[splunk] Intro Splulnk

zyeon·2022년 8월 5일


목록 보기

Topic 1 – Intro to Splunk

▪ Splunk components

▪ Basic Splunk functions

Topic 2 – Using Splunk

▪ Define Splunk apps

▪ Understand Splunk user roles

▪ Search & Reporting app

▪ Splunk Web interface

Topic 3 – Using Search

▪ Run basic searches

▪ Save search results

▪ Identify the contents of search results

▪ Work with events

▪ Share search jobs

▪ Export search results

▪ Select search modes

▪ Control a search job

Topic 4 - Exploring Events

▪ Refine searches

▪ Understand timestamps

Topic 5 – Search Processing Language

▪ Use wildcards to search for multiple terms

▪ Understand case sensitivity in searches

▪ Use booleans to include and exclude search criteria

▪ Use special characters with search terms

Topic 6 – What are Commands?

▪ Understand the anatomy of Splunk's search language:

o Search terms
o Commands
o Functions
o Arguments
o Clauses

▪ Understand best practices for writing searches

Topic 7 – What are Knowledge Objects?

▪ Identify the five categories of knowledge objects:

o Data interpretation
o Data classification
o Data Enrichment
o Data Normalization
o Data Models
▪ Understand types of knowledge objects

Topic 8 – Creating Reports and Dashboards

▪ Save a search as a report

▪ Edit reports

▪ Use transforming commands to create visualizations

▪ Create a dashboard

▪ Add a report to a dashboard

▪ Edit a dashboard


1개의 댓글

2022년 8월 9일

I look forward to your next article : )

답글 달기