data; Sending out the data request; Verifying the token; Indexing the data; Enabling the HEC; Generating an HEC authentication token; Seeing the HEC in action with cURL; Indexer acknowledgement; Summary
Summary Transform machine data into powerful analytical intelligence using Splunk Key Features Analyze and visualize machine data to step into the world of Splunk! Leverage the exceptional analysis and visualization capabilities to make informed decisions for your business This easy-to-follow, practical book can be used by anyone - even if you have never managed data before Book Description Splunk is a search, reporting, and analytics software platform for machine data, which has an ever-growing market adoption rate. More organizations than ever are adopting Splunk to make informed decisions in areas such as IT operations, information security, and the Internet of Things. The first two chapters of the book will get you started with a simple Splunk installation and set up of a sample machine data generator, called Eventgen. After this, you will learn to create various reports, dashboards, and alerts. You will also explore Splunk's Pivot functionality to model data for business users. You will then have the opportunity to test-drive Splunk's powerful HTTP Event Collector. After covering the core Splunk functionality, you'll be provided with some real-world best practices for using Splunk, and information on how to build upon what you've learned in this book. Throughout the book, there will be additional comments and best practice recommendations from a member of the SplunkTrust Community, called "Tips from the Fez". What you will learn Install and configure Splunk for personal use Store event data in Splunk indexes, classify events into sources, and add data fields Learn essential Splunk Search Processing Language commands and best practices Create powerful real-time or user-input dashboards Be proactive by implementing alerts and scheduled reports Tips from the Fez: best practices using Splunk features and add-ons Understand security and deployment considerations for taking Splunk to an organizational level Who this book is for This book is for the beginners who want to get well versed in the services offered by Splunk 7. If you want to be a data/business analyst or want to be a system administrator, this book is what you want. No prior knowledge of Splunk is required
Bibliography Includes bibliographical references
Notes Online resource; title from digital title page (viewed on July 29, 2019)
Subject Big data.
Data mining.
Automatic data collection systems.
Data Mining
Operational research.
Database design & theory.
Data capture & analysis.
Information architecture.
Enterprise software.
Computers. -- Data Processing.
Computers. -- Data Modeling & Design.
Computers. -- Enterprise Applications -- Business Intelligence Tools.
Automatic data collection systems
Big data
Data mining
Form Electronic book
Author Sigman, Betsy Page, author
Delgado, Erickson, author
ISBN 9781788830126
1788830121
Other Titles Splunk seven essentials