More Related Content
Similar to UG_SEPT_2022_Q3.pdf (20)
UG_SEPT_2022_Q3.pdf
- 1. © 2021 SPLUNK INC.
© 2021 SPLUNK INC.
Welcome!
Austria Splunk User Group
- 2. © 2021 SPLUNK INC.
Community
Guidelines,
Terms, and
Conditions
Every individual who is in attendance at
this Splunk User Group Meeting, for any
period of time, without exception, must
adhere to the Splunk Community
Guidelines, as well as the Splunk
Website Terms of Use. This includes
leaders, users, customers, guests,
speakers, Splunkers, partners, and
anyone not listed.
All attendees at must officially register for this
event. If you have not yet done so, please
register now at:
https://usergroups.splunk.com/e/mbevht/
If someone forwarded the link to join this presentation, you
are not likely registered for the event.
Splunk Community Guidelines:
splk.it/CommunityGuidelines
Splunk Website Terms of Use:
splk.it/WebTerms
- 3. © 2021 SPLUNK INC.
Event Annotation
(EA)
Austrian Splunk Meetup 2022 Q3
- 4. © 2021 SPLUNK INC.
Alexander Sötz
Married, 2 Kids
Kössen, Tirol
Splunk Consultant
SVA System Vertrieb Alexander GmbH
München
- 5. © 2021 SPLUNK INC.
“A time series visualization that overlays a chart with event
flags and labels that are pulled from a secondary search
from logs, lookups, or a manually added data source.”
“ Event annotations can provide context for trends in a chart
by displaying correlating events. Event annotations can be
added to line charts, column charts, and area charts
using Simple XML or JSON (Dashboard Studio).”
What is Event Annotation?
Source: Splexicon
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 6. © 2021 SPLUNK INC.
Event annotations allow you to add context to
the trends returned by your time charts.
Or to keep it simple, add another Dimension by using
an additional search.
What is Event Annotation?
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 7. © 2021 SPLUNK INC.
DEMO TIME
How does it look like?
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 8. © 2021 SPLUNK INC.
Prerequisites for EA
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 9. © 2021 SPLUNK INC.
How to configure Event Annotation
“Simple XML”
- 11. © 2021 SPLUNK INC.
Is there a Difference?! Yes there is
JSON:
- 12. © 2021 SPLUNK INC.
XML
JSON
Is there a Difference?! Yes there is
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 13. © 2021 SPLUNK INC.
DEMO TIME
How does it look like?
Placeholders
Contain multiple text styles. Hit Tab or (Shift+Tab)
to navigate. See slide 47-48 for more information.
- 14. © 2021 SPLUNK INC.
1. Annotations are great to enrich you
timeseries panel
2. You need a second annotation
Search
3. AE are available for json and xml
4. There is a difference between json
and xml
Key Take
Aways