Splunk Search Expert Fast Start

Splunk Search Expert Fast Start

Upcoming Classes

Online

Instructor-led online training

Location Oct 2022 Nov 2022 Dec 2022 Jan 2023 Feb 2023 Mar 2023 Apr 2023
AMER Pacific Time - Virtual Oct 19 – Oct 21
Nov 30 – Dec 2
Jan 11 – Jan 13
AMER Eastern Time - Virtual Oct 24 – Oct 26
Dec 14 – Dec 16
Jan 18 – Jan 20
EMEA UK Time - Virtual Nov 28 – Nov 30
Jan 25 – Jan 27

Summary

This "Fast Start" course covers over 60 commands and functions and prepares students to be search experts. Students will learn how to effectively utilize time in searches, work with different time zones, use transforming commands and eval functions to calculate statistics, compare field values with eval functions and eval expressions, manipulate output, normalize fields and field values, use lookups and subsearches to enrich results, and correlate and filter data from multiple sources.

This class will take place over three 6-hour days (plus a 1-hour break each day)

Description

  • Working with Time
  • Statistical Processing
  • Comparing Values
  • Result Modification
  • Leveraging Lookups and Subsearches
  • Correlation Analysis

 

Duration

3 Days

Objectives

Topic 1 – Working with Time

  • Searching with Time
  • Formatting Time
  • Comparing index Time versus Search Time
  • Using Time Commands
  • Working with Time Zones

Topic 2 – Statistical Processing

  • What is a Data Series?
  • Transforming Data
  • Manipulating Data with eval
  • Formatting Data

Topic 3 – Comparing Values

  • Using eval to Compare
  • Filtering with where

Topic 4 – Result Modification

  • Manipulating Output
  • Modifying REsults Sets
  • Managing Missing Data
  • Modifying Field Values
  • Normalizing with eval

Topic 5 – Leveraging Lookups and Subsearches

  • Using Lookup Commands
  • Adding a Subsearch
  • Using the return Command

Topic 6 - Correlation Analysis

  • Caclulate Co-Occurance Between Fields
  • Analyze Multiple Datasets

Prerequisites

To be successful, students should have a solid understanding of the following:

  • How Splunk Works
  • Creating Search queries
  • Knowledge objects (specifically reports, lookups, and fields)

OR have taken the following:

  • Foundation Fast Start OR
  • What is Splunk, Intro to Splunk and Using Fields

Onsite Training

For groups of three or more

Request Quote

Public Training

AMER Pacific Time - Virtual

AMER Eastern Time - Virtual

EMEA UK Time - Virtual


Don't see a date that works for you?

Request Class