Build a Splunk instance, and learn the concepts and terminology you need to produce insightful data reports and dashboard from data
Key Features
- Build and administer a Splunk system and use it to complete lab activities—no need for preexisting Splunk environments.
- Hands-on labs walk you through building environments, bringing in data, and ultimately using your own Splunk environment that you built yourself!
Book Description
Maybe you've heard about Splunk, but don't know how to use it to take control of big data? Have you used Splunk, but want to learn how to set it up and use it properly? If so, this course is for you.
In this course, you will work with Splunk from the ground up. You'll learn the basics of Splunk terminology, and how to use the Splunk web interface to find data. You'll also build your own Splunk environment, add data to the Common Information Model (CIM), create dashboards, and find events within data. Finally, you'll master advanced searching techniques that are especially useful to those in network, security, and system administration roles.
The course also covers the latest additions brought in for Splunk 8 and helps you quickly perform an upgrade. By the end of the course, you will be confident about using Splunk and will be well on the road to becoming a proficient Splunk architect and administrator as quickly as possible!
The reference links and other sources for this video course are available at https://github.com/PacktPublishing/Learning-Splunk
What you will learn
- Build your own Splunk development environment from scratch on a Linux server—and use it!
- Onboard and index multiple types of data into your Splunk instance
- Understand the importance of the Splunk Common Information Model (CIM), and why data models make Splunk a powerful tool for managing logs at volume
- Normalize data using Splunk apps
- Develop basic reports and dashboards using your new Splunk instance and the data from your Linux system
- Understand why leaving systems exposed to the internet is a bad idea
Who this book is for
This course is for IT professionals and data analysts who want to get started with Splunk and rapidly take their skills to the point where they can get hands-on and fully proficient with its features and benefits.
Requirement: No prior knowledge of Splunk is needed for taking this course, but a Splunk account (free of charge) will be required for the lab activities. Knowledge of Unix/Linux command line will be helpful.