万本电子书0元读

万本电子书0元读

顶部广告

Splunk 7 Essentials - Third Edition电子书

售       价:¥

4人正在读 | 0人评论 9.8

作       者:J-P Contreras,Erickson Delgado,Betsy Page Sigman

出  版  社:Packt Publishing

出版时间:2018-03-29

字       数:18.4万

所属分类: 进口书 > 外文原版书 > 电脑/网络

温馨提示:数字商品不支持退换货,不提供源文件,不支持导出打印

为你推荐

  • 读书简介
  • 目录
  • 累计评论(0条)
  • 读书简介
  • 目录
  • 累计评论(0条)
Transform machine data into powerful analytical intelligence using Splunk About This Book ? Analyze and visualize machine data to step into the world of Splunk! ? Leverage the exceptional analysis and visualization capabilities to make informed decisions for your business ? This easy-to-follow, practical book can be used by anyone - even if you have never managed data before Who This Book Is For This book is for the beginners who want to get well versed in the services offered by Splunk 7. If you want to be a data/business analyst or want to be a system administrator, this book is what you want. No prior knowledge of Splunk is required. What You Will Learn ? Install and configure Splunk for personal use ? Store event data in Splunk indexes, classify events into sources, and add data fields ? Learn essential Splunk Search Processing Language commands and best practices ? Create powerful real-time or user-input dashboards ? Be proactive by implementing alerts and scheduled reports ? Tips from the Fez: best practices using Splunk features and add-ons ? Understand security and deployment considerations for taking Splunk to an organizational level In Detail Splunk is a search, reporting, and analytics software platform for machine data, which has an ever-growing market adoption rate. More organizations than ever are adopting Splunk to make informed decisions in areas such as IT operations, information security, and the Internet of Things. The first two chapters of the book will get you started with a simple Splunk installation and set up of a sample machine data generator, called Eventgen. After this, you will learn to create various reports, dashboards, and alerts. You will also explore Splunk's Pivot functionality to model data for business users. You will then have the opportunity to test-drive Splunk's powerful HTTP Event Collector. After covering the core Splunk functionality, you'll be provided with some real-world best practices for using Splunk, and information on how to build upon what you've learned in this book. Throughout the book, there will be additional comments and best practice recommendations from a member of the SplunkTrust Community, called "Tips from the Fez". Style and approach This fast-paced, example-rich guide will help you analyze and visualize machine data with Splunk through simple, practical instructions and recommendations.
目录展开

Title Page

Copyright and Credits

Splunk 7 Essentials Third Edition

Packt Upsell

Why subscribe?

PacktPub.com

Contributors

About the authors

About the reviewers

Packt is searching for authors like you

Preface

Who this book is for

What this book covers

To get the most out of this book

Download the example code files

Download the color images

Conventions used

Get in touch

Reviews

Splunk – Getting Started

Your Splunk account

Obtaining a Splunk account

Installing Splunk on Windows

Installing Splunk on Linux

Logging in for the first time

Running a simple search

Creating a Splunk app

Populating data with Eventgen

Using the CLI to configure Eventgen

Installing the Eventgen add-on (Windows and Linux)

Controlling Splunk

Configuring Eventgen

Viewing the Destinations app

Creating your first dashboard

Summary

Bringing in Data

Splunk and big data

Streaming data

Analytical data latency

Sparseness of data

Splunk data sources

Machine data

Web logs

Data files

Social media data

Relational database data

Other data types

Creating indexes

Buckets

Log files as data input

Splunk events and fields

Extracting new fields

Summary

Search Processing Language

Anatomy of a search

Search pipeline

Time modifiers

Filtering search results

Search command – stats

Search command – top/rare

Search commands – chart and timechart

Search command – eval

Search command – rex

Summary

Reporting, Alerts, and Search Optimization

Data classification with Event Types

Data normalization with Tags

Data enrichment with Lookups

Creating and scheduling reports

Creating alerts

Search and Report acceleration

Scheduling options

Summary indexing

Summary

Dynamic Dashboarding

Creating effective dashboards

Types of dashboards

Gathering business requirements

Dynamic form-based dashboard

Creating a Status Distribution panel

Creating the Status Types Over Time panel

Creating the Hits vs Response Time panel

Arrange the dashboard

Panel options

Pie chart – Status Distribution

Stacked area chart – Status Types Over Time

Column with overlay combination chart – Hits vs Response Time

Form inputs

Creating a time range input

Creating a radio input

Creating a drop-down input

Static real-time dashboard

Single-value panels with color ranges

Creating panels by cloning

Single-value panels with trends

Real-time column charts with line overlays

Creating a choropleth map

Summary

Data Models and Pivot

Creating a data model

Adding attributes to objects

Creating child objects

Creating an attribute based on a regular expression

Data model acceleration

The Pivot editor

Creating a Pivot and a chart

Creating an area chart

Creating a pie chart

Single value with trending sparkline

Rearranging your dashboard

Summary

HTTP Event Collector

What is the HEC?

How does the HEC work?

How data flows to the HEC

Logging data

Using a token with data

Sending out the data request

Verifying the token

Indexing the data

Enabling the HEC

Generating an HEC authentication token

Seeing the HEC in action with cURL

Indexer acknowledgement

Summary

Best Practices and Advanced Queries

Indexes for testing

Searching within an index

Search within a limited time frame

Quick searches via fast mode

Using event sampling

Use the fields command to improve search performance

Advanced searches

Subsearch

Using append

Using join

Using eval and if

Using eval and match with a case function

Summary

Taking Splunk to the Organization

Common organizational use cases

IT operations

Cybersecurity

Software development and support operations

Internet of Things

Splunk architecture considerations

Splunk architecture for an organization

Search capacity

Indexing capacity and data replication

High availability for critical environments

Monitoring Console

Forwarders

Universal forwarder

Heavy forwarder

Splunk Cloud

Splunk pricing model

The Splunk community and online resources

Summary

累计评论(0条) 0个书友正在讨论这本书 发表评论

发表评论

发表评论,分享你的想法吧!

买过这本书的人还买过

读了这本书的人还在读

回顶部