1.1 Part - 1 | Welcome to this course! SPLUNK | SPLUNK tutorial | SPLUNK full course
1.2 PART - 2 | Demo Analyzing some data | SPLUNK tutorial
2.1 PART - 3 | The Basics of Splunking | SPLUNK tutorial
2.2 PART - 4 | Splunk installation options | SPLUNK tutorial
2.3 PART - 5 | Demo installing Splunk in Linux | SPLUNK tutorial
2.4 PART - 6 | Demo installing Splunk in Windows | SPLUNK tutorial
2.5 PART - 7 | Demo installing Splunk in MacOS | SPLUNK tutorial
2.6 PART - 8 | Identify Splunk components | SPLUNK tutorial
2.6.2.3 Indexer Cluster Master
2.6.2.4 Search Head Cluster Deployer
3 SPLUNK 3. Licence management
3.1 PART - 9 | License to Splunk | SPLUNK tutorial
3.2 PART - 10 | Identify license types | SPLUNK tutorial
3.3 PART - 11 | Understand license violations | SPLUNK tutorial
3.4 PART - 12 | Demo licensing | SPLUNK tutorial
3.5 PART - 13 | Distributed Licensing | SPLUNK tutorial
4 SPLUNK 4. SPLUNK configuration files
4.1 PART -14 | Configuration Files | SPLUNK tutorial
4.2 PART - 15 | Describe Splunk configuration directory structure | SPLUNK tutorial
4.2.2 Common Configuration Files
4.3 PART - 16 | Understand configuration layering and precedence | SPLUNK tutorial
4.4 PART - 17 | Demo Use btool to examine configuration settings demo | SPLUNK tutorial
5.1 PART - 18 | All About Indexes | SPLUNK tutorial
5.2 PART - 19 | Describe index structure | SPLUNK tutorial
5.3 PART - 20 | List types of index buckets | SPLUNK tutorial
5.4 %PART - 21 | Check index data integrity | SPLUNK tutorial
5.5 %PART - 22 | Describe indexes conf options | SPLUNK tutorial
5.6 PART - 23 | Describe the fishbucket | SPLUNK tutorial
5.7 PART - 24 | Demo Create an index | SPLUNK tutorial
5.8 PART - 25 | Demo Apply a data retention policy | SPLUNK tutorial
5.9 PART - 26 | Demo Exploring buckets in the Splunk file system | SPLUNK tutorial
5.10 PART - 27 | Check hashes to validate data | SPLUNK tutorial
SPLUNK 1. Introduction
Part - 1 | Welcome to this course! SPLUNK | SPLUNK tutorial | SPLUNK full course
Twitter : @adam_frisbee / Udeme course
Answers.splunk.com
PART - 2 | Demo Analyzing some data | SPLUNK tutorial
Add Data – upload – Search
Splunk discovered data and listed in left as
Selected Fields
Interesting Fields
“+ Extract New Fields” – lists raw data from the source
Compare success and error – this has visualization
Create Dashboard based on this
SPLUNK 2. Admin Basics
PART - 3 | The Basics of Splunking | SPLUNK tutorial
PART - 4 | Splunk installation options | SPLUNK tutorial
PART - 5 | Demo installing Splunk in Linux | SPLUNK tutorial
PART - 6 | Demo installing Splunk in Windows | SPLUNK tutorial
PART - 7 | Demo installing Splunk in MacOS | SPLUNK tutorial
PART - 8 | Identify Splunk components | SPLUNK tutorial
Processing Component
Forwarder
Universal Farworder
Easy to install
Heavy Forwarder
Forward, Parse, route
Indexer
Search Head
Monitoring Component
Deployment Server
License Master
Indexer Cluster Master
Search Head Cluster Deployer
SPLUNK 3. Licence management
PART - 9 | License to Splunk | SPLUNK tutorial
PART - 10 | Identify license types | SPLUNK tutorial
PART - 11 | Understand license violations | SPLUNK tutorial
PART - 12 | Demo licensing | SPLUNK tutorial
Splunk > Settings > Licensing
Not available for me in EPB
PART - 13 | Distributed Licensing | SPLUNK tutorial
Universal Forwarder doesn’t required License but Heavy Forwarder needs license.
SPLUNK 4. SPLUNK configuration files
PART -14 | Configuration Files | SPLUNK tutorial
PART - 15 | Describe Splunk configuration directory structure | SPLUNK tutorial
Directory Structure
Common Configuration Files
PART - 16 | Understand configuration layering and precedence | SPLUNK tutorial
Config file context
Global
App or User specific
Precedences
Btool
Used for Troubleshoot
Merged configurations
PART - 17 | Demo Use btool to examine configuration settings demo | SPLUNK tutorial
SPLUNK 5. Splunk Indexes
PART - 18 | All About Indexes | SPLUNK tutorial
PART - 19 | Describe index structure | SPLUNK tutorial
PART - 20 | List types of index buckets | SPLUNK tutorial
%PART - 21 | Check index data integrity | SPLUNK tutorial
%PART - 22 | Describe indexes conf options | SPLUNK tutorial
Indexes.Conf options
PART - 23 | Describe the fishbucket | SPLUNK tutorial
Keep track of which part of the files in bucket already indexed
_audit
Fish bucket contains Seek Pointers, CRC (Cyclical Redundancy Check) for the files
Directory monitor on Windows machine
C:\logs directory
PART - 24 | Demo Create an index | SPLUNK tutorial
2 ways to create Index
Add new data splunk we can create index
Create indexes with existing data in splunk – Settings > Indexes > New Index
Tsidx = Time Size index policy
PART - 25 | Demo Apply a data retention policy | SPLUNK tutorial
Default retain the data for 6 years
Global or user context
Cd etc/system/default/indexes.conf
In the indexes.conf > under stanza, frozenTimePeriodInSecs = 2419200 > this is 21 days
PART - 26 | Demo Exploring buckets in the Splunk file system | SPLUNK tutorial
PART - 27 | Check hashes to validate data | SPLUNK tutorial
As there is no data the integrity checking failoed.
No comments:
Post a Comment