Splunk is a tool that indexes and searches data to generate graphs, alerts, and dashboards. It can analyze data from sources like logs, metrics, and other sources on both local and remote machines. Key concepts in Splunk include indexes which are databases that store events, which are individual data entries that are broken down and tagged with metadata during indexing. Searches in Splunk return results in tabs for events, statistics, and visualizations.
What is Splunk?
[4]Splunk is a tool that can be used to index, and search
data. Splunk can generate graphs, alerts, and dashboards
for this data.
3.
What kind ofdata is used by Splunk?
[5] IT streaming and historical data. Data from:
1. Event logs (e.g. event viewer logs)
2. Web logs (e.g. IIS logs)
3. System metrics (e.g. Windows performance counters)
4. And Others sources
4.
Splunk local, andremote data
Data used by Splunk can be on the same machine (local
data), or in a remote machine (remote data)
5.
Splunk Concepts
Index. Datarepositories created in splunk are called
Indexes. An index is a database.
Event. A single piece of data in Splunk is called Event [6].
Examples - single record or entry in a log file.
- single record or entry in the event viewer.
6.
Splunk Indexing
When Splunkindexes data, it breaks up the data into
individual pieces and gives each piece a timestamp, host,
source, and source type.
Splunk Search Concepts
•Index. An Index is a data repository in Splunk.
• Host. Host is the name, or IP address of the network machine that
originated the event.
• Source. Source is the file, directory path, network port, or script
from which the event was originated.
• Source Type. Source Type classify the data based on how it is
formatted.
9.
Installing Splunk
• Splunkinstallation can be done by following the steps described
in the below URL:
http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchTu
torial/Systemrequirements
10.
Getting Familiar withSplunk
• Get familiar with Splunk Enterprise:
http://docs.splunk.com/Documentation/Splunk/latest/SearchT
utorial/NavigatingSplunk
11.
Getting Data intoSplunk
• Get data into Splunk Enterprise:
http://docs.splunk.com/Documentation/Splunk/latest/SearchT
utorial/GetthetutorialdataintoSplunk
12.
Splunk Search &Reporting – UI elements
Application
Bar
Search Bar
Time Rage
Picker
Splunk Search Results– Events Tab
• Shows how many events have occurred at a particular
point in time.
Timeline
• When data is indexed, Splunk extract information from
the data that is formatted as name and value pairs.
Fields sidebar
25.
Splunk Search Results– Events Tab
• Shows the events that match the search criteria.
Search term matches
• Shows menus with options to format the search
results.
Event view options
26.
Searching Data usingSplunk
• To search for events / logs in Splunk, go to Splunk Search page.
1. In the Search textbox, type the word(s) you want to search
2. Specify filters to narrow the search result such as host or source
3. Click on the Search icon
Searching Data usingSplunk
• Additional details about searching data in Splunk can be found in
the below link:
http://docs.splunk.com/Documentation/Splunk/6.3.0/SearchTu
torial/Startsearching
References
5. About gettingdata into Splunk Enterprise.
http://docs.splunk.com/Documentation/Splunk/latest/SearchTutori
al/AboutgettingdataintoSplunk
6. Event
http://docs.splunk.com/Splexicon:Event
7. Splunk Installation Manual.
http://docs.splunk.com/Documentation/Splunk/6.2.0/Installation/I
nstallonWindows
8. About Splunk Free
http://docs.splunk.com/Documentation/Splunk/latest/Admin/More
aboutSplunkFree
31.
References
9. Get thetutorial data into Splunk
http://docs.splunk.com/Documentation/Splunk/6.2.0/SearchT
utorial/GetthetutorialdataintoSplunk
10.About the Search Tutorial
http://docs.splunk.com/Documentation/Splunk/latest/SearchT
utorial/WelcometotheSearchTutorial
11.Splunk download. http://www.splunk.com/download