Search This Blog

Friday, March 22, 2024

09_Splunk 9 Creating Data Models and Optimizing Pivot

 1 Splunk 9: Creating Data Models and Optimizing Pivot - by Adam Frisbee *

1.1 Course Overview

2 Getting Familiar with Data Models and the Pivot Tool in Splunk

2.1 Getting Familiar with Data Models and the Pivot Tool in Splunk

2.2 Event Types, Lookups, Tags, and Aliases

2.3 Introducing the Splunk Pivot Tool

2.4 Demo: Splunk Pivot Tool

2.5 Summary

3 Diving Deeper into Data Models

3.1 The Benefits of Modeling Data]

3.2 The Ingredients of a Data Model

3.3 Data Model Configuration Files

3.4 Data Model Acceleration

3.5 Demo: Examine a Data Model in JSON

3.6 Data Model Datasets

3.7 Dataset Field Categories

3.8 Field Extractions

3.9 Business Requirements and Our Scenario

3.10 Demo: Build a Data Model

3.10.1 Add Data

3.10.2 Add Lookup

3.10.3 Do Lookup Defnition

3.10.4 Set up data model

3.11 Module Summary

4 Using the Pivot Tool to Build Dashboards, Reports, and Alerts from a Data Model

4.1 Pivot Table Elements

4.2 Visualization Types and Their Uses

4.3 Demo: Create Dashboards, Reports, and Alerts Based on Our Data Model

4.4 Course Wrap Up


  1. Splunk 9: Creating Data Models and Optimizing Pivot - by Adam Frisbee *

    1. Course Overview

A diagram of data model

Description automatically generated


A screenshot of a computer

Description automatically generated



  1. Getting Familiar with Data Models and the Pivot Tool in Splunk

    1. Getting Familiar with Data Models and the Pivot Tool in Splunk

A pink background with white text

Description automatically generated


A white background with black text

Description automatically generated


A screenshot of a computer

Description automatically generated


A orange circle with white text

Description automatically generated


A close-up of a number

Description automatically generated


With = sign

Pattern

Values with no explicit key 

A screenshot of a computer

Description automatically generated





  1. Event Types, Lookups, Tags, and Aliases

A screenshot of a computer

Description automatically generated


A yellow and purple circles with black text

Description automatically generated

A screenshot of a computer

Description automatically generated

A purple object with text

Description automatically generated

A diagram of a computer

Description automatically generated with medium confidence


Eval used one field name for multiple field results


A pink and orange rectangles with white text

Description automatically generated








  1. Introducing the Splunk Pivot Tool

A white background with black text

Description automatically generated

A pair of scissors with text

Description automatically generated


A close-up of a white background

Description automatically generated


A computer code with black text

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a data analysis

Description automatically generated


A group of colorful objects with text

Description automatically generated



  1. Demo: Splunk Pivot Tool

A blue and pink text on a white background

Description automatically generated


Search > Datasets > 

A screenshot of a computer

Description automatically generated


Choose data set > visualize 

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated



  1. Summary

A white background with black text

Description automatically generated

  1. Diving Deeper into Data Models

Do this excercises 

  1. The Benefits of Modeling Data]

A white background with black text

Description automatically generated


A close-up of a white background

Description automatically generated


A close-up of a person's face

Description automatically generated


A diagram of a data model

Description automatically generated

  1. The Ingredients of a Data Model


A blue and white logo

Description automatically generated with medium confidence


A blue background with white text

Description automatically generated

  1. Data Model Configuration Files

A close-up of a white background

Description automatically generated


A stack of papers

Description automatically generated with medium confidence

Default directory has lowest precedence.



A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated



  1. Data Model Acceleration

A white background with black text

Description automatically generated


A close-up of a text

Description automatically generated


A screenshot of a computer program

Description automatically generated




  1. Demo: Examine a Data Model in JSON

  • Data Models are either global or associated with App

  • Settings > Data Modeal >

  • Bin directory for all splunk executables, exe directory for splunk licensing info, var directory for all of the indexes

  • C:\Program Files\Splunk\etc\apps\search\default in windows

  • Config files is available in 

  • Json file C:\Program Files\Splunk\etc\apps\search\default\data\models\

    • internal_audit_logs.json

    • internal_server.json


A white background with black text

Description automatically generated

  1. Data Model Datasets

A close-up of a text

Description automatically generated

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A white background with pink text

Description automatically generated



  1. Dataset Field Categories

A close-up of a dataset

Description automatically generated

A white background with red text

Description automatically generated


A white background with red text

Description automatically generated




A white background with pink text

Description automatically generated

  1. Field Extractions

A white background with text

Description automatically generated


A close-up of text

Description automatically generated



A screen shot of a computer code

Description automatically generated






  1. Business Requirements and Our Scenario

A white text with black and orange writing

Description automatically generated


A screenshot of a computer

Description automatically generated


A blue and white rectangular boxes with black text

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated



  1. Demo: Build a Data Model

A close-up of text

Description automatically generated

  1. Add Data

Add Data  - Upload – mack_data.csv – next

Next

Host field value = mock_data, index = default (we can choose mockdata


  1. Add Lookup 

A screenshot of a computer

Description automatically generated


Go to look up file – change the permsion

A screenshot of a computer

Description automatically generated



  1. Do Lookup Defnition

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


  1. Set up data model


Settings – Data Model – New data model  

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated


Choose Root Event – 

A screenshot of a computer

Description automatically generated


Save then the next screen comes

A screenshot of a computer

Description automatically generated


Add the required fields based on the business requirements

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated



A screenshot of a computer

Description automatically generated


We need to get only Ad_Click=Yes > we need root search event 

A screenshot of a computer

Description automatically generated



A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


Add another field from broad dataset – choose auto extracted

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated



A screenshot of a computer

Description automatically generated


This satisfieds our first requirement

Add other fields from broad events for our use case

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated

Change revenue field to number

This Data moldel is the appications requirements –


A screenshot of a computer

Description automatically generated






  1. Module Summary

A white text on a white background

Description automatically generated

  1. Using the Pivot Tool to Build Dashboards, Reports, and Alerts from a Data Model

    1. Pivot Table Elements

A pink background with white text

Description automatically generated


A close-up of a pivot table

Description automatically generated


A close-up of a diagram

Description automatically generated



  1. Visualization Types and Their Uses

A green and pink rectangles with red text

Description automatically generated


A green and pink circle with pink text

Description automatically generated


A pie chart with different colored circles

Description automatically generated


A close-up of a chart

Description automatically generated


A white background with pink text

Description automatically generated


A graph showing the growth of the company

Description automatically generated


A white background with orange and pink text

Description automatically generated


A graph of a financial report

Description automatically generated with medium confidence


A diagram with text and bubbles

Description automatically generated with medium confidence


  1. Demo: Create Dashboards, Reports, and Alerts Based on Our Data Model

A white paper with black text

Description automatically generated


  • In the data modal click Pivot

  • A screenshot of a computer

Description automatically generated


Available data sets are :

A screenshot of a computer

Description automatically generated


Click Broad

A screenshot of a computer

Description automatically generated


A yellow background with black text

Description automatically generated


A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated



A yellow rectangle with black text

Description automatically generated

A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


Income range

A screen shot of a computer

Description automatically generated


A yellow background with black text

Description automatically generated



A screenshot of a computer

Description automatically generated


A screenshot of a computer

Description automatically generated


Nice dashboard and set the dashboard as home dashboard 


A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated





  1. Course Wrap Up

A white text on a white background

Description automatically generateds


No comments:

Post a Comment