Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Splunk Search and Reporting
Rating: 3.3 out of 5(9 ratings)
84 students

Splunk Search and Reporting

Splunk Search and Reporting and Basic Syntax
Created byPraveen Soni
Last updated 9/2021
English

What you'll learn

  • Fields, Interesting fields, extracted fields
  • Search and Reporting basics
  • Search and reporting syntax
  • Search Modes
  • Report and Alert creation
  • Dashboard creation

Course content

1 section11 lectures4h 14m total length
  • Introduction2:53
  • Search and Reporting Basics34:08
  • Fields,Search Modes,Interesting and selected fields32:58
  • Search Best Practices19:42
  • Splunk Search Language,Syntax and its components.Commands table53:12
  • Type Of Commands, Transforming Commands, top, rare and its functions13:55
  • Transforming Commands, stats Command, its functions and table formatting21:32
  • Splunk Reports, Creating and Working With Splunk Reports26:33
  • Splunk Dashboard, Creating and Working With Dashboards16:27
  • Scheduling Splunk Reports, Sending Reports to Your Inbox11:50

    Learn to schedule Splunk reports and alerts, choose frequency and time windows, and automatically email results with optional report links and notifications.

  • Splunk Alerts, Creating and Scheduling Alerts, Working with Alerts21:04

Requirements

  • Non

Description

This course is intended to explain the basics of search and reporting. This will help you start with search and reporting.Also help you do understand the basics about the fields. You can create complex search queries by following the best practise.

By default, Splunk Enterprise provides the Search and Reporting app. This interface provides the core functionality of Splunk Enterprise. The Splunk Home page provides a view to the app when you first log into Splunk Web.


It has default app as search and reporting by which you interact with the data, and create reports, alerts, Dashboard etc.

Log processing is one of the core competencies of Splunk. It stores all your logs and provides very fast search capabilities roughly in the same way Google does for the internet device log files.

The Search Processing Language (SPL) for Splunk is an extremely powerful tool for extracting meaning out of vast amounts of data and performing statistical operations on what is relevant in a specific context.

Splunk indexes any kind of machine data that can be represented as text and there is no need to define tables and fields before you can store data. Splunk does not have a fixed schema. In fact, it performs field extraction at search time. This aspect allows for great flexibility.

It does not reduce the granularity of older events, compressing many data points into one because of capacity limits. It can seamlessly index hundreds of terabytes per day and keep practically unlimited amounts of data.

Splunk dashboards allow you to monitor all of your systems at once, so when a problem occurs you can start looking for a solution even before the problem starts bothering the system, or even better, its dashboard allows to clearly look for signs of a possibly arising problem.

Who this course is for:

  • Splunk Search and Reporting