Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Splunk 7 Essentials
Rating: 3.5 out of 5(12 ratings)
73 students

Splunk 7 Essentials

Transform machine data into powerful analytical intelligence with Splunk
Last updated 7/2019
English
English [Auto],

What you'll learn

  • Explore what role each feature plays while installing and configuring Splunk
  • Store event data in Splunk indexes, classify events into sources and add data fields
  • Learn and use Splunk search processing language commands and best practices
  • Create powerful real-time or user-input dashboards
  • Discover security and deployment considerations while creating a Splunk environment
  • Create your own forms for custom visualization

Course content

8 sections48 lectures2h 25m total length
  • Course Overview4:05

    Throughout the course, we will be covering the fundamental concepts of Splunk so that you can learn quickly and efficiently. As the concepts become more complex, we reserve their deep discussion for Splunk's online documentation or the vibrant Splunk online community at http://docs.splunk.com. Wherever necessary, we provide links to help provide you with the practical skills and examples so that you can get started quickly. This course is for anyone who needs to get reports and analytics from machine data

  • Installation and Setup3:55

    Let’s get started with the installation and set up our environment.

  • Introduction to Splunk11:40

    Splunk is a search, reporting, and analytics software platform for machine data. More organizations than ever are adopting Splunk to make informed decisions in such areas as IT operations, information security, and the Internet of Things (IoT).

  • Lesson Overview1:23

    In this chapter, you will learn about Splunk and how it relates to an often-used term – big data, as well as the most common methods of ingesting data into Splunk. The chapter will also introduce essential concepts such as forwarders, indexes, events, event types, fields, sources, and source types. It is paramount that you learn this early on as it will empower you to get the most value from your data.

  • Splunk and Big Data3:24

    Big data is a widely used term but, as is often the case, one that means different things to different people. In this part of the chapter, we present common characteristics of big data.

  • Splunk Data Sources4:03

    Splunk was invented as a way to keep track of and analyze machine data coming from a variety of computerized systems. It is a powerful platform for doing just that. But since its invention, it has been used for a myriad of different data types, including streaming log data, database, and spreadsheet data, and data provided by web services. The various types of data that Splunk is often used for are explained in the next few sections.

  • Creating Indexes1:53

    Indexes are where Splunk Enterprise stores all the data it has processed. Let’s look at it in more detail.

  • Buckets1:45

    You may have noticed that there is a certain pattern in this configuration file, in which folders are broken into three locations: coldPath, homePath, and thawedPath. This is a very important concept in Splunk. An index contains compressed raw data and associated index files which are spread out into age-designated directories. Each age-designated directory is called a bucket.

  • Log Files as Data Input1:25

    Any configuration you make in the Splunk portal corresponds to a *.conf file written under the $SPLUNK_HOME directory. The same goes for the creation of data inputs; adding data inputs using the Splunk user interface creates a file called inputs.conf.

  • Splunk Events and Fields2:12

    All throughout this chapter, you have been running Splunk search queries that have returned data. It is important to understand what events and fields are before we go any further, for an understanding of these is essential to comprehend what happens when you run Splunk on the data.

  • Extracting New Fields1:08

    Most raw data that you will encounter will have some form of structure. Just like a CSV (comma-separated value) file or a weblog file, it is assumed that each entry in the log corresponds to some sort of format. Splunk makes custom field extraction very easy, especially for delimited files. Let’s look at it.

  • Lesson Summary0:36

    Let us summarize what we learned from this lesson.

  • Test your knowledge

Requirements

  • Prior knowledge of Splunk is not required to understand the concepts explained in the course.

Description

Splunk has evolved from a normal log monitoring tool to a de facto tool used in almost every enterprise, spanning from IT to security and even marketing.

This course will get you off to a steady start by helping you understand how to install Splunk and set up a sample machine data generator, called Eventgen. By learning how to create various reports, dashboards, and alerts, you’ll then be able to analyze and visualize your data with a completely new perspective. You’ll later explore how to model data for business users using Splunk's Pivot functionality. As you cover more chapters, you’ll get up to speed with testing Splunk's powerful HTTP Event Collector and send data to Splunk Enterprise and Splunk Cloud. After covering core Splunk functionality, you'll gain insights into some real-world best practices for using this technology. Throughout this fully updated edition, you’ll also come across ’Tips from the Fez’, which are additional comments and best practice recommendations from a member of the SplunkTrust Community.

By the end of this course, you’ll know exactly how to use the many features of Splunk to your advantage and transform your machine data into resourceful insights that positively affect business decisions.

About the Author

  • J-P Contreras, a Splunk-certified administrator and sales engineer, has delivered value-oriented data analytics and performance planning solutions for more than 20 years. He has built award-winning consulting teams to help companies turn data into analytical insights. He helps companies implement Splunk. He received his MBA in e-commerce from DePaul University's Kellstadt Graduate School of Business, Chicago, in 2001. He trains in DePaul's Continuing Education Program and is a member of DePaul's Driehaus School of Business Advisory Board.


  • Erickson Delgado is an enterprise architect living in Orlando who loves to mine and analyze data. He began using Splunk in version 4.0 and has pioneered its use into his current work. He has worked with start-up companies in the Philippines to help build their open-source infrastructure. He has developed applications with Python and Node.js, is interested in Go, and loves recovering programming with C/C++. In recent years, he engaged himself in employing DevOps in his work. He blows off steam by saltwater fishing, mountain biking, crafting robots, and touring the country.


  • Betsy Page Sigman is a distinguished professor at the McDonough School of Business at Georgetown University in Washington, D.C. She has taught courses in statistics, project management, databases, and electronic commerce for the last 16 years, and has been recognized with awards for teaching and service. She has also worked at George Mason University in the past. Her recent publications include a Harvard Business case study and a Harvard Business review article. Additionally, she is a frequent media commentator on technological issues and big data


  • Adam Frisbee is a 15 year IT veteran and holds an MS in Information Systems from the University of Utah, where he also teaches graduate and undergraduate classes in Information Systems. His expertise is in cloud computing, VMware, Splunk, data warehousing, systems analysis and design, networking and servers, and university-level teaching.

Who this course is for:

  • If you are an application developer who wants to understand the operational intelligence of your enterprise, this course will show you the way.
  • You will also find this course useful if you’re just getting started with Splunk and want to become well versed with the services offered by Splunk 7.