1 Splunk 9: Creating Data Models and Optimizing Pivot - by Adam Frisbee *
2 Getting Familiar with Data Models and the Pivot Tool in Splunk
2.1 Getting Familiar with Data Models and the Pivot Tool in Splunk
2.2 Event Types, Lookups, Tags, and Aliases
2.3 Introducing the Splunk Pivot Tool
3 Diving Deeper into Data Models
3.1 The Benefits of Modeling Data]
3.2 The Ingredients of a Data Model
3.3 Data Model Configuration Files
3.5 Demo: Examine a Data Model in JSON
3.9 Business Requirements and Our Scenario
4 Using the Pivot Tool to Build Dashboards, Reports, and Alerts from a Data Model
4.2 Visualization Types and Their Uses
4.3 Demo: Create Dashboards, Reports, and Alerts Based on Our Data Model
Splunk 9: Creating Data Models and Optimizing Pivot - by Adam Frisbee *
Course Overview
Getting Familiar with Data Models and the Pivot Tool in Splunk
Getting Familiar with Data Models and the Pivot Tool in Splunk
With = sign
Pattern
Values with no explicit key
Event Types, Lookups, Tags, and Aliases
Eval used one field name for multiple field results
Introducing the Splunk Pivot Tool
Demo: Splunk Pivot Tool
Search > Datasets >
Choose data set > visualize
Summary
Diving Deeper into Data Models
Do this excercises
The Benefits of Modeling Data]
The Ingredients of a Data Model
Data Model Configuration Files
Default directory has lowest precedence.
Data Model Acceleration
Demo: Examine a Data Model in JSON
Data Models are either global or associated with App
Settings > Data Modeal >
Bin directory for all splunk executables, exe directory for splunk licensing info, var directory for all of the indexes
C:\Program Files\Splunk\etc\apps\search\default in windows
Config files is available in
Json file C:\Program Files\Splunk\etc\apps\search\default\data\models\
internal_audit_logs.json
internal_server.json
Data Model Datasets
Dataset Field Categories
Field Extractions
Business Requirements and Our Scenario
Demo: Build a Data Model
Add Data
Add Data - Upload – mack_data.csv – next
Next
Host field value = mock_data, index = default (we can choose mockdata
Add Lookup
Go to look up file – change the permsion
Do Lookup Defnition
Set up data model
Settings – Data Model – New data model
Choose Root Event –
Save then the next screen comes
Add the required fields based on the business requirements
We need to get only Ad_Click=Yes > we need root search event
Add another field from broad dataset – choose auto extracted
This satisfieds our first requirement
Add other fields from broad events for our use case
Change revenue field to number
This Data moldel is the appications requirements –
Module Summary
Using the Pivot Tool to Build Dashboards, Reports, and Alerts from a Data Model
Pivot Table Elements
Visualization Types and Their Uses
Demo: Create Dashboards, Reports, and Alerts Based on Our Data Model
In the data modal click Pivot
Available data sets are :
Click Broad
Income range
Nice dashboard and set the dashboard as home dashboard
Course Wrap Up
s
No comments:
Post a Comment