Advanced Searching and Reporting with Splunk 8.0.1

Advanced Searching and Reporting with Splunk 8.0.1

Upcoming Classes

Online

Instructor-led online training

Location Oct 2020 Nov 2020 Dec 2020 Jan 2021 Feb 2021 Mar 2021 Apr 2021
AMER Pacific Time - Virtual Nov 4 – Nov 6
Nov 11 – Nov 13
Nov 18 – Nov 20
Dec 2 – Dec 4
Dec 9 – Dec 11
Jan 6 – Jan 8
Jan 20 – Jan 22
AMER Eastern Time - Virtual Nov 11 – Nov 13
Dec 2 – Dec 4
Dec 16 – Dec 18
Jan 6 – Jan 8
Jan 13 – Jan 15
Jan 27 – Jan 29
EMEA UK Time - Virtual Dec 16 – Dec 18
Jan 20 – Jan 22
APAC Singapore - Virtual Dec 16 – Dec 18
Jan 20 – Jan 22

Australia

Location Oct 2020 Nov 2020 Dec 2020 Jan 2021 Feb 2021 Mar 2021 Apr 2021
Ingeniq - Online Nov 11 – Nov 13

Summary

This 13 hour course supplements the Splunk Fundamentals 3 class. It focuses on more advanced search and reporting commands. Scenario-based examples and hands-on challenges enable users to create robust searches, reports, and charts. Students are coached step by step through complex searches to produce final results. Major topics include optimizing searches, additional charting commands and functions, formatting and calculating results, correlating events, and using combined searches and subsearches.

Description

  • Using Search Efficiently
  • More Search Tuning
  • Manipulating and Filtering Data
  • Working with Multivalue Fields
  • Using Advanced Transactions
  • Working with Time
  • Using Subsearches
  • Combining Searches
  • Some Extra tips

Duration

3 Days

Objectives

Module 1 – Using Search Efficiently

  • Review search architecture
  • Understand how the components of a bucket (.tsidx an djournal.gz files) are used
  • How bloom filters are used to improve search speed
  • Understand the use of centralized vs. distributable commands

Module 2 – More Search Tuning

  • Understand how segmenters are used in Splunk
  • Use lispy to reduce the number of events read from disk
  • Use TERM directive to force Splunk to search for complete values
  • Understand how search-time and aliased fields affect disk reads

Module 3 – Manipulating Data

  • Divide search results into different groups, based on values in a specified field, using the bin command
  • Regroup fields of search results using untable and xyseries
  • Create a template for performing additional processing on a set of related fields using foreach

Module 4 – Working with Multivalue Fields

  • Use multivalue eval functions to analyze and format data
  • Use the makemv command to convert a single value into a multivalue field
  • Use the mvexpand command to create separate events for each value in a multivalue field

Module 5 – Using Advanced Transactions

  • Find events logged before or after a particular event occurs
  • Compare complete vs. incomplete transactions
  • Analyze transactions

Module 6 – Working with Time

  • Use time modifiers
  • Visualize data from two different time periods in one search
  • Search for events using custom time ranges and time windows
  • Display and use using relative dates

Module 7 – Using Subsearches

  • Use subsearches to provide filtering and other information to a main search
  • Know when NOT to use subsearches
  • Troubleshoot subsearches

Module 8 – Combining Searches

  • Use the append and appendcols commands (and know the differences)
  • Use join and union (and when not to use them)

Module 9 – Some Extra Tips

  • Describe the use of regular expressions
  • Provide some guidance on using lookups
  • Provide miscellaneous optimization tips
  •  

     

     

     

    Prerequisites

    • Splunk Fundamentals 1
    • Splunk Fundamentals 2
    • Splunk Fundamentals 3
    • Highly recommended: at least 6 months experience with the Splunk search language

    Onsite Training

    For groups of three or more

    Request Quote

    Public Training

    AMER Pacific Time - Virtual

    AMER Eastern Time - Virtual

    Chatswood, NSW

    EMEA UK Time - Virtual

    APAC Singapore - Virtual


    Don't see a date that works for you?

    Request Class