SlideShare a Scribd company logo
1 of 43
Download to read offline
Copyright © 2014 Splunk Inc.
GETTING STARTED
WITH SPLUNK
KELLY FEAGANS
SR. SE, TK-421
During	
  the	
  course	
  of	
  this	
  presenta1on,	
  we	
  may	
  make	
  forward-­‐looking	
  statements	
  regarding	
  future	
  events	
  or	
  the	
  
expected	
  performance	
  of	
  the	
  company.	
  We	
  cau1on	
  you	
  that	
  such	
  statements	
  reflect	
  our	
  current	
  
expecta1ons	
  and	
  es1mates	
  based	
  on	
  factors	
  currently	
  known	
  to	
  us	
  and	
  that	
  actual	
  events	
  or	
  results	
  could	
  differ	
  
materially.	
  For	
  important	
  factors	
  that	
  may	
  cause	
  actual	
  results	
  to	
  differ	
  from	
  those	
  contained	
  in	
  our	
  forward-­‐
looking	
  statements,	
  please	
  review	
  our	
  filings	
  with	
  the	
  SEC.	
  	
  The	
  forward-­‐looking	
  statements	
  made	
  in	
  this	
  
presenta1on	
  are	
  being	
  made	
  as	
  of	
  the	
  1me	
  and	
  date	
  of	
  its	
  live	
  presenta1on.	
  	
  If	
  reviewed	
  aHer	
  its	
  live	
  
presenta1on,	
  this	
  presenta1on	
  may	
  not	
  contain	
  current	
  or	
  accurate	
  informa1on.	
  	
  	
  We	
  do	
  not	
  assume	
  any	
  
obliga1on	
  to	
  update	
  any	
  forward-­‐looking	
  statements	
  we	
  may	
  make.	
  	
  In	
  addi1on,	
  any	
  informa1on	
  about	
  
our	
  roadmap	
  outlines	
  our	
  general	
  product	
  direc1on	
  and	
  is	
  subject	
  to	
  change	
  at	
  any	
  1me	
  without	
  no1ce.	
  	
  It	
  is	
  for	
  
informa1onal	
  purposes	
  only	
  and	
  shall	
  not,	
  be	
  incorporated	
  into	
  any	
  contract	
  or	
  other	
  commitment.	
  	
  Splunk	
  
undertakes	
  no	
  obliga1on	
  either	
  to	
  develop	
  the	
  features	
  or	
  func1onality	
  described	
  or	
  to	
  include	
  any	
  such	
  feature	
  
or	
  func1onality	
  in	
  a	
  future	
  release.	
  
	
  
Splunk,	
  Splunk>,	
  Splunk	
  Storm,	
  Listen	
  to	
  Your	
  Data,	
  SPL	
  and	
  The	
  Engine	
  for	
  Machine	
  Data	
  are	
  trademarks	
  and	
  registered	
  trademarks	
  of	
  
Splunk	
  Inc.	
  in	
  the	
  United	
  States	
  and	
  other	
  countries.	
  All	
  other	
  brand	
  names,	
  product	
  names,	
  or	
  trademarks	
  belong	
  to	
  their	
  respecCve	
  
owners.	
  	
  
©2013	
  Splunk	
  Inc.	
  All	
  rights	
  reserved.	
  
Legal	
  No)ces	
  
2
What	
  is	
  Splunk?	
  
GeLng	
  Started	
  
Basic	
  Searching	
  (demo)	
  
Using	
  Fields	
  (demo)	
  
Saving	
  and	
  Sharing	
  Reports	
  (demo)	
  
Next	
  Steps	
  
AGENDA	
  
Spelunking:	
  
	
  
Splunking:	
  
to	
  explore	
  
underground	
  caves	
  
to	
  explore	
  machine	
  data	
  
4
What	
  is	
  Machine	
  Data?	
  
5
!   Log	
  files	
  
!   Custom	
  applica1ons	
  
!   Web	
  servers	
  
!   User	
  clickstreams	
  
!   Social	
  plaTorms	
  
!   Servers/hypervisors/virtual	
  machines	
  
!   Configura1ons	
  
!   Telecom	
  devices	
  
!   Storage	
  devices	
  
!   Network	
  devices	
  
!   Security	
  devices,	
  firewalls,	
  IDS	
  
!   Databases	
  
!   Web	
  services	
  
!   System	
  metrics	
  
!   GPS	
  
!   DNS,	
  DHCP	
  
!   AAA	
  logs	
  
!   Proxy	
  servers	
  
!   Errors	
  
!   Scripts	
  
!   Sensors	
  
Machine	
  Data	
  Contains	
  Cri)cal	
  Insights	
  
6
What	
  Does	
  Splunk	
  Really	
  Do?	
  
Into	
  this	
  It	
  turns	
  this	
  
[Thu Sep 24 14:57:33 2009] [error] [client 10.2.1.44] ap_proxy: trying GET /petstore/
enter_order_information.screen at backend host '127.0.0.1/7001; got exception
'CONNECTION_REFUSED [os error=0, line 1739 of ../nsapi/URL.cpp]: Error connecting to host
127.0.0.1:7001', referer: http://10.2.1.223/petstore/cart.do?action=purchase&itemId=EST-14
7
GeAng	
  Started	
  
Splunk	
  Web	
  
9
!   Splunk's	
  dynamic	
  and	
  interac1ve	
  browser-­‐based	
  interface	
  
!   The	
  primary	
  interface	
  for	
  inves1ga1ng	
  problems,	
  repor1ng	
  on	
  results,	
  and	
  
managing	
  Splunk	
  deployments	
  
!   Note:	
  Splunk	
  with	
  a	
  free	
  license	
  does	
  not	
  have	
  access	
  controls,	
  so	
  you	
  will	
  not	
  be	
  
prompted	
  for	
  login	
  informa1on	
  
Search	
  &	
  Repor)ng	
  App	
  –	
  Summary	
  View	
  
current	
  view	
  
search	
  bar	
  
app	
  naviga1on	
  
current	
  app	
  
global	
  stats	
  
start	
  search	
  1me	
  range	
  picker	
  
resources	
  
10	
  
Events	
  
11
!   Searches	
  return	
  events	
  
!   In	
  Splunk,	
  an	
  event	
  is	
  a	
  single	
  piece	
  of	
  data,	
  such	
  as	
  a	
  record	
  in	
  a	
  log	
  file	
  
or	
  other	
  data	
  input	
  
!   Splunk	
  breaks	
  up	
  input	
  data	
  into	
  individual	
  events	
  and	
  	
  
gives	
  each	
  a	
  1mestamp,	
  host,	
  source,	
  and	
  sourcetype	
  
Events	
  (con)nued)	
  
12	
  
Everything	
  is	
  Searchable	
  
!   *	
  wildcard	
  supported	
  	
  
!   Search	
  terms	
  are	
  case	
  
insensi1ve	
  
!   Booleans	
  AND,	
  OR,	
  NOT	
  	
  
•  Must	
  be	
  uppercase	
  
•  AND	
  is	
  implied	
  between	
  
terms	
  
!   Use	
  ()	
  for	
  complex	
  searches	
  
!   Use	
  quota1on	
  marks	
  	
  
for	
  phrases	
  	
  
fail*!
fail* nfs!
error OR 404!
error OR failed OR (sourcetype=access* (500 OR 503))!
"login failure"!
13
Basic	
  Searching	
  
	
  
Search	
  
15
!   Matching	
  results	
  are	
  
displayed	
  in	
  reverse	
  
chronological	
  order	
  
(newest	
  first)	
  
!   Matching	
  search	
  
terms	
  are	
  highlighted	
  
Search	
  Results	
  
16
16
Fields	
  sidebar	
  
1mestamp	
  
1meline	
  
selected	
  fields	
  
event	
  
data	
  
Naviga)ng	
  Search	
  Results	
  	
  
17
!   Mouse	
  over	
  search	
  results	
  
–  Keywords	
  and	
  parts	
  of	
  
keywords	
  are	
  highlighted	
  
!   To	
  add	
  a	
  term	
  to	
  the	
  
search,	
  click	
  it	
  
–  AND	
  is	
  implied	
  
–  To	
  remove,	
  click	
  again	
  
!   To	
  exclude	
  a	
  term	
  from	
  a	
  
search,	
  alt+click	
  it	
  
–  Adds	
  NOT	
  [term]	
  to	
  search	
  
Selec)ng	
  Search	
  Time	
  Range	
  
18
!   By	
  default,	
  search	
  is	
  
“all	
  1me”	
  
–  Can	
  consume	
  a	
  great	
  
deal	
  of	
  resources	
  
–  Ideal	
  for	
  looking	
  at	
  long	
  
term	
  paierns,	
  such	
  as,	
  
advanced	
  persistent	
  
threat	
  
!   To	
  narrow	
  your	
  search,	
  
use	
  the	
  1me	
  range	
  
picker	
  
Basic	
  Searching	
  Demo	
  
	
  
Using	
  Fields	
  
What	
  are	
  Fields?	
  
!  Fields	
  are	
  searchable	
  key/value	
  pairs	
  in	
  your	
  event	
  data	
  
•  Example:	
  host=www1, status=503!
!  All	
  fields	
  have	
  names	
  and	
  can	
  be	
  searched	
  with	
  those	
  names	
  
•  Example:	
  Separa1ng	
  an	
  hip	
  status	
  code	
  of	
  404	
  from	
  Atlanta’s	
  area	
  code	
  
!  There	
  are	
  2	
  types	
  of	
  fields:	
  
default fields
data-specific fields
21
!   Data-­‐specific	
  field	
  values	
  come	
  from	
  your	
  data	
  
!   Some1mes	
  indicated	
  by	
  obvious	
  key=value	
  pairs:	
  
	
  
	
  
	
  
	
  
!   Some1mes	
  not:	
  
!   For	
  more	
  informa1on,	
  please	
  see:	
  
hip://docs.splunk.com/Documenta1on/Splunk/latest/Data/Listofpretrainedsourcetypes	
  	
  
Iden)fying	
  Data-­‐specific	
  Fields	
  
22
22	
  
!  For	
  the	
  current	
  search,	
  shows	
  	
  
•  Selected	
  fields	
  
•  Interes1ng	
  fields	
  
•  Link	
  to	
  view	
  all	
  fields	
  
!  Fields	
  returned	
  are	
  those	
  
Splunk	
  recognized	
  from	
  your	
  
search	
  results	
  
!  Interes1ng	
  fields	
  are	
  fields	
  that	
  
have	
  values	
  in	
  at	
  least	
  50%	
  of	
  
events	
  
Fields	
  Sidebar	
  	
  
Selected
fields
Interesting
fields
View all fields
(#)	
  indicates	
  number	
  
of	
  unique	
  values	
  
23
Selected	
  Fields	
  
24
!   Selected	
  fields	
  and	
  their	
  values	
  	
  
display	
  under	
  every	
  event	
  when	
  a	
  	
  
value	
  is	
  available	
  
!   By	
  default,	
  host,	
  source,	
  and	
  
sourcetype	
  are	
  selected	
  fields	
  
!   Fields	
  sidebar	
  is	
  interac1ve	
  
24	
  
!   Alt-­‐click	
  any	
  field	
  to	
  see	
  	
  
a	
  window	
  of	
  op1ons	
  for	
  
that	
  field	
  
!   Click	
  Yes	
  to	
  the	
  right	
  	
  
of	
  Selected	
  
•  The	
  field	
  will	
  appear	
  in	
  
the	
  selected	
  fields	
  list	
  
and	
  in	
  the	
  search	
  results	
  
Adding	
  Fields	
  to	
  Selected	
  Fields	
  
25
25	
  
More	
  Ways	
  to	
  Use	
  the	
  Fields	
  Sidebar	
  
Create	
  reports	
  (charts)	
  
Click	
  a	
  value	
  to	
  add	
  to	
  a	
  
search	
  
ALT	
  +	
  click	
  a	
  value	
  to	
  remove	
  
from	
  a	
  search	
  
Narrow	
  the	
  search	
  to	
  
show	
  only	
  results	
  that	
  
contain	
  this	
  field	
  
26	
  
Using	
  Fields	
  in	
  Searches	
  
!   Efficient	
  way	
  to	
  pinpoint	
  searches	
  and	
  refine	
  results	
  
	
  
!   Use	
  wildcards	
  
	
  
!   Field	
  names	
  ARE	
  case	
  sensi1ve,	
  field	
  values	
  are	
  NOT	
  
•  Example:	
  Splunk	
  extracts	
  a	
  field	
  in	
  linux_secure	
  data	
  named	
  user	
  
•  These	
  two	
  searches	
  return	
  results:	
  	
  	
  	
  	
  	
  	
  	
  	
  	
  	
  	
   	
   	
  This	
  one	
  does	
  not:	
  
vs
.
vs.	
  
27
!   From	
  the	
  fields	
  sidebar,	
  select	
  a	
  field	
  and	
  a	
  report	
  defini1on	
  
(Top	
  values,	
  Top	
  values	
  by	
  1me,	
  or	
  Rare	
  values)	
  
Create	
  Reports	
  from	
  Fields	
  Sidebar	
  
28
28	
  
Create	
  a	
  ‘Top	
  Values’	
  Report	
  
Mouse	
  over	
  a	
  bar	
  for	
  a	
  detailed	
  view	
  of	
  its	
  count	
  
Using	
  Fields	
  Demo	
  
Saving	
  and	
  Sharing	
  
Reports	
  
!  Save	
  search	
  criteria	
  and	
  1me	
  range,	
  but	
  not	
  results,	
  to	
  re-­‐run	
  at	
  any	
  point	
  in	
  
the	
  future	
  
!  Click	
  the	
  Save	
  As	
  buion,	
  select	
  Report,	
  enter	
  a	
  1tle	
  
Saving	
  Reports	
  
Running	
  Saved	
  Reports	
  
33	
  
Sharing	
  Reports	
  (Jobs)	
  
!   Save	
  report	
  results	
  and	
  generate	
  a	
  link	
  to	
  it	
  –	
  good	
  for	
  7	
  days	
  
!   Use	
  Share	
  buion	
  or	
  Job	
  dropdown	
  
!   Distribute	
  link	
  as	
  appropriate	
  
!  Capture	
  the	
  search	
  output	
  at	
  a	
  point	
  in	
  1me	
  –	
  “freeze”	
  results	
  
!  Click	
  Export	
  
!  Choose	
  a	
  format	
  
Saving	
  Results	
  
Beyond	
  the	
  Basics	
  
!   Splunk	
  has	
  many	
  powerful	
  features	
  and	
  search	
  commands	
  that	
  
allow	
  you	
  to:	
  
–  Pivot	
  -­‐	
  quickly	
  build	
  queries	
  and	
  display	
  results	
  through	
  an	
  easy	
  to	
  use	
  interface	
  
–  Create	
  alerts	
  
–  Capture	
  and	
  share	
  knowledge	
  
–  Calculate	
  sta1s1cs	
  
–  Format	
  and	
  organize	
  values	
  within	
  search	
  results	
  
–  Create	
  compelling	
  data	
  visualiza1ons	
  and	
  reports	
  
–  And	
  more!	
  
–  Learn	
  about	
  these	
  features	
  in	
  other	
  Using	
  Splunk	
  track	
  sessions	
  
36
Saving	
  and	
  Sharing	
  
Reports	
  Demo	
  
Next	
  Steps	
  
Get	
  Yourself	
  Educated!	
  
www.splunk.com	
  >	
  	
  Services	
  >	
  	
  Educa1on	
  
	
  
39
Catch	
  a	
  Flick!	
  
40
Read	
  Any	
  Good	
  Books	
  Lately?	
  
splunk.com/goto/book
41	
  
!  Download	
  Splunk	
  Enterprise	
  -­‐	
  build	
  your	
  own	
  sandbox	
  
!  Free!	
  	
  	
  	
  	
  www.splunk.com/download	
  	
  	
  
!  Pick	
  your	
  plaTorm	
  
!  Installs	
  in	
  minutes	
  
Take	
  a	
  Test	
  Drive!	
  
42
42	
  
Thank	
  You	
  

More Related Content

Similar to Getting Started with Splunk: Learn Machine Data Analytics

Splunk .conf2011: Search Language: Beginner
Splunk .conf2011: Search Language: BeginnerSplunk .conf2011: Search Language: Beginner
Splunk .conf2011: Search Language: BeginnerErin Sweeney
 
Splunk for ITOps
Splunk for ITOpsSplunk for ITOps
Splunk for ITOpsSplunk
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionSplunk
 
dlux splunk>live! 2012 Beginners Session
dlux splunk>live! 2012 Beginners Sessiondlux splunk>live! 2012 Beginners Session
dlux splunk>live! 2012 Beginners SessionDavid Lutz
 
Lesser known-search-commands
Lesser known-search-commandsLesser known-search-commands
Lesser known-search-commandspendoo
 
SplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunk
 
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding OverviewSplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding OverviewSplunk
 
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...Splunk
 
Deploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkDeploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkSplunk
 
SplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding OverviewSplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding OverviewSplunk
 
Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Splunk
 
Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Splunk
 
SplunkLive! Zurich 2018: Intro to Security Analytics Methods
SplunkLive! Zurich 2018: Intro to Security Analytics MethodsSplunkLive! Zurich 2018: Intro to Security Analytics Methods
SplunkLive! Zurich 2018: Intro to Security Analytics MethodsSplunk
 
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk
 
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...Splunk
 
SplunkLive! Data Models 101
SplunkLive! Data Models 101SplunkLive! Data Models 101
SplunkLive! Data Models 101Splunk
 
Conf2014_SplunkSecurityNinjutsu
Conf2014_SplunkSecurityNinjutsuConf2014_SplunkSecurityNinjutsu
Conf2014_SplunkSecurityNinjutsuSplunk
 
Power of Splunk Search Processing Language (SPL) ...
Power of Splunk Search Processing Language (SPL)                             ...Power of Splunk Search Processing Language (SPL)                             ...
Power of Splunk Search Processing Language (SPL) ...Splunk
 
SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1Splunk
 
Splunk for DataScience (.conf2014)
Splunk for DataScience (.conf2014)Splunk for DataScience (.conf2014)
Splunk for DataScience (.conf2014)stelligence
 

Similar to Getting Started with Splunk: Learn Machine Data Analytics (20)

Splunk .conf2011: Search Language: Beginner
Splunk .conf2011: Search Language: BeginnerSplunk .conf2011: Search Language: Beginner
Splunk .conf2011: Search Language: Beginner
 
Splunk for ITOps
Splunk for ITOpsSplunk for ITOps
Splunk for ITOps
 
Getting Started with Splunk Breakout Session
Getting Started with Splunk Breakout SessionGetting Started with Splunk Breakout Session
Getting Started with Splunk Breakout Session
 
dlux splunk>live! 2012 Beginners Session
dlux splunk>live! 2012 Beginners Sessiondlux splunk>live! 2012 Beginners Session
dlux splunk>live! 2012 Beginners Session
 
Lesser known-search-commands
Lesser known-search-commandsLesser known-search-commands
Lesser known-search-commands
 
SplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners SessionSplunkLive 2011 Beginners Session
SplunkLive 2011 Beginners Session
 
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding OverviewSplunkLive! Frankfurt 2018 - Data Onboarding Overview
SplunkLive! Frankfurt 2018 - Data Onboarding Overview
 
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
SplunkLive! Frankfurt 2018 - Legacy SIEM to Splunk, How to Conquer Migration ...
 
Deploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do SplunkDeploying Splunk. Arquitetura e dimensionamento do Splunk
Deploying Splunk. Arquitetura e dimensionamento do Splunk
 
SplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding OverviewSplunkLive! Munich 2018: Data Onboarding Overview
SplunkLive! Munich 2018: Data Onboarding Overview
 
Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Introduction into Security Analytics Methods
Introduction into Security Analytics Methods
 
Introduction into Security Analytics Methods
Introduction into Security Analytics Methods Introduction into Security Analytics Methods
Introduction into Security Analytics Methods
 
SplunkLive! Zurich 2018: Intro to Security Analytics Methods
SplunkLive! Zurich 2018: Intro to Security Analytics MethodsSplunkLive! Zurich 2018: Intro to Security Analytics Methods
SplunkLive! Zurich 2018: Intro to Security Analytics Methods
 
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
Splunk conf2014 - Splunk Monitoring - New Native Tools for Monitoring your Sp...
 
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
SplunkLive! Zurich 2018: Legacy SIEM to Splunk, How to Conquer Migration and ...
 
SplunkLive! Data Models 101
SplunkLive! Data Models 101SplunkLive! Data Models 101
SplunkLive! Data Models 101
 
Conf2014_SplunkSecurityNinjutsu
Conf2014_SplunkSecurityNinjutsuConf2014_SplunkSecurityNinjutsu
Conf2014_SplunkSecurityNinjutsu
 
Power of Splunk Search Processing Language (SPL) ...
Power of Splunk Search Processing Language (SPL)                             ...Power of Splunk Search Processing Language (SPL)                             ...
Power of Splunk Search Processing Language (SPL) ...
 
SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1SplunkLive! Analytics with Splunk Enterprise - Part 1
SplunkLive! Analytics with Splunk Enterprise - Part 1
 
Splunk for DataScience (.conf2014)
Splunk for DataScience (.conf2014)Splunk for DataScience (.conf2014)
Splunk for DataScience (.conf2014)
 

More from Splunk

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routineSplunk
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTVSplunk
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)Splunk
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank InternationalSplunk
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett Splunk
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)Splunk
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...Splunk
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...Splunk
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)Splunk
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)Splunk
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College LondonSplunk
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSplunk
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability SessionSplunk
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - KeynoteSplunk
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform SessionSplunk
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security SessionSplunk
 

More from Splunk (20)

.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine.conf Go 2023 - Data analysis as a routine
.conf Go 2023 - Data analysis as a routine
 
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
.conf Go 2023 - How KPN drives Customer Satisfaction on IPTV
 
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica).conf Go 2023 - Navegando la normativa SOX (Telefónica)
.conf Go 2023 - Navegando la normativa SOX (Telefónica)
 
.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International.conf Go 2023 - Raiffeisen Bank International
.conf Go 2023 - Raiffeisen Bank International
 
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett .conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
.conf Go 2023 - På liv og død Om sikkerhetsarbeid i Norsk helsenett
 
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär).conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
.conf Go 2023 - Many roads lead to Rome - this was our journey (Julius Bär)
 
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu....conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
.conf Go 2023 - Das passende Rezept für die digitale (Security) Revolution zu...
 
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever....conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
.conf go 2023 - Cyber Resilienz – Herausforderungen und Ansatz für Energiever...
 
.conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex).conf go 2023 - De NOC a CSIRT (Cellnex)
.conf go 2023 - De NOC a CSIRT (Cellnex)
 
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
conf go 2023 - El camino hacia la ciberseguridad (ABANCA)
 
Splunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11ySplunk - BMW connects business and IT with data driven operations SRE and O11y
Splunk - BMW connects business and IT with data driven operations SRE and O11y
 
Splunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go KölnSplunk x Freenet - .conf Go Köln
Splunk x Freenet - .conf Go Köln
 
Splunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go KölnSplunk Security Session - .conf Go Köln
Splunk Security Session - .conf Go Köln
 
Data foundations building success, at city scale – Imperial College London
 Data foundations building success, at city scale – Imperial College London Data foundations building success, at city scale – Imperial College London
Data foundations building success, at city scale – Imperial College London
 
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
Splunk: How Vodafone established Operational Analytics in a Hybrid Environmen...
 
SOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security WebinarSOC, Amore Mio! | Security Webinar
SOC, Amore Mio! | Security Webinar
 
.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session.conf Go 2022 - Observability Session
.conf Go 2022 - Observability Session
 
.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote.conf Go Zurich 2022 - Keynote
.conf Go Zurich 2022 - Keynote
 
.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session.conf Go Zurich 2022 - Platform Session
.conf Go Zurich 2022 - Platform Session
 
.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session.conf Go Zurich 2022 - Security Session
.conf Go Zurich 2022 - Security Session
 

Recently uploaded

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGSujit Pal
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slidevu2urc
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 

Recently uploaded (20)

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAG
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 

Getting Started with Splunk: Learn Machine Data Analytics

  • 1. Copyright © 2014 Splunk Inc. GETTING STARTED WITH SPLUNK KELLY FEAGANS SR. SE, TK-421
  • 2. During  the  course  of  this  presenta1on,  we  may  make  forward-­‐looking  statements  regarding  future  events  or  the   expected  performance  of  the  company.  We  cau1on  you  that  such  statements  reflect  our  current   expecta1ons  and  es1mates  based  on  factors  currently  known  to  us  and  that  actual  events  or  results  could  differ   materially.  For  important  factors  that  may  cause  actual  results  to  differ  from  those  contained  in  our  forward-­‐ looking  statements,  please  review  our  filings  with  the  SEC.    The  forward-­‐looking  statements  made  in  this   presenta1on  are  being  made  as  of  the  1me  and  date  of  its  live  presenta1on.    If  reviewed  aHer  its  live   presenta1on,  this  presenta1on  may  not  contain  current  or  accurate  informa1on.      We  do  not  assume  any   obliga1on  to  update  any  forward-­‐looking  statements  we  may  make.    In  addi1on,  any  informa1on  about   our  roadmap  outlines  our  general  product  direc1on  and  is  subject  to  change  at  any  1me  without  no1ce.    It  is  for   informa1onal  purposes  only  and  shall  not,  be  incorporated  into  any  contract  or  other  commitment.    Splunk   undertakes  no  obliga1on  either  to  develop  the  features  or  func1onality  described  or  to  include  any  such  feature   or  func1onality  in  a  future  release.     Splunk,  Splunk>,  Splunk  Storm,  Listen  to  Your  Data,  SPL  and  The  Engine  for  Machine  Data  are  trademarks  and  registered  trademarks  of   Splunk  Inc.  in  the  United  States  and  other  countries.  All  other  brand  names,  product  names,  or  trademarks  belong  to  their  respecCve   owners.     ©2013  Splunk  Inc.  All  rights  reserved.   Legal  No)ces   2
  • 3. What  is  Splunk?   GeLng  Started   Basic  Searching  (demo)   Using  Fields  (demo)   Saving  and  Sharing  Reports  (demo)   Next  Steps   AGENDA  
  • 4. Spelunking:     Splunking:   to  explore   underground  caves   to  explore  machine  data   4
  • 5. What  is  Machine  Data?   5 !   Log  files   !   Custom  applica1ons   !   Web  servers   !   User  clickstreams   !   Social  plaTorms   !   Servers/hypervisors/virtual  machines   !   Configura1ons   !   Telecom  devices   !   Storage  devices   !   Network  devices   !   Security  devices,  firewalls,  IDS   !   Databases   !   Web  services   !   System  metrics   !   GPS   !   DNS,  DHCP   !   AAA  logs   !   Proxy  servers   !   Errors   !   Scripts   !   Sensors  
  • 6. Machine  Data  Contains  Cri)cal  Insights   6
  • 7. What  Does  Splunk  Really  Do?   Into  this  It  turns  this   [Thu Sep 24 14:57:33 2009] [error] [client 10.2.1.44] ap_proxy: trying GET /petstore/ enter_order_information.screen at backend host '127.0.0.1/7001; got exception 'CONNECTION_REFUSED [os error=0, line 1739 of ../nsapi/URL.cpp]: Error connecting to host 127.0.0.1:7001', referer: http://10.2.1.223/petstore/cart.do?action=purchase&itemId=EST-14 7
  • 9. Splunk  Web   9 !   Splunk's  dynamic  and  interac1ve  browser-­‐based  interface   !   The  primary  interface  for  inves1ga1ng  problems,  repor1ng  on  results,  and   managing  Splunk  deployments   !   Note:  Splunk  with  a  free  license  does  not  have  access  controls,  so  you  will  not  be   prompted  for  login  informa1on  
  • 10. Search  &  Repor)ng  App  –  Summary  View   current  view   search  bar   app  naviga1on   current  app   global  stats   start  search  1me  range  picker   resources   10  
  • 11. Events   11 !   Searches  return  events   !   In  Splunk,  an  event  is  a  single  piece  of  data,  such  as  a  record  in  a  log  file   or  other  data  input   !   Splunk  breaks  up  input  data  into  individual  events  and     gives  each  a  1mestamp,  host,  source,  and  sourcetype  
  • 13. Everything  is  Searchable   !   *  wildcard  supported     !   Search  terms  are  case   insensi1ve   !   Booleans  AND,  OR,  NOT     •  Must  be  uppercase   •  AND  is  implied  between   terms   !   Use  ()  for  complex  searches   !   Use  quota1on  marks     for  phrases     fail*! fail* nfs! error OR 404! error OR failed OR (sourcetype=access* (500 OR 503))! "login failure"! 13
  • 15. Search   15 !   Matching  results  are   displayed  in  reverse   chronological  order   (newest  first)   !   Matching  search   terms  are  highlighted  
  • 16. Search  Results   16 16 Fields  sidebar   1mestamp   1meline   selected  fields   event   data  
  • 17. Naviga)ng  Search  Results     17 !   Mouse  over  search  results   –  Keywords  and  parts  of   keywords  are  highlighted   !   To  add  a  term  to  the   search,  click  it   –  AND  is  implied   –  To  remove,  click  again   !   To  exclude  a  term  from  a   search,  alt+click  it   –  Adds  NOT  [term]  to  search  
  • 18. Selec)ng  Search  Time  Range   18 !   By  default,  search  is   “all  1me”   –  Can  consume  a  great   deal  of  resources   –  Ideal  for  looking  at  long   term  paierns,  such  as,   advanced  persistent   threat   !   To  narrow  your  search,   use  the  1me  range   picker  
  • 21. What  are  Fields?   !  Fields  are  searchable  key/value  pairs  in  your  event  data   •  Example:  host=www1, status=503! !  All  fields  have  names  and  can  be  searched  with  those  names   •  Example:  Separa1ng  an  hip  status  code  of  404  from  Atlanta’s  area  code   !  There  are  2  types  of  fields:   default fields data-specific fields 21
  • 22. !   Data-­‐specific  field  values  come  from  your  data   !   Some1mes  indicated  by  obvious  key=value  pairs:           !   Some1mes  not:   !   For  more  informa1on,  please  see:   hip://docs.splunk.com/Documenta1on/Splunk/latest/Data/Listofpretrainedsourcetypes     Iden)fying  Data-­‐specific  Fields   22 22  
  • 23. !  For  the  current  search,  shows     •  Selected  fields   •  Interes1ng  fields   •  Link  to  view  all  fields   !  Fields  returned  are  those   Splunk  recognized  from  your   search  results   !  Interes1ng  fields  are  fields  that   have  values  in  at  least  50%  of   events   Fields  Sidebar     Selected fields Interesting fields View all fields (#)  indicates  number   of  unique  values   23
  • 24. Selected  Fields   24 !   Selected  fields  and  their  values     display  under  every  event  when  a     value  is  available   !   By  default,  host,  source,  and   sourcetype  are  selected  fields   !   Fields  sidebar  is  interac1ve   24  
  • 25. !   Alt-­‐click  any  field  to  see     a  window  of  op1ons  for   that  field   !   Click  Yes  to  the  right     of  Selected   •  The  field  will  appear  in   the  selected  fields  list   and  in  the  search  results   Adding  Fields  to  Selected  Fields   25 25  
  • 26. More  Ways  to  Use  the  Fields  Sidebar   Create  reports  (charts)   Click  a  value  to  add  to  a   search   ALT  +  click  a  value  to  remove   from  a  search   Narrow  the  search  to   show  only  results  that   contain  this  field   26  
  • 27. Using  Fields  in  Searches   !   Efficient  way  to  pinpoint  searches  and  refine  results     !   Use  wildcards     !   Field  names  ARE  case  sensi1ve,  field  values  are  NOT   •  Example:  Splunk  extracts  a  field  in  linux_secure  data  named  user   •  These  two  searches  return  results:                            This  one  does  not:   vs . vs.   27
  • 28. !   From  the  fields  sidebar,  select  a  field  and  a  report  defini1on   (Top  values,  Top  values  by  1me,  or  Rare  values)   Create  Reports  from  Fields  Sidebar   28 28  
  • 29. Create  a  ‘Top  Values’  Report   Mouse  over  a  bar  for  a  detailed  view  of  its  count  
  • 31. Saving  and  Sharing   Reports  
  • 32. !  Save  search  criteria  and  1me  range,  but  not  results,  to  re-­‐run  at  any  point  in   the  future   !  Click  the  Save  As  buion,  select  Report,  enter  a  1tle   Saving  Reports  
  • 34. Sharing  Reports  (Jobs)   !   Save  report  results  and  generate  a  link  to  it  –  good  for  7  days   !   Use  Share  buion  or  Job  dropdown   !   Distribute  link  as  appropriate  
  • 35. !  Capture  the  search  output  at  a  point  in  1me  –  “freeze”  results   !  Click  Export   !  Choose  a  format   Saving  Results  
  • 36. Beyond  the  Basics   !   Splunk  has  many  powerful  features  and  search  commands  that   allow  you  to:   –  Pivot  -­‐  quickly  build  queries  and  display  results  through  an  easy  to  use  interface   –  Create  alerts   –  Capture  and  share  knowledge   –  Calculate  sta1s1cs   –  Format  and  organize  values  within  search  results   –  Create  compelling  data  visualiza1ons  and  reports   –  And  more!   –  Learn  about  these  features  in  other  Using  Splunk  track  sessions   36
  • 37. Saving  and  Sharing   Reports  Demo  
  • 39. Get  Yourself  Educated!   www.splunk.com  >    Services  >    Educa1on     39
  • 41. Read  Any  Good  Books  Lately?   splunk.com/goto/book 41  
  • 42. !  Download  Splunk  Enterprise  -­‐  build  your  own  sandbox   !  Free!          www.splunk.com/download       !  Pick  your  plaTorm   !  Installs  in  minutes   Take  a  Test  Drive!   42 42