Search This Blog

Saturday, March 16, 2024

05_PS_Splunk 9 Optimizing Fields, Tags, and Event Types

 Contents

1 *Splunk 9: Optimizing Fields, Tags, and Event Types - Course Overview

2 Understanding Splunk Knowledge

2.1 Let’s Talk About Splunk!

2.2 Understanding Splunk Knowledge

2.3 The Splunk Search Operations

2.4 Optimizing Knowledge Objects

2.5 Managing Knowledge Objects

2.6 Splunk Data Enrichment

3 *Customizing Splunk Fields

3.1 Managing Splunk Fields

3.2 Creating Fields in Splunk

3.3 Using Calculated Fields in Splunk

3.4 Creating Calculated Fields in Splunk

3.5 Introducing the Field Extraction Process

3.6 Working with the Field Extractor in Splunk

4 Using Tags and Event Types

4.1 Introducing Tags and Event Types

4.2 Using Tags in Splunk

4.3 Creating Tags in Splunk

4.4 Using Event Types in Splunk

4.5 Creating Event Types in Splunk – Demo

5 Enriching Splunk Knowledge

5.1 Exploring Splunk Lookups

5.2 Creating and Using Splunk Lookups

5.3 Detailing Splunk Scripted Lookups

5.4 Creating and Using Scripted Lookups (External Lookup)

5.5 Understanding Geospatial Lookups

5.6 Configuring Splunk for Geo Lookups

6 Utilizing Search Macros

6.1 Understanding Splunk Macros

6.2 Creating and Using Simple Macros

6.3 Configuring Macros with Variables and Arguments

6.4 Reviewing Splunk Knowledge Objects

6.5 Searching Efficiently Using Knowledge Objects

6.6 Wrapping up Splunk Knowledge Optimization


  1. *Splunk 9: Optimizing Fields, Tags, and Event Types - Course Overview

A screenshot of a computer screen

Description automatically generated





  1. Understanding Splunk Knowledge

    1. Let’s Talk About Splunk!

A group of rectangular black boxes with white text

Description automatically generated

  1. Understanding Splunk Knowledge

A close-up of a white background

Description automatically generated


During searches - Index time or search time knowledge created

A screenshot of a phone

Description automatically generated

And etc.,

A colorful rectangular boxes with text

Description automatically generated

A diagram of a building blocks

Description automatically generated with medium confidence


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


  1. The Splunk Search Operations

A screenshot of a white and orange chart

Description automatically generated


A close-up of a search table

Description automatically generated

A close-up of a white background

Description automatically generated

  1. Optimizing Knowledge Objects

A screenshot of a screen

Description automatically generated


A green square with white text

Description automatically generated


A white background with orange text

Description automatically generated

  1. Managing Knowledge Objects

A screenshot of a computer

Description automatically generated


A person standing in front of a white background

Description automatically generated

A blue and white background with text

Description automatically generated


Settings – All configurations




  1. Splunk Data Enrichment

A screenshot of a web page

Description automatically generated

A purple background with white text

Description automatically generated



  1. *Customizing Splunk Fields

Watch one more time

  1. Managing Splunk Fields

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A diagram of a data processing process

Description automatically generated with medium confidence


A screenshot of a computer

Description automatically generated

  1. Creating Fields in Splunk

A blue and white rectangle with text

Description automatically generated


A screenshot of a computer

Description automatically generated

Naming conventions to be standardized

  1. Using Calculated Fields in Splunk

A close-up of a text

Description automatically generated


A screenshot of a calculator

Description automatically generated

A screenshot of a computer program

Description automatically generated


How can we get all calculated fields?

  1. Creating Calculated Fields in Splunk

A screenshot of a computer

Description automatically generated


  1. Introducing the Field Extraction Process

A field extraction types

Description automatically generated


Inline – using regex or delimitter

Settings > Fields > Fiedld Extractions 

A screenshot of a computer

Description automatically generated

Splunk_TA_Windows ???

A screenshot of a computer

Description automatically generated


 


  1. Working with the Field Extractor in Splunk

Open Field Extractor >

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated


A diagram of a field

Description automatically generated with medium confidence


  1. Using Tags and Event Types

    1. Introducing Tags and Event Types

A screenshot of a computer

Description automatically generated


A blue background with white text

Description automatically generated

  1. Using Tags in Splunk


A screenshot of a computer

Description automatically generated


Settings > Tags > Add New

A screenshot of a computer

Description automatically generated


Or Add Tags from Search Results

A screenshot of a search results

Description automatically generated


A screenshot of a computer program

Description automatically generated


 

A white background with black text

Description automatically generated


  • Event types if we collect more data every day



  1. Creating Tags in Splunk

Settings > Tag > List by Tag Name > New Tag

A screenshot of a computer

Description automatically generated



  1. Using Event Types in Splunk

A screenshot of a computer

Description automatically generated


Automatically find event types for given index

A screenshot of a computer

Description automatically generated

???

A screenshot of a program

Description automatically generated



  1. Creating Event Types in Splunk – Demo

Settings > EventTypes

Combination of some items which we can see in Search string

Add New

First write search string and check in search then use it in EventTypes definition to narrow down

A screenshot of a computer

Description automatically generated


A screenshot of a search engine

Description automatically generated



A table with text and black text

Description automatically generated with medium confidence





  1. Enriching Splunk Knowledge

    1. Exploring Splunk Lookups

A black text on a white background

Description automatically generated


A screenshot of a phone

Description automatically generated


A screenshot of a computer

Description automatically generated


A table with text on it

Description automatically generated

A screenshot of a computer

Description automatically generated



  1. Creating and Using Splunk Lookups

Settings > Lookups

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


  1. Add Lookup file

  2. Defin Lookup definition – familiar with Type


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated

A screenshot of a computer program

Description automatically generated

??? how to delete the uploaded file with index

???Search – if we add more condition the search will be faster

  1. Detailing Splunk Scripted Lookups

A white paper with black text

Description automatically generated


A graphic of a data storage

Description automatically generated with medium confidence


A screenshot of a computer

Description automatically generated


A purple background with white text

Description automatically generated

  1. Creating and Using Scripted Lookups (External Lookup)

Check external_lookup.py 



  1. Understanding Geospatial Lookups

A close-up of a map

Description automatically generated

  1. Configuring Splunk for Geo Lookups


| inputlookup geo_countries

| inputlookup geo_us_states

Settings > Lookups > GeoIP lookups file 

A screenshot of a computer

Description automatically generated

Get the file from https://www.maxmind.com/en/home - we can create account to use their database

A screenshot of a computer

Description automatically generated

Upload required of file in splunk 

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated






  1. Utilizing Search Macros

    1. Understanding Splunk Macros

A black text on a white background

Description automatically generated

A black and white text

Description automatically generated


A white background with black text

Description automatically generated





  1. Creating and Using Simple Macros

Settings > Advanced search > Search Macro > 

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screen shot of a computer

Description automatically generated

Macro surrounded by “`”

To see macro definition in search itself > CTRL+SHIFT+E

A screenshot of a computer

Description automatically generated







CLI

  1. Configuring Macros with Variables and Arguments

Settings > Advanced Search > Search Macros > Add New

A screenshot of a computer

Description automatically generated





  1. Reviewing Splunk Knowledge Objects

A close-up of a white background

Description automatically generated


A screenshot of a computer

Description automatically generated


A white paper with black text

Description automatically generated



  1. Searching Efficiently Using Knowledge Objects

Not completed with understanding

A blue text on a white background

Description automatically generated

  • Creating a new macro



  1. Wrapping up Splunk Knowledge Optimization

A screenshot of a website

Description automatically generated



No comments:

Post a Comment